Wow! Lots of kernel flaws...

Gilbert Sebenste sebenste at weather.admin.niu.edu
Wed Nov 22 21:19:20 UTC 2006


Hello Arjan,

>> Stack-based buffer overflow in A5AGU.SYS 1.0.1.41 for the D-Link DWL-G132
>> wireless adapter allows remote attackers to execute arbitrary code via a
>> 802.11 beacon request with a long Rates information element (IE).
>
> this is a WINDOWS driver!

Whoops! My bad. My cut 'n' paste didn't work well here.

> the rest is basically the known set of "if you get enough power to have
> a fully malformed filesystem the kernel oopses" category.. not that
> urgent..
> (should be fixed at some point of course like any kernel crash. But to
> consider them as serious security issue... you could classify every
> kernel oops as security that way)


True. But one of them, the ext3, looked more serious. OK, I'll hold off on 
the bugzilla.

*******************************************************************************
Gilbert Sebenste                                                     ********
(My opinions only!)                                                  ******
*******************************************************************************




More information about the fedora-test-list mailing list