Advertisement
Promo

Security threats Toolkit

Broadcom kernel exploit affects many laptops

Tom Espiner ZDNet.co.uk

Published: 13 Nov 2006 17:01 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

IT managers have been warned about a flaw that affects notebook PCs running Windows 2000 and XP that use Broadcom chipsets.

The Wi-Fi security hole affects many manufacturers' equipment, including HP, Dell, Gateway, Fujitsu and eMachines. The Broadcom Wireless Driver Probe Response SSID Buffer Overflow exploit is at kernel level, allowing an attacker to compromise and fully control a machine, according to malware alert company Secunia.

The vulnerability is caused due to a boundary error in the BCMWL5.SYS device driver when handling probe response requests with a long SSID. This can be exploited to cause a stack-based buffer overflow via a specially crafted packet, according to Secunia. The flaw was discovered by a researcher known as Johnny Cache.

Broadcom created an updated reference driver but opted not to issue a security advisory, according to TechRepublic blogger George Ou. The company was unavailable for comment at the time of writing.

Wireless and Ethernet networking company, Linksys, has released an updated driver that addresses this flaw. Dell and HP have not responded to a request for comment as to whether they have issued updated drivers yet. According to Ou, it's possible to run the Linksys drivers on other laptops to gain protection from the flaw.

For advice on how to install the Linksys drivers visit George Ou's blog.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
307 out of 370 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

Post a comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

Post a comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters