<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="e359f84108f33e47c88b77987c15390b"!-->
<patch
    xmlns="http://novell.com/package/metadata/suse/patch"
    xmlns:yum="http://linux.duke.edu/metadata/common"
    xmlns:rpm="http://linux.duke.edu/metadata/rpm"
    xmlns:suse="http://novell.com/package/metadata/suse/common"
    patchid="sdkp1-madwifi-3897"
    timestamp="1184574189"
    engine="1.0">
  <yum:name>sdkp1-madwifi</yum:name>
  <summary lang="en">Security update for madwifi</summary>
  <summary lang="de">Security update for madwifi</summary>
  <description lang="en">The madwifi driver and userland packages were updated to
0.9.3.1. Please note that while the RPM version still says
&quot;0.9.3&quot;, the content is the 0.9.3.1 version.

This updates fixes following security problems:

CVE-2007-2829: The 802.11 network stack in
net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows
remote attackers to cause a denial of service (system hang)
via a crafted length field in nested 802.3 Ethernet frames
in Fast Frame packets, which results in a NULL pointer
dereference.

CVE-2007-2830: The ath_beacon_config function in if_ath.c
in MadWifi before 0.9.3.1 allows remote attackers to cause
a denial of service (system crash) via crafted beacon
interval information when scanning for access points, which
triggers a divide-by-zero error.

CVE-2007-2831: Array index error in the (1)
ieee80211_ioctl_getwmmparams and (2)
ieee80211_ioctl_setwmmparams functions in
net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1
allows local users to cause a denial of service (system
crash), possibly obtain kernel memory contents, and
possibly execute arbitrary code via a large negative array
index value.

&quot;remote attackers&quot; are attackers within range of the WiFi
reception of the card.

Please note that the problems fixed in 0.9.3 were fixed by
the madwifi Version upgrade to 0.9.3 in SLE10 Service Pack
1. (CVE-2005-4835, CVE-2006-7177, CVE-2006-7178,
CVE-2006-7179, CVE-2006-7180).
</description>
  <description lang="de">The madwifi driver and userland packages were updated to
0.9.3.1. Please note that while the RPM version still says
&quot;0.9.3&quot;, the content is the 0.9.3.1 version.

This updates fixes following security problems:

CVE-2007-2829: The 802.11 network stack in
net80211/ieee80211_input.c in MadWifi before 0.9.3.1 allows
remote attackers to cause a denial of service (system hang)
via a crafted length field in nested 802.3 Ethernet frames
in Fast Frame packets, which results in a NULL pointer
dereference.

CVE-2007-2830: The ath_beacon_config function in if_ath.c
in MadWifi before 0.9.3.1 allows remote attackers to cause
a denial of service (system crash) via crafted beacon
interval information when scanning for access points, which
triggers a divide-by-zero error.

CVE-2007-2831: Array index error in the (1)
ieee80211_ioctl_getwmmparams and (2)
ieee80211_ioctl_setwmmparams functions in
net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1
allows local users to cause a denial of service (system
crash), possibly obtain kernel memory contents, and
possibly execute arbitrary code via a large negative array
index value.

&quot;remote attackers&quot; are attackers within range of the WiFi
reception of the card.

Please note that the problems fixed in 0.9.3 were fixed by
the madwifi Version upgrade to 0.9.3 in SLE10 Service Pack
1. (CVE-2005-4835, CVE-2006-7177, CVE-2006-7178,
CVE-2006-7179, CVE-2006-7180).
</description>
  <yum:version ver="3897" rel="0"/>
  <rpm:requires>
    <rpm:entry kind="atom" name="madwifi" epoch="0" ver="0.9.3" rel="6.11" flags="EQ"/>
    <rpm:entry kind="atom" name="madwifi-devel" epoch="0" ver="0.9.3" rel="6.11" flags="EQ"/>
  </rpm:requires>
  <category>security</category>
  <atoms>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>madwifi</name>
      <arch>i586</arch>
      <version epoch="0" ver="0.9.3" rel="6.11"/>
      <checksum type="sha" pkgid="YES">87c7faab379571650685c6b10636ff804b516bf7</checksum>
      <time file="1184666229" build="1184574189"/>
      <size package="47429" installed="91375" archive="94032"/>
      <location xml:base="media://#1" href="suse/i586/madwifi-0.9.3-6.14.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="madwifi" epoch="0" ver="0.9.3" rel="6.11" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="madwifi"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
    <package xmlns="http://linux.duke.edu/metadata/common" type="rpm">
      <name>madwifi-devel</name>
      <arch>i586</arch>
      <version epoch="0" ver="0.9.3" rel="6.11"/>
      <checksum type="sha" pkgid="YES">d2c98edf7c912abde83f89a012f03bdf2cb5f9d2</checksum>
      <time file="1184666230" build="1184574189"/>
      <size package="57973" installed="240632" archive="244644"/>
      <location xml:base="media://#1" href="suse/i586/madwifi-devel-0.9.3-6.14.i586.rpm"/>
      <format>
        <rpm:requires>
          <rpm:entry kind="package" name="madwifi-devel" epoch="0" ver="0.9.3" rel="6.11" flags="GE"/>
        </rpm:requires>
        <suse:freshens>
          <suse:entry kind="package" name="madwifi-devel"/>
        </suse:freshens>
      </format>
      <pkgfiles xmlns="http://novell.com/package/metadata/suse/patch">
      </pkgfiles>
    </package>
  </atoms>
</patch>
