The Linux Orinoco driver, included in the kernel since 2.4.3 and in David Hinds' pcmcia-cs package since 3.1.30 supports a large number of wireless NICs based on the Lucent/Agere Hermes, Symbol Spectrum24 and Intersil/Conexant Prism 2/2.5/3 chipsets.
Vulnerability in Orinoco Drivers allows Information Leakage.
Attacker can use arping(8) to send ARP requests to the target running vulnerable orinoco drivers and observe contents of uninitialized memory in the ARP replies.
Vendor status:
Developers of linux orinoco drivers where notified and the fix, which has been incorporated into 2.6.13.4 kernel, was issued.
Disclosure Timeline:
04.10.05 - Issue discovered. Vendor notified.
04.10.05 - Vendor response received along with the patch to remedy the problem.
10.10.05 - Confirmed that patch was incorporated into 2.6.13.4 kernel.