This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Broadcom Wireless Vuln - ZERT advisory

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://isc.sans.org/diary.php?storyid=1845
Last Updated: 2006-11-12 01:09:18 UTC

- http://isotf.org/advisories/zert-01-111106.htm
"…ZERT sees this vulnerability as critical, but can not patch it. This advisory comes to explain why this is a critical issue, why we can't patch it, and what can be done.
MoKB's advisory states: "The Broadcom BCMWL5.SYS wireless device driver is vulnerable to a stack-based buffer overflow that can lead to arbitrary kernel-mode code execution. This particular vulnerability is caused by improper handling of 802.11 probe responses containing a long SSID field. The BCMWL5.SYS driver is bundled with new PCs from HP, Dell, Gateway, eMachines, and other computer manufacturers. Broadcom has released a fixed driver to their partners, which are in turn providing updates for the affected products. Linksys*, Zonet, and other wireless card manufactures also provide devices that ship with this driver…
Q: Is it possible for Microsoft to push this update through their automatic updates system?
A: We believe that has been done before (last week as an example, with a smaller Broadcom update). However, the only answer to that question can come from Microsoft. Patching third party software is never an easy task, even if in collaboration with the third party. Microsoft potentially helping to patch this third-party issue could be of a significant help to get ahead of this threat."

EDIT/ADD:
* Linksys driver:
- http://preview.tinyurl.com/jchla

:ph34r:
Tip:
- http://blog.washingtonpost.com/securityfix…ly_deploye.html
11/11/2006
"A security researcher has released a set of instructions for exploiting a security flaw in the wireless Internet devices built into millions of new laptops from HP, Dell, Gateway and other computer makers. An attacker could use the flaw to take complete control over any vulnerable machine located within a few hundred feet… In the meantime, many laptops sold these days come with a button you can push to disable the built-in wireless card. If your laptop came with one of those, it might not be a bad idea to get into the habit of using it."
FYI…

Broadcom Wireless Driver Probe Response SSID Buffer Overflow
- http://secunia.com/advisories/22831/
Release Date: 2006-11-13
Critical: Moderately critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: Broadcom NIDS 5.0 Wireless Driver 3.x
…The vulnerability is caused due to a boundary error in the BCMWL5.SYS device driver when handling probe response requests with a long SSID. This can be exploited to cause a stack-based buffer overflow via a specially crafted packet. The vulnerability is reported in version 3.50.21.10. Other versions may also be affected.
Solution: Update to the latest version.
Linksys: http://preview.tinyurl.com/jchla
Turn off the wireless card when not in use…"
FYI…

- http://blog.washingtonpost.com/securityfix…security_h.html
November 14, 2006
"…It turns out that HP issued a patch in October to fix this flaw. HP users should be able to install this patch by visiting Microsoft Update, letting it scan, and then selecting the "Hardware/Optional" option at the left hand side of the screen. This worked on my HP laptop*, and there may be updates for this flaw from other affected PC makers (Dell and Gateway come to mind). I think it's great that Microsoft is offering Microsoft Update as a distribution mechanism for serious flaws in the PCs made by third parties, but most people probably would not know to check that portion of Microsoft Update, and I can't recall ever seeing any alerts from HP about this important patch."

* http://blog.washingtonpost.com/securityfix/hpmu.html

:huh: