vendor:
aircrack-ng tools
by:
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: aircrack-ng tools
Affected Version From: svn r1675
Affected Version To: svn r1675
Patch Exists: No
Related CWE:
CPE:
Platforms Tested:
Aircrack-ng Remote Exploit
A remote exploit against the aircrack-ng tools that allows for remote code execution. The exploit takes advantage of a vulnerability in the code responsible for parsing IEEE802.11 packets, specifically EAPOL packets. By manipulating the proclaimed length of the EAPOL packet and the packet's padding, an attacker can cause heap corruption and potentially gain control over $EIP. This exploit requires Scapy >= 2.x and Pyrit >= 0.3.1-dev r238 to work.
Mitigation:
Update aircrack-ng tools to the latest version to mitigate this vulnerability.