Stack-based buffer overflow in the parseTaggedData function in WavePacket.mm in KisMAC R54 through R73p allows remote attackers to execute arbitrary code via multiple SSIDs in a Cisco vendor tag in a 802.11 management frame.
| Software | From | Fixed in |
|---|---|---|
| kismac / kismac | 0.2a | 0.2a.x |
| kismac / kismac | 0.10a | 0.10a.x |
| kismac / kismac | 0.11a | 0.11a.x |
| kismac / kismac | 0.1a | 0.1a.x |
| kismac / kismac | 0.1b | 0.1b.x |
| kismac / kismac | 0.5d | 0.5d.x |
| kismac / kismac | 0.12a | 0.12a.x |
| kismac / kismac | 0.5d4 | 0.5d4.x |
| kismac / kismac | 0.1c | 0.1c.x |