CVE-2009-0282
Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.83%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.83% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- ralinktech/rt73
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512995
- http://secunia.com/advisories/33592Vendor Advisory
- http://secunia.com/advisories/33699Vendor Advisory
- http://secunia.com/advisories/35743Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200907-08.xml
- http://www.debian.org/security/2009/dsa-1712
- http://www.debian.org/security/2009/dsa-1713
- http://www.debian.org/security/2009/dsa-1714
- http://www.securityfocus.com/archive/1/500168/100/0/threaded
- http://www.securityfocus.com/bid/33340
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512995
- http://secunia.com/advisories/33592Vendor Advisory
- http://secunia.com/advisories/33699Vendor Advisory
- http://secunia.com/advisories/35743Vendor Advisory
- http://security.gentoo.org/glsa/glsa-200907-08.xml
- http://www.debian.org/security/2009/dsa-1712
- http://www.debian.org/security/2009/dsa-1713
- http://www.debian.org/security/2009/dsa-1714
- http://www.securityfocus.com/archive/1/500168/100/0/threaded
- http://www.securityfocus.com/bid/33340
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.