Vulnerability Description
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aircrack-Ng | Aircrack-Ng | <= 1.1 |
Related Weaknesses (CWE)
References
- http://aircrack-ng.blogspot.com/2014/10/aircrack-ng-12-release-candidate-1.htmlProductRelease NotesThird Party Advisory
- http://packetstormsecurity.com/files/128943/Aircrack-ng-1.2-Beta-3-DoS-Code-ExecThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/35018Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98459Third Party AdvisoryVDB Entry
- https://github.com/aircrack-ng/aircrack-ng/commit/091b153f294b9b695b0b2831e65936PatchThird Party Advisory
- https://github.com/aircrack-ng/aircrack-ng/pull/14PatchThird Party Advisory
- http://aircrack-ng.blogspot.com/2014/10/aircrack-ng-12-release-candidate-1.htmlProductRelease NotesThird Party Advisory
- http://packetstormsecurity.com/files/128943/Aircrack-ng-1.2-Beta-3-DoS-Code-ExecThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/35018Third Party AdvisoryVDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98459Third Party AdvisoryVDB Entry
- https://github.com/aircrack-ng/aircrack-ng/commit/091b153f294b9b695b0b2831e65936PatchThird Party Advisory
- https://github.com/aircrack-ng/aircrack-ng/pull/14PatchThird Party Advisory
FAQ
What is CVE-2014-8322?
CVE-2014-8322 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
How severe is CVE-2014-8322?
CVE-2014-8322 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2014-8322?
Check the references section above for vendor advisories and patch information. Affected products include: Aircrack-Ng Aircrack-Ng.