AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1845
Last Updated: 2006-11-12 01:09:18 UTC
- http://isotf.org/advisories/zert-01-111106.htm
"…ZERT sees this vulnerability as critical, but can not patch it. This advisory comes to explain why this is a critical issue, why we can't patch it, and what can be done.
MoKB's advisory states: "The Broadcom BCMWL5.SYS wireless device driver is vulnerable to a stack-based buffer overflow that can lead to arbitrary kernel-mode code execution. This particular vulnerability is caused by improper handling of 802.11 probe responses containing a long SSID field. The BCMWL5.SYS driver is bundled with new PCs from HP, Dell, Gateway, eMachines, and other computer manufacturers. Broadcom has released a fixed driver to their partners, which are in turn providing updates for the affected products. Linksys*, Zonet, and other wireless card manufactures also provide devices that ship with this driver…
Q: Is it possible for Microsoft to push this update through their automatic updates system?
A: We believe that has been done before (last week as an example, with a smaller Broadcom update). However, the only answer to that question can come from Microsoft. Patching third party software is never an easy task, even if in collaboration with the third party. Microsoft potentially helping to patch this third-party issue could be of a significant help to get ahead of this threat."
EDIT/ADD:
* Linksys driver:
- http://preview.tinyurl.com/jchla

- http://isc.sans.org/diary.php?storyid=1845
Last Updated: 2006-11-12 01:09:18 UTC
- http://isotf.org/advisories/zert-01-111106.htm
"…ZERT sees this vulnerability as critical, but can not patch it. This advisory comes to explain why this is a critical issue, why we can't patch it, and what can be done.
MoKB's advisory states: "The Broadcom BCMWL5.SYS wireless device driver is vulnerable to a stack-based buffer overflow that can lead to arbitrary kernel-mode code execution. This particular vulnerability is caused by improper handling of 802.11 probe responses containing a long SSID field. The BCMWL5.SYS driver is bundled with new PCs from HP, Dell, Gateway, eMachines, and other computer manufacturers. Broadcom has released a fixed driver to their partners, which are in turn providing updates for the affected products. Linksys*, Zonet, and other wireless card manufactures also provide devices that ship with this driver…
Q: Is it possible for Microsoft to push this update through their automatic updates system?
A: We believe that has been done before (last week as an example, with a smaller Broadcom update). However, the only answer to that question can come from Microsoft. Patching third party software is never an easy task, even if in collaboration with the third party. Microsoft potentially helping to patch this third-party issue could be of a significant help to get ahead of this threat."
EDIT/ADD:
* Linksys driver:
- http://preview.tinyurl.com/jchla