CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
AI Score
Confidence
High
EPSS
Percentile
95.0%
Multiple integer underflows in Kismet before 2005-08-R1 allow remote attackers to execute arbitrary code via (1) kernel headers in a pcap file or (2) data frame dissection, which leads to heap-based buffer overflows.
Vendor | Product | Version | CPE |
---|---|---|---|
kismet | kismet | 2.4.5 | cpe:2.3:a:kismet:kismet:2.4.5:*:*:*:*:*:*:* |
kismet | kismet | 2.4.6 | cpe:2.3:a:kismet:kismet:2.4.6:*:*:*:*:*:*:* |
kismet | kismet | 2.6.0 | cpe:2.3:a:kismet:kismet:2.6.0:*:*:*:*:*:*:* |
kismet | kismet | 2.8.0 | cpe:2.3:a:kismet:kismet:2.8.0:*:*:*:*:*:*:* |
kismet | kismet | 2.8.0a | cpe:2.3:a:kismet:kismet:2.8.0a:*:*:*:*:*:*:* |
kismet | kismet | 2.8.1 | cpe:2.3:a:kismet:kismet:2.8.1:*:*:*:*:*:*:* |
kismet | kismet | 2004-02_r1 | cpe:2.3:a:kismet:kismet:2004-02_r1:*:*:*:*:*:*:* |
kismet | kismet | 2004-04_r1 | cpe:2.3:a:kismet:kismet:2004-04_r1:*:*:*:*:*:*:* |
kismet | kismet | 2004-04_r1a | cpe:2.3:a:kismet:kismet:2004-04_r1a:*:*:*:*:*:*:* |
kismet | kismet | 2004-10_r1 | cpe:2.3:a:kismet:kismet:2004-10_r1:*:*:*:*:*:*:* |
secunia.com/advisories/16447
secunia.com/advisories/16477
secunia.com/advisories/16634
www.debian.org/security/2005/dsa-788
www.gentoo.org/security/en/glsa/glsa-200508-10.xml
www.kismetwireless.net/blog/?entry=/kismet/entry-1124158146.txt
www.kismetwireless.net/CHANGELOG
www.novell.com/linux/security/advisories/2005_20_sr.html
www.securityfocus.com/bid/14430
www.vupen.com/english/advisories/2005/1422