CVE-2010-1159
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
28/10/2013
Last modified:
11/04/2025
Description
Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL packet.
Impact
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:aircrack-ng:aircrack-ng:*:*:*:*:*:*:*:* | 1.0 (including) | |
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.4.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.4.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.4.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.4.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.6.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.6.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:aircrack-ng:aircrack-ng:0.7:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://pyrit.googlecode.com/svn/tags/opt/aircrackng_exploit.py
- http://secunia.com/advisories/39150
- http://secunia.com/advisories/55053
- http://security.gentoo.org/glsa/glsa-201310-06.xml
- http://svn.aircrack-ng.org/trunk/ChangeLog
- http://pyrit.googlecode.com/svn/tags/opt/aircrackng_exploit.py
- http://secunia.com/advisories/39150
- http://secunia.com/advisories/55053
- http://security.gentoo.org/glsa/glsa-201310-06.xml
- http://svn.aircrack-ng.org/trunk/ChangeLog



