PT-2015-2729 · Wpa Supplicant+3 · Hostapd+4

Kostya Kortchinsky

·

Publicado

2015-06-01

·

Atualizado

2024-06-15

·

CVE-2015-4143

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions hostapd and wpa supplicant versions 1.0 through 2.4
Description The issue allows remote attackers to cause a denial of service, resulting in an out-of-bounds read and crash, via a crafted message payload. This can be achieved by sending a specially crafted (1) Commit or (2) Confirm message. The problem is caused by a buffer overflow in the EAP-pwd server and peer implementation.
Recommendations For hostapd and wpa supplicant versions 1.0 through 2.4, consider disabling the EAP-pwd functionality until a patch is available to prevent remote attackers from exploiting this issue. Restrict access to the EAP-pwd server and peer implementation to minimize the risk of exploitation. Avoid using crafted message payloads in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1915
ALT-PU-2016-1916
BDU:2015-12094
CVE-2015-4143
DSA-3397-1
OPENSUSE-SU-2017_2896-1
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:10022-1
OPENSUSE-SU-2024:10499-1
SUSE-SU-2016:2305-1
SUSE-SU-2020:3380-1
USN-2650-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Hostapd
Wpa Supplicant