Vulnerability Description
Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aircrack-Ng | Aircrack-Ng | <= 1.1 |
Related Weaknesses (CWE)
References
- http://aircrack-ng.blogspot.com/2014/10/aircrack-ng-12-release-candidate-1.htmlProductRelease NotesThird Party Advisory
- http://packetstormsecurity.com/files/128943/Aircrack-ng-1.2-Beta-3-DoS-Code-ExecThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98458Third Party AdvisoryVDB Entry
- https://github.com/aircrack-ng/aircrack-ng/commit/ff70494dd389ba570dbdbf36f217c2PatchThird Party Advisory
- https://github.com/aircrack-ng/aircrack-ng/pull/13PatchThird Party Advisory
- http://aircrack-ng.blogspot.com/2014/10/aircrack-ng-12-release-candidate-1.htmlProductRelease NotesThird Party Advisory
- http://packetstormsecurity.com/files/128943/Aircrack-ng-1.2-Beta-3-DoS-Code-ExecThird Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98458Third Party AdvisoryVDB Entry
- https://github.com/aircrack-ng/aircrack-ng/commit/ff70494dd389ba570dbdbf36f217c2PatchThird Party Advisory
- https://github.com/aircrack-ng/aircrack-ng/pull/13PatchThird Party Advisory
FAQ
What is CVE-2014-8321?
CVE-2014-8321 is a vulnerability with a CVSS score of 7.8 (HIGH). Stack-based buffer overflow in the gps_tracker function in airodump-ng.c in Aircrack-ng before 1.2 RC 1 allows local users to execute arbitrary code or gain privileges via unspecified vectors.
How severe is CVE-2014-8321?
CVE-2014-8321 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8321?
Check the references section above for vendor advisories and patch information. Affected products include: Aircrack-Ng Aircrack-Ng.