PT-2015-2755 · Hostap+3 · Hostapd+3
Publicado
2015-11-09
·
Atualizado
2024-06-15
·
CVE-2015-8041
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
hostapd versions prior to 2.5
wpa supplicant versions prior to 2.5
Description
The issue is related to multiple integer overflows in the NDEF record parser, which can be exploited by remote attackers to cause a denial of service, such as a process crash or infinite loop. This can be achieved by sending a large payload length field value in a WPS or P2P NFC NDEF record, resulting in an out-of-bounds read. The exploitation of these vulnerabilities may allow a remote attacker to cause a denial of service by setting too large values in the WPS or P2P NFC NDEF fields.
Recommendations
For hostapd versions prior to 2.5, update to version 2.5 or later to resolve the issue.
For wpa supplicant versions prior to 2.5, update to version 2.5 or later to resolve the issue.
As a temporary workaround, consider restricting access to WPS and P2P NFC NDEF records to minimize the risk of exploitation.
Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Hostapd
Wpa Supplicant