|Summary:||CVE-2014-8321 CVE-2014-8322 CVE-2014-8323 CVE-2014-8324 aircrack-ng: multiple vulnerabilities|
|Product:||[Other] Security Response||Reporter:||Vasyl Kaigorodov <vkaigoro>|
|Component:||vulnerability||Assignee:||Red Hat Product Security <security-response-team>|
|Status:||NEW ---||QA Contact:|
|Version:||unspecified||CC:||carnil, opensource, pfrields|
|Fixed In Version:||Doc Type:||Bug Fix|
|Doc Text:||Story Points:||---|
|oVirt Team:||---||RHEL 7.3 requirements from Atomic Host:|
|Bug Depends On:||1159813|
Description Vasyl Kaigorodov 2014-11-03 12:04:47 UTC
It was reported  that four vulnerabilities exist on aircrack-ng <= 1.2 Beta 3 which allow remote/local code execution, privilege escalation and denial of service. Specifically, the following vulnerabilities were identified: - CVE-2014-8321 A stack overflow at airodump-ng gps_tracker() which may lead to code execution, privilege escalation. https://github.com/aircrack-ng/aircrack-ng/commit/ff70494dd389ba570dbdbf36f217c28d4381c6b5 - CVE-2014-8322 A length parameter inconsistency at aireplay tcp_test() which may lead to remote code execution. https://github.com/aircrack-ng/aircrack-ng/commit/091b153f294b9b695b0b2831e65936438b550d7b - CVE-2014-8323 A missing check for data format at buddy-ng which may lead to denial of service. https://github.com/aircrack-ng/aircrack-ng/commit/da087238963c1239fdabd47dc1b65279605aca70 - CVE-2014-8324 A missing check for invalid values at airserv-ng net_get() which may lead to denial of service. https://github.com/aircrack-ng/aircrack-ng/commit/88702a3ce4c28a973bf69023cd0312f412f6193e Soon a new version will be released but at the time there is no patched version. : http://seclists.org/bugtraq/2014/Nov/1
Comment 1 Vasyl Kaigorodov 2014-11-03 12:05:15 UTC
Created aircrack-ng tracking bugs for this issue: Affects: fedora-all [bug 1159813]
Comment 2 Fedora Update System 2014-11-10 06:38:15 UTC
aircrack-ng-1.2-0.5rc1.fc21 has been pushed to the Fedora 21 stable repository. If problems still persist, please make note of it in this bug report.
Comment 3 Fedora Update System 2014-11-13 18:16:42 UTC
aircrack-ng-1.2-0.3.rc1.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.
Comment 4 Fedora Update System 2014-11-13 18:18:59 UTC
aircrack-ng-1.2-0.3.rc1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.