This Metasploit module exploits a stack-based buffer overflow in the Madwifi driver.
0754c28ffae1c6acf4d1bb93d5f0ef0b22f7d54c1e399116520b529c45ac5417
Ubuntu Security Notice 404-1 - Laurent Butti, Jerome Razniewski, and Julien Tinnes discovered that the MadWifi wireless driver did not correctly check packet contents when receiving scan replies. A remote attacker could send a specially crafted packet and execute arbitrary code with root privileges.
e5d647388f32d6aae84a6bd05bc45f6e06ca672b4252d0241fd92a444119957a
There is a buffer overflow in the Madwifi Atheros driver in some functions called by SIOCSIWSCAN ioctl.
ae78388667ab3deb4319d8f83bc674032a7c7b8df47d26ab5490c18a34bceb0c