ID

VAR-201211-0020


CVE

CVE-2012-2619


TITLE

Broadcom BCM4325 and BCM4329 wireless chipset denial-of-service vulnerability

Trust: 0.8

sources: CERT/CC: VU#160027

DESCRIPTION

The Broadcom BCM4325 and BCM4329 Wi-Fi chips, as used in certain Acer, Apple, Asus, Ford, HTC, Kyocera, LG, Malata, Motorola, Nokia, Pantech, Samsung, and Sony products, allow remote attackers to cause a denial of service (out-of-bounds read and Wi-Fi outage) via an RSN 802.11i information element. Broadcom BCM4325 and BCM4329 wireless chipsets have been reported to contain an out-of-bounds read error condition that may be exploited to produce a denial-of-service condition. Broadcom Multiple products that use wireless chipset made of service disruption (DoS) Vulnerabilities exist. Broadcom Multiple wireless chipset firmware provided by the (DoS) Vulnerabilities exist.Service disruption by a third party (DoS) There is a possibility of being attacked. The BCM4325 and BCM4329 chips are used in a variety of mobile device chips. An attacker can send an RSN (802.11i) information element that can cause the Wi-Fi NIC to stop responding. The following products use BCM4325 and BCM4329 chips: BCM4325 Apple iPhone 3GS Apple iPod 2GHTC Touch Pro 2HTC Droid IncredibleSamsung SpicaAcer LiquidMotorola DevourFord Edge BCM4329Apple iPhone 4Apple iPhone 4 VerizonApple iPod 3GApple iPad Wi-FiApple iPad 3GApple iPad 2Apple Tv 2GMotorola XoomMotorola Droid X2Motorola AtrixSamsung Galaxy TabSamsung Galaxy S 4GSamsung Nexus SSamsung StratosphereSamsung FascinateHTC Nexus OneHTC Evo 4GHTC ThunderBoltHTC Droid Incredible 2LG RevolutionSony Ericsson Xperia PlayPantech BreakoutNokia Lumina 800Kyocera EchoAsus Transformer PrimeMalata ZPad. Broadcom BCM4325 and BCM4329 Wireless Chipsets are prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause an affected device to crash, denying service to legitimate users. Due to the nature of this issue, sensitive information may be obtained. The following Chipsets are vulnerable: BCM4325 BCM4329. Broadcom is the world's leading semiconductor company for wired and wireless communications. Vulnerabilities exist in Chipsets BCM4325 and BCM4329 versions. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2013-01-28-1 iOS 6.1 Software Update iOS 6.1 Software Update is now available and addresses the following: Identity Services Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Authentication relying on certificate-based Apple ID authentication may be bypassed Description: An error handling issue existed in Identity Services. If the user's AppleID certificate failed to validate, the user's AppleID was assumed to be the empty string. If multiple systems belonging to different users enter this state, applications relying on this identity determination may erroneously extend trust. This issue was addressed by ensuring that NULL is returned instead of an empty string. CVE-ID CVE-2013-0963 International Components for Unicode Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack Description: A canonicalization issue existed in the handling of the EUC-JP encoding, which could lead to a cross-site scripting attack on EUC-JP encoded websites. This issue was addressed by updating the EUC-JP mapping table. CVE-ID CVE-2011-3058 : Masato Kinugawa Kernel Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: A user-mode process may be able to access the first page of kernel memory Description: The iOS kernel has checks to validate that the user- mode pointer and length passed to the copyin and copyout functions would not result in a user-mode process being able to directly access kernel memory. The checks were not being used if the length was smaller than one page. This issue was addressed through additional validation of the arguments to copyin and copyout. CVE-ID CVE-2013-0964 : Mark Dowd of Azimuth Security Security Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: An attacker with a privileged network position may intercept user credentials or other sensitive information Description: Several intermediate CA certificates were mistakenly issued by TURKTRUST. This may allow a man-in-the-middle attacker to redirect connections and intercept user credentials or other sensitive information. This issue was addressed by not allowing the incorrect SSL certificates. StoreKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: JavaScript may be enabled in Mobile Safari without user interaction Description: If a user disabled JavaScript in Safari Preferences, visiting a site which displayed a Smart App Banner would re-enable