CVE-2014-8322

EUVD-2014-8163
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attackers to execute arbitrary code via a crafted length parameter value.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
aircrack-ngaircrack-ng
𝑥
≤ 1.1
aircrack-ngaircrack-ng
1.2:beta1
aircrack-ngaircrack-ng
1.2:beta2
aircrack-ngaircrack-ng
1.2:beta3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
aircrack-ng
bookworm
1:1.7-5
fixed
bullseye
1:1.6+git20210130.91820bc-1
fixed
sid
1:1.7+git20230807.4bf83f1a-2
fixed
trixie
1:1.7+git20230807.4bf83f1a-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
aircrack-ng
artful
not-affected
bionic
not-affected
cosmic
not-affected
disco
not-affected
lucid
ignored
precise
dne
trusty
dne
utopic
ignored
vivid
ignored
wily
ignored
xenial
not-affected
yakkety
not-affected
zesty
not-affected