Overview
- Description
- ieee80211_input.c in MadWifi before 0.9.3 does not properly process Channel Switch Announcement Information Elements (CSA IEs), which allows remote attackers to cause a denial of service (loss of communication) via a Channel Switch Count less than or equal to one, triggering a channel change.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.8
- Impact score
- 6.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:N/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Social media
- Hype score
- Not currently trending
Vendor comments
- Red HatNot vulnerable. The MadWiFi wireless driver is not shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:madwifi:madwifi:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6960E4C4-F392-47FD-B334-6F840CE977EF", "versionEndIncluding": "0.9.2" }, { "criteria": "cpe:2.3:a:madwifi:madwifi:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "322E4516-03E5-44E3-9E5A-A4C8A628832D", "versionEndIncluding": "0.9.2.1" } ], "operator": "OR" } ] } ]