« Volver al listado

CVE-2005-4835

Estado: ModificadaAlta (7.1)—

The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2005-4835",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2005-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://madwifi.org/ticket/162",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://madwifi.org/ticket/279",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://madwifi.org/ticket/287",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://madwifi.org/wiki/Releases/0.9.3",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/24841",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/26083",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:082",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2007_14_sr.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://madwifi.org/ticket/162",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://madwifi.org/ticket/279",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://madwifi.org/ticket/287",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://madwifi.org/wiki/Releases/0.9.3",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/24841",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/26083",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:082",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.novell.com/linux/security/advisories/2007_14_sr.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission."
    }
  ],
  "lastModified": "2026-06-16T22:19:32.560",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:madwifi:madwifi:0.9.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ADB6BFE-CEB2-4DFD-AB76-7A47708997AA"
            },
            {
              "criteria": "cpe:2.3:a:madwifi:madwifi:0.9.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A2309CA-C570-4994-A25C-452762651E73"
            },
            {
              "criteria": "cpe:2.3:a:madwifi:madwifi:0.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA6E66DE-5EF4-4772-ADCB-98DA4C8D4521"
            },
            {
              "criteria": "cpe:2.3:a:madwifi:madwifi:0.9.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "180B84A9-47AC-404A-A7D7-91EEA8BAB6D4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Not vulnerable. The MadWiFi wireless driver is not shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.",
      "lastModified": "2007-04-17T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}