Debian DSA-788-1 : kismet - several vulnerabilities

critical Nessus Plugin ID 19531

Synopsis

The remote Debian host is missing a security-related update.

Description

Several security related problems have been discovered in kismet, a wireless 802.11b monitoring tool. The Common Vulnerabilities and Exposures project identifies the following problems :

- CAN-2005-2626 Insecure handling of unprintable characters in the SSID.

- CAN-2005-2627

Multiple integer underflows could allow remote attackers to execute arbitrary code.

The old stable distribution (woody) does not seem to be affected by these problems.

Solution

Upgrade the kismet package.

For the stable distribution (sarge) these problems have been fixed in version 2005.04.R1-1sarge1.

See Also

http://www.debian.org/security/2005/dsa-788

Plugin Details

Severity: Critical

ID: 19531

File Name: debian_DSA-788.nasl

Version: 1.19

Type: local

Agent: unix

Published: 8/30/2005

Updated: 1/4/2021

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Critical

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:kismet, cpe:/o:debian:debian_linux:3.1

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 8/29/2005

Vulnerability Publication Date: 8/3/2005

Reference Information

CVE: CVE-2005-2626, CVE-2005-2627

DSA: 788