JavaScript without warning the user. This issue was addressed by not enabling JavaScript when visiting a site with a Smart App Banner. CVE-ID CVE-2013-0974 : Andrew Plotkin of Zarfhome Software Consulting, Ben Madison of BitCloud, Marek Durcek WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution Description: Multiple memory corruption issues existed in WebKit. These issues were addressed through improved memory handling. CVE-ID CVE-2012-2824 : miaubiz CVE-2012-2857 : Arthur Gerkis CVE-2012-3606 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3607 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3621 : Skylined of the Google Chrome Security Team CVE-2012-3632 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2012-3687 : kuzzcc CVE-2012-3701 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0948 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0949 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0950 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0951 : Apple CVE-2013-0952 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0953 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0954 : Dominic Cooney of Google and Martin Barbella of the Google Chrome Security Team CVE-2013-0955 : Apple CVE-2013-0956 : Apple Product Security CVE-2013-0958 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0959 : Abhishek Arya (Inferno) of the Google Chrome Security Team CVE-2013-0968 : Aaron Nelson WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Copying and pasting content on a malicious website may lead to a cross-site scripting attack Description: A cross-site scripting issue existed in the handling of content pasted from a different origin. This issue was addressed through additional validation of pasted content. CVE-ID CVE-2013-0962 : Mario Heiderich of Cure53 WebKit Available for: iPhone 3GS and later, iPod touch (4th generation) and later, iPad 2 and later Impact: Visiting a maliciously crafted website may lead to a cross- site scripting attack Description: A cross-site scripting issue existed in the handling of frame elements. This issue was addressed through improved origin tracking. CVE-ID CVE-2012-2889 : Sergey Glazunov WiFi Available for: iPhone 3GS, iPhone 4, iPod touch (4th generation), iPad 2 Impact: A remote attacker on the same WiFi network may be able to temporarily disable WiFi Description: An out of bounds read issue exists in Broadcom's BCM4325 and BCM4329 firmware's handling of 802.11i information elements. This issue was addressed through additional validation of 802.11i information elements. CVE-ID CVE-2012-2619 : Andres Blanco and Matias Eissler of Core Security Installation note: This update is available through iTunes and Software Update on your iOS device, and will not appear in your computer's Software Update application, or in the Apple Downloads site. Make sure you have an Internet connection and have installed the latest version of iTunes from www.apple.com/itunes/ iTunes and Software Update on the device will automatically check Apple's update server on its weekly schedule. When an update is detected, it is downloaded and the option to be installed is presented to the user when the iOS device is docked. We recommend applying the update immediately if possible. Selecting Don't Install will present the option the next time you connect your iOS device. The automatic update process may take up to a week depending on the day that iTunes or the device checks for updates. You may manually obtain the update via the Check for Updates button within iTunes, or the Software Update on your device. To check that the iPhone, iPod touch, or iPad has been updated: * Navigate to Settings * Select General * Select About. The version after applying this update will be "6.1". Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJRBffvAAoJEPefwLHPlZEwzYgP/0qhsTft9TUGuphoY9tth5WB D0+8pAKs+1HU+nMOaEKPbK+zdMxblhRNPQyhMuTAQaY5Z/iGn1EXVCTlQBO8esRW epxNZuhFoaW4wzK9kvw5d/HZ9tfq059ozlFOp1TI2D6J5RwNgxDfigt2PUKCTV4X u/BONQHIfINYMofgf5897LHYYFSU2+NJj5ouM5dY4Y/kfJkwAnG5AWCAGlEt3QOo MZdaVv3/itPj4te838FYCVAepel3xBWX0Hhuu87+waHslRrIfQl+EvNk3YZXxWiF O5Hw9Ng/H8n0sbeA39w0U8tw+q/wPhVexdULgRjBH65+6g7Cu5u+rMuYuRjl8fO/ glLhKZNSrQDa5ZNOraOrF62AFVByHaSxv4cZwo262/6uH93FIBtklMt947GMVQLC 1FT0CIGNJb1/0156bvsABfRScBtK9ZdIUjXhOHMinhQJX3qiBqyKc4/juYPmC9VC KXk2/K8b0sGWQRc5RuQsSpzkZF9WcrwmgGOBIghp2DLmbAAj0uh2Ttf1GdrOaajR XpZ2TTJ5qE+IHNU0/etroTYnzjKVjQ0pODrPZj7ALLXULTraXJRJy7fqraUzsHbi AZiRca+3x/S9nqV0NpTNPZgTwxenox10t0w5vhcBK+SPGga1oVRbtOjGtVIkgoG4 KI3sdgb6PtpZWuIJ6iZA =J2jv -----END PGP SIGNATURE-----

