UBUNTU-CVE-2019-9500
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9500
UBUNTU-CVE-2019-9500
Summary:
Details: The Broadcom brcmfmac WiFi driver prior to commit 1b5e2423164b3670e8bc9174e4762d297990deff is vulnerable to a heap buffer overflow. If the Wake-up on Wireless LAN functionality is configured, a malicious event frame can be constructed to trigger an heap buffer overflow in the brcmf_wowl_nd_results function. This vulnerability can be exploited with compromised chipsets to compromise the host, or when used in combination with CVE-2019-9503, can be used remotely. In the worst case scenario, by sending specially-crafted WiFi packets, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. More typically, this vulnerability will result in denial-of-service conditions.
References: https://ubuntu.com/security/CVE-2019-9500, https://blog.quarkslab.com/reverse-engineering-broadcom-wireless-chipsets.html, https://ubuntu.com/security/notices/USN-3979-1, https://ubuntu.com/security/notices/USN-3980-1, https://ubuntu.com/security/notices/USN-3981-1, https://ubuntu.com/security/notices/USN-3980-2, https://ubuntu.com/security/notices/USN-3981-2, https://www.cve.org/CVERecord?id=CVE-2019-9500
Affected packages
Package
Name: linux-azure
Purl: pkg:deb/ubuntu/[email protected]~14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
