Overview
A vulnerability exists in the Apple AirPort Extreme wireless driver that may allow an attacker to crash a vulnerable system.
Description
The Apple AirPort Extreme adapter is an 802.11g compatible wireless adapter used in Apple OS X laptops and desktops. A flaw exists in the way AirPort Extreme wireless drivers handle certain malformed 802.11 frames which may result in an out-of-bounds memory access. This flaw results in a vulnerability that could allow an attacker to cause a kernel panic on a vulnerable system. |
Impact
A remote unauthenticated attacker within 802.11 radio range may be able to create a denial-of-service condition by crashing a vulnerable system. |
Solution
Upgrade |
Turn your AirPort Card off when you're in situations where radio communication may be prohibited, such as in an airplane or at a hospital. If you have disabled the AirPort port in Network preferences, then your AirPort Card is already turned off. To disable the AirPort port, choose Network Port Configurations from the Show pop-up menu and deselect the AirPort checkbox. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://lists.apple.com/archives/security-announce/2007/Jan/msg00001.html
- http://www.apple.com/support/downloads/airportextremeupdate2007001.html
- http://en.wikipedia.org/wiki/AirPort#Airport_Extreme_Card
- http://projects.info-pull.com/mokb/MOKB-30-11-2006.html
- http://docs.info.apple.com/article.html?artnum=305031
- http://docs.info.apple.com/article.html?artnum=106227
- http://standards.ieee.org/getieee802/download/802.11g-2003.pdf
- http://secunia.com/advisories/23159/
Acknowledgements
This issue was made public by LMH on the Month of Kernel Bugs website.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-6292 |
Severity Metric: | 0.37 |
Date Public: | 2006-11-30 |
Date First Published: | 2007-02-02 |
Date Last Updated: | 2007-02-02 20:45 UTC |
Document Revision: | 15 |