ieee80211_output.c in MadWifi before 0.9.3 sends unencrypted packets before WPA authentication succeeds, which allows remote attackers to obtain sensitive information (related to network structure), and possibly cause a denial of service (disrupted authentication) and conduct spoofing attacks.
- http://www.novell.com/linux/security/advisories/2007_14_sr.html
No PoCs found on GitHub currently.