The ath_beacon_config function in if_ath.c in MadWifi before 0.9.3.1 allows remote attackers to cause a denial of service (system crash) via crafted beacon interval information when scanning for access points, which triggers a divide-by-zero error.
- http://www.novell.com/linux/security/advisories/2007_14_sr.html
No PoCs found on GitHub currently.