Trust: 3.42

sources: NVD: CVE-2012-2619 // CERT/CC: VU#160027 // JVNDB: JVNDB-2012-005120 // CNVD: CNVD-2012-6066 // BID: 56184 // VULHUB: VHN-55900 // PACKETSTORM: 119897 // PACKETSTORM: 119898

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

category:['other device']sub_category:general

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2012-6066

AFFECTED PRODUCTS

vendor:applemodel:iphone osscope:eqversion:6.0.1

Trust: 1.6

vendor:applemodel:iphone osscope:eqversion:6.0

Trust: 1.6

vendor:broadcommodel:bcm4329scope:eqversion:*

Trust: 1.0

vendor:applemodel:iphone osscope:lteversion:6.0.2

Trust: 1.0

vendor:broadcommodel:bcm4325scope:eqversion:*

Trust: 1.0

vendor:applemodel: - scope: - version: -

Trust: 0.8

vendor:broadcommodel: - scope: - version: -

Trust: 0.8

vendor:htcmodel: - scope: - version: -

Trust: 0.8

vendor:broadcommodel:bcm4325scope: - version: -

Trust: 0.8

vendor:broadcommodel:bcm4329scope: - version: -

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (ipad 2)

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (iphone 3gs)

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (iphone 4)

Trust: 0.8

vendor:applemodel:iosscope:ltversion:6.1 (ipod touch first 4 generation )

Trust: 0.8

vendor:broadcommodel:bcm4325/bcm4329scope: - version: -

Trust: 0.6

vendor:applemodel:iphone osscope:eqversion:6.0.2

Trust: 0.6

vendor:applemodel:tvscope:eqversion:5.0

Trust: 0.3

sources: CERT/CC: VU#160027 // CNVD: CNVD-2012-6066 // BID: 56184 // JVNDB: JVNDB-2012-005120 // CNNVD: CNNVD-201210-545 // NVD: CVE-2012-2619

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2012-2619
value: HIGH

Trust: 1.0

NVD: CVE-2012-2619
value: MEDIUM

Trust: 0.8

NVD: CVE-2012-2619
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201210-545
value: HIGH

Trust: 0.6

VULHUB: VHN-55900
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2012-2619
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2012-2619
severity: MEDIUM
baseScore: 6.1
vectorString: NONE
accessVector: ADJACENT NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 6.5
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-55900
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#160027 // VULHUB: VHN-55900 // JVNDB: JVNDB-2012-005120 // CNNVD: CNNVD-201210-545 // NVD: CVE-2012-2619

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-55900 // JVNDB: JVNDB-2012-005120 // NVD: CVE-2012-2619

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201210-545

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201210-545

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-005120

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#160027 // VULHUB: VHN-55900

PATCH

title:HT5642url:http://support.apple.com/kb/HT5642

Trust: 0.8

title:HT5642url:http://support.apple.com/kb/HT5642?viewlocale=ja_JP

Trust: 0.8

title:Top Pageurl:http://www.broadcom.com/

Trust: 0.8

title:Broadcom BCM4325 and BCM4329 Wireless Chips Cross-Boundary Read Denial of Service Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/24193

Trust: 0.6

sources: CNVD: CNVD-2012-6066 // JVNDB: JVNDB-2012-005120

EXTERNAL IDS

db:CERT/CCid:VU#160027

Trust: 3.9

db:NVDid:CVE-2012-2619

Trust: 3.7

db:BIDid:56184

Trust: 1.0

db:JVNDBid:JVNDB-2012-005120

Trust: 0.8

db:CNNVDid:CNNVD-201210-545

Trust: 0.7

db:CNVDid:CNVD-2012-6066

Trust: 0.6

db:PACKETSTORMid:119898

Trust: 0.2

db:OTHERid:NONE

Trust: 0.1

db:PACKETSTORMid:118150

Trust: 0.1

db:EXPLOIT-DBid:22739

Trust: 0.1

db:SEEBUGid:SSVID-76537

Trust: 0.1

db:VULHUBid:VHN-55900

Trust: 0.1

db:PACKETSTORMid:119897

Trust: 0.1

sources: OTHER: None // CERT/CC: VU#160027 // CNVD: CNVD-2012-6066 // VULHUB: VHN-55900 // BID: 56184 // JVNDB: JVNDB-2012-005120 // PACKETSTORM: 119897 // PACKETSTORM: 119898 // CNNVD: CNNVD-201210-545 // NVD: CVE-2012-2619

