Debian Security Advisory

DSA-788-1 kismet -- several vulnerabilities

Date Reported:
29 Aug 2005
Affected Packages:
kismet
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2005-2626, CVE-2005-2627.
More information:

Several security related problems have been discovered in kismet, a wireless 802.11b monitoring tool. The Common Vulnerabilities and Exposures project identifies the following problems:

  • CAN-2005-2626

    Insecure handling of unprintable characters in the SSID.

  • CAN-2005-2627

    Multiple integer underflows could allow remote attackers to execute arbitrary code.

The old stable distribution (woody) does not seem to be affected by these problems.

For the stable distribution (sarge) these problems have been fixed in version 2005.04.R1-1sarge1.

For the unstable distribution (sid) these problems have been fixed in version 2005.08.R1-1.

We recommend that you upgrade your kismet package.

Fixed in:

Debian GNU/Linux 3.1 (sarge)

Source:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1.dsc
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1.diff.gz
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1.orig.tar.gz
Alpha:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_alpha.deb
ARM:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_arm.deb
Intel IA-32:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_i386.deb
Intel IA-64:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_ia64.deb
HPPA:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_hppa.deb
Motorola 680x0:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_m68k.deb
Big endian MIPS:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_mips.deb
Little endian MIPS:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_mipsel.deb
PowerPC:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_powerpc.deb
IBM S/390:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_s390.deb
Sun Sparc:
http://security.debian.org/pool/updates/main/k/kismet/kismet_2005.04.R1-1sarge1_sparc.deb

MD5 checksums of the listed files are available in the original advisory.