// For flags

CVE-2010-1159

Aircrack-NG Tools svn r1675 - Remote Heap Buffer Overflow (PoC)

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet or (2) long EAPOL packet.

Múltiples desbordamientos de buffer basados en memoria dinámica en Aircrack-ng anteriores a 1.1 permiten a atacantes remotos causar denegación de servicio (caída) y ejecutar código arbitrario a través de (1) un valor grande en un paquete EAPOL o (2) un paquete EAPOL grande.

A buffer overflow vulnerability has been discovered in Aircrack-ng. A remote attacker could entice a user to open a specially crafted dump file using Aircrack-ng, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-03-29 CVE Reserved
  • 2010-04-14 First Exploit
  • 2013-10-07 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
<= 1.0
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version " <= 1.0"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.1
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.1"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.2
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.2"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.2.1
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.2.1"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.3
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.3"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.4
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.4"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.4.1
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.4.1"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.4.2
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.4.2"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.4.3
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.4.3"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.4.4
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.4.4"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.5
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.5"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.6
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.6"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.6.1
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.6.1"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.6.2
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.6.2"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.7
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.7"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.8
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.8"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.9
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.9"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.9.1
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.9.1"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.9.2
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.9.2"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
0.9.3
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "0.9.3"
-
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
1.0
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "1.0"
beta1
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
1.0
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "1.0"
beta2
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
1.0
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "1.0"
rc1
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
1.0
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "1.0"
rc2
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
1.0
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "1.0"
rc3
Affected
Aircrack-ng
Search vendor "Aircrack-ng"
Aircrack-ng
Search vendor "Aircrack-ng" for product "Aircrack-ng"
1.0
Search vendor "Aircrack-ng" for product "Aircrack-ng" and version "1.0"
rc4
Affected
Gentoo
Search vendor "Gentoo"
Linux
Search vendor "Gentoo" for product "Linux"
*-
Affected