NETGEAR WN802T无线接入点EAPoL密钥长度缓冲区溢出漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1185449 漏洞类型 输入验证
发布时间 2008-09-04 更新时间 2008-09-04
CVE编号 CVE-2008-1144 CNNVD-ID CNNVD-200809-084
漏洞平台 N/A CVSS评分 6.3
|漏洞来源
https://www.securityfocus.com/bid/31013
https://cxsecurity.com/issue/WLB-2008090013
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200809-084
|漏洞详情
NETGEARWN802T是一款小型的无线接入设备。基于Marvell88W8361P-BEM1芯片组的NETGEARWN802T设备没有正确地解析用户所发送的EAPoL-Key报文,通过802.11认证的用户可以向接入点发送包含有超长长度字段的EAPoL-Key报文触发缓冲区溢出,导致拒绝服务或执行任意指令。
|漏洞EXP
Title:
------
* Marvell Driver EAPoL-Key Length Overflow

Summary:
--------
* The wireless drivers in some Wi-Fi access points (such as the
MARVELL-based Netgear WN802T) do not correctly parse malformed EAPoL-Key
packets. This packet is used for unicast/multicast key derivation (which
are called 4-way handshake and group key handshake) of any secure
wireless connection (WPA-PSK, WPA2-PSK, WPA-EAP, WPA2-EAP).

Assigned CVE:
-------------
* CVE-2008-1144

Details:
--------
* The bug can be triggered by a malicious EAPoL-Key packet sent to the
wireless access point (this packet has an advertised length too long
triggering the overflow). This can be achieved only after a successful
802.11 authentication (in "Open" mode according to the configuration of
the wireless access point) and a successful 802.11 association with
appropriate security parameters (e.g. WPA w/ TKIP unicast, TKIP
multicast) which depends on the configuration of the wireless access point.

Attack Impact:
--------------
* Denial-of-service (reboot or hang-up) and possibly remote arbitrary
code execution

Attack Vector:
--------------
* Unauthenticated wireless device for WPA/WPA2-PSK and EAP-based
authenticated wireless device for WPA/WPA2-EAP

Timeline:
---------
* 2008-02-19 - Vulnerability reported Netgear
* 2008-03-06 - PoC sent to Netgear
* 2008-09-04 - Public disclosure

Affected Products:
------------------
* Netgear WN802T (firmware 1.3.16) with MARVELL 88W8361P-BEM1 chipset

Vulnerable Devices:
-------------------
* As it is a wireless driver specific issue, the wireless vendor should
use the latest chipset wireless driver for their access point firmwares.
This security vulnerability was reported to Netgear, updated firmwares
should be available on their web site. Any other wireless device relying
on this vulnerable wireless driver is likely to be vulnerable.

Credits:
--------
* This vulnerability was discovered by Laurent Butti and Julien Tinnes
from France Telecom / Orange
|受影响的产品
NetGear WN802T Firmware 1.3.16 Marvell Semiconductor 88W8361P-BEM1 chipset 0
|参考资料

来源:XF
名称:netgear-wn802t-eapolkey-dos(44919)
链接:http://xforce.iss.net/xforce/xfdb/44919
来源:BID
名称:31013
链接:http://www.securityfocus.com/bid/31013
来源:BUGTRAQ
名称:20080904MarvellDriverEAPoL-KeyLengthOverflow
链接:http://www.securityfocus.com/archive/1/archive/1/495982/100/0/threaded
来源:SREASON
名称:4227
链接:http://securityreason.com/securityalert/4227
来源:SECUNIA
名称:31770
链接:http://secunia.com/advisories/31770