REFERENCES

url:http://www.kb.cert.org/vuls/id/160027

Trust: 2.5

url:http://support.apple.com/kb/ht5642

Trust: 1.9

url:http://www.coresecurity.com/content/broadcom-input-validation-bcm4325-bcm4329

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2013/jan/msg00000.html

Trust: 1.1

url:http://lists.apple.com/archives/security-announce/2013/jan/msg00001.html

Trust: 1.1

url:http://support.apple.com/kb/ht5643

Trust: 1.1

url:about vulnerability notes

Trust: 0.8

url:contact us about this vulnerability

Trust: 0.8

url:provide a vendor statement

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-2619

Trust: 0.8

url:http://jvn.jp/cert/jvnvu160027/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-2619

Trust: 0.8

url:http://www.kb.cert.org/vuls/id/160027http

Trust: 0.6

url:http://www.securityfocus.com/bid/56184

Trust: 0.6

url:http://www.broadcom.com/products/wireless-lan

Trust: 0.3

url:http://support.apple.com/kb/ht1222

Trust: 0.2

url:https://www.apple.com/support/security/pgp/

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2012-2619

Trust: 0.2

url:http://gpgtools.org

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-0964

Trust: 0.2

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

url:https://www.apple.com/itunes/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0956

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3687

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0954

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0955

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0948

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2889

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3621

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0959

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0952

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0958

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3701

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0949

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0962

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0968

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3058

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2857

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0950

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0951

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0974

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2824

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0953

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3606

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3607

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0963

Trust: 0.1

sources: OTHER: None // CERT/CC: VU#160027 // CNVD: CNVD-2012-6066 // VULHUB: VHN-55900 // BID: 56184 // JVNDB: JVNDB-2012-005120 // PACKETSTORM: 119897 // PACKETSTORM: 119898 // CNNVD: CNNVD-201210-545 // NVD: CVE-2012-2619

CREDITS

Andres Blanco and Matias Eissler

Trust: 0.9

sources: BID: 56184 // CNNVD: CNNVD-201210-545

SOURCES

db:OTHERid: -
db:CERT/CCid:VU#160027
db:CNVDid:CNVD-2012-6066
db:VULHUBid:VHN-55900
db:BIDid:56184
db:JVNDBid:JVNDB-2012-005120
db:PACKETSTORMid:119897
db:PACKETSTORMid:119898
db:CNNVDid:CNNVD-201210-545
db:NVDid:CVE-2012-2619

LAST UPDATE DATE

2025-04-11T20:19:04.063000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#160027date:2013-01-28T00:00:00
db:CNVDid:CNVD-2012-6066date:2012-10-25T00:00:00
db:VULHUBid:VHN-55900date:2013-02-05T00:00:00
db:BIDid:56184date:2013-01-28T21:10:00
db:JVNDBid:JVNDB-2012-005120date:2013-02-06T00:00:00
db:CNNVDid:CNNVD-201210-545date:2012-10-25T00:00:00
db:NVDid:CVE-2012-2619date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#160027date:2012-10-23T00:00:00
db:CNVDid:CNVD-2012-6066date:2012-10-25T00:00:00
db:VULHUBid:VHN-55900date:2012-11-14T00:00:00
db:BIDid:56184date:2012-10-23T00:00:00
db:JVNDBid:JVNDB-2012-005120date:2012-10-25T00:00:00
db:PACKETSTORMid:119897date:2013-01-30T02:53:29
db:PACKETSTORMid:119898date:2013-01-30T02:58:08
db:CNNVDid:CNNVD-201210-545date:2012-10-25T00:00:00
db:NVDid:CVE-2012-2619date:2012-11-14T12:30:58.740