PT-2016-5970 · Hostap+1 · Wpa Supplicant+1
Imre Rad
·
Publicado
2016-05-09
·
Atualizado
2024-06-15
·
CVE-2016-4477
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wpa supplicant versions 0.4.0 through 2.5
Description
The issue allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service, via a crafted command. This is possible because
wpa supplicant does not reject and r characters in passphrase parameters. Specifically, the vulnerability can be exploited through a crafted (1) SET, (2) SET CRED, or (3) SET NETWORK command.Recommendations
For wpa supplicant versions 0.4.0 through 2.5, consider updating to a version that rejects
and r characters in passphrase parameters to prevent arbitrary library loading and potential privilege escalation or denial of service. As a temporary workaround, restrict access to the SET, SET CRED, and SET NETWORK commands to minimize the risk of exploitation. Avoid using the passphrase parameter with untrusted input in the affected commands until the issue is resolved.Correção
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ubuntu
Wpa Supplicant