You are here: silicon.com > Software > Security Strategy

Security Strategy

Intel patches Centrino flaws

Wireless worries...

Tags: flaw, centrino, intel

By Dawn Kawamoto

Published: 3 August 2006 08:30 BST

Intel has issued patches for flaws in its Centrino device drivers and ProSet management software that affect the security of the wireless products.

Three flaws are addressed with the updates. One could allow an attacker to break into a PC via wi-fi or even create a worm that jumps from one wireless-enabled laptop to another, provided the computers are within each other's range. Another security hole makes the system vulnerable to attacks that let a malicious user gain additional privileges, according to security experts at F-Secure and Sans Internet Storm Center.

Intel's patches address vulnerabilities in its Intel PRO/Wireless 2200BG, 2915ABG, 2100 and 3945ABG Network Connection products, according to a security advisory from the chipmaker.

The vulnerability involving the Intel Centrino wireless driver could allow attackers within range of a wi-fi station to access a vulnerable laptop and execute arbitrary code on the target system, according to the Intel advisory.

F-Secure notes the vulnerabilities involving the drivers are "pretty awful" and that the patch can be troublesome to download and install because of its size, 129MB.

Mikko Hypponen, chief research officer at F-Secure, said: "You have to manually install this patch, and it is unusually large. Most people, especially home users, may not know how to do it, since it is not that straightforward."

Intel offers a complete version of the software for the driver system, which means the download is relatively large, a representative for the chipmaker said.

Security experts note there are no known exploits publicly circulating that have been crafted to take advantage of these flaws.

Intel, meanwhile, provides a link to help users identify vulnerable systems and advises them to install the patches.

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Embedded C development - 802.11 / Bluetooth / Wi fi expertise

Embedded C developer required for this hardware interfacing contract where expertise in one of either 802.11, bluetooth or wi-fi expertise is ...

Systems Engineers

Intel-based servers (any brand) Build / configure / rack-mount, etc TCP/IP - Practical experience with DNS POP SMTP SNMP, etc Linux - Practical ...

SAP FI/CO Consultants - Great Career Prospects - SAP FICO

This is a great opportunity for aspiring SAP FI/CO experts to work in a leading Global Consultancy. Prestigious Global Consultancy is now urgently ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: