The bug can be triggered thanks to a malformed association request which is typically too short (truncated). Any association request sent in the air by the attacker will be parsed by the access point wireless driver and thus may trigger some implementation bugs. This bug is only triggerable when the access point is in WEP mode and if the association request contains the WEP flag.
Impact:
Denial-of-service (reboot or hang-up) and possibly remote arbitrary code execution