Buffer overflow bug bites Linux wireless component
Proximity hack threat sparks security update
Posted in Enterprise Security, 10th November 2008 09:56 GMT
VMware whitepaper - The business case for Virtualization
A security flaw involving a wireless driver poses a severe risk for Linux-based systems.
The buffer overflow bug in NDISwrapper's Windows Wi-Fi driver kicks in when a long Extended Service Set Identifier (ESSID) is processed. The flaw could be used to crash vulnerable systems. In certain conditions, it might even be possible to inject malicious code into systems with kernel-level privileges.
Exploit scenarios would include a hacker near his intended victim who generates malformed traffic to crash affected Linux-based systems.
NDISwrapper version 1.53 is known to be vulnerable. The component appears, for example, in Ubuntu's 2.6.27 kernel. To defend against attack, either update to the latest version of NDISwrapper or install distribution packages that bundle later versions of the program, where available. ®

Rethink virtualization in business terms
The Business Case for Virtualization
Implementing energy efficient data centers
Distribute the workload for greater efficiency and power
HP and VMware take the cost and complexity out of IT

Scareware mongers hitch free ride on Microsoft.com and others
Home Office death list 'stops ID fraud'
Boffin brings 'write once, run anywhere' to Cisco hijacks
American Express bitten by XSS bugs (again)