PT-2016-5969 · Hostap+4 · Hostapd+4
Imre Rad
·
Published
2016-05-09
·
Updated
2024-06-15
·
CVE-2016-4476
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
hostapd versions 0.6.7 through 2.5
wpa supplicant versions 0.6.7 through 2.5
Description
The issue allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation, due to the failure to reject
and r characters in passphrase parameters.Recommendations
For hostapd versions 0.6.7 through 2.5, consider disabling WPS operations until a patch is available.
For wpa supplicant versions 0.6.7 through 2.5, restrict the use of passphrase parameters to minimize the risk of exploitation.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Hostapd
Wpa Supplicant