Integer overflow in IEEE 802.11 network subsystem (ieee80211_ioctl.c) in FreeBSD before 6.0-STABLE, while scanning for wireless networks, allows remote attackers to execute arbitrary code by broadcasting crafted (1) beacon or (2) probe response frames.
| Software | From | Fixed in |
|---|---|---|
| freebsd / freebsd | 6.0-release | 6.0-release.x |
| freebsd / freebsd | 6.0-stable | 6.0-stable.x |