CVE-2010-4648
Published: 12 January 2012
The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.
From the Ubuntu security team
An error was reported in the kernel's ORiNOCO wireless driver's handling of TKIP countermeasures. This reduces the amount of time an attacker needs breach a wireless network using WPA+TKIP for security.
Priority
Status
Package | Release | Status |
---|---|---|
linux Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
Patches: Introduced by d03032af511c56d3c1580fa4f54f6285f650e638 Fixed by 0a54917c3fc295cb61f3fb52373c173fd3b69f48 |
||
linux-armadaxp Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
linux-ec2 Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
linux-fsl-imx51 Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
linux-lts-backport-maverick Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
linux-lts-backport-natty Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
linux-lts-backport-oneiric Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
linux-mvl-dove Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
linux-ti-omap4 Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.6.37~rc6)
|
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4648
- https://www.redhat.com/archives/rhsa-announce/2011-April/msg00007.html
- https://usn.ubuntu.com/usn/usn-1080-2
- https://usn.ubuntu.com/usn/usn-1080-1
- https://usn.ubuntu.com/usn/usn-1081-1
- https://usn.ubuntu.com/usn/usn-1093-1
- https://usn.ubuntu.com/usn/usn-1187-1
- NVD
- Launchpad
- Debian