Stack-based buffer overflow in the firmware in Broadcom Wi-Fi HardMAC SoC chips, when the firmware supports CCKM Fast and Secure Roaming and the feature is enabled in RAM, allows remote attackers to execute arbitrary code via a crafted reassociation response frame with a Cisco IE (156).
References
Link | Resource |
---|---|
https://bugs.chromium.org/p/project-zero/issues/detail?id=1051 | Third Party Advisory |
http://www.securityfocus.com/bid/97054 | Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/141803/Broadcom-Stack-Buffer-Overflow.html | Exploit Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2017-03-27 07:59
Updated : 2017-03-31 04:37
NVD link : CVE-2017-6957
Mitre link : CVE-2017-6957
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
broadcom
- bcm4339_soc_firmware
- bcm4339_soc