PT-2016-5970 · Hostap+1 · Wpa Supplicant+1

Imre Rad

·

Published

2016-05-09

·

Updated

2024-06-15

·

CVE-2016-4477

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions wpa supplicant versions 0.4.0 through 2.5
Description The issue allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service, via a crafted command. This is possible because wpa supplicant does not reject and r characters in passphrase parameters. Specifically, the vulnerability can be exploited through a crafted (1) SET, (2) SET CRED, or (3) SET NETWORK command.
Recommendations For wpa supplicant versions 0.4.0 through 2.5, consider updating to a version that rejects and r characters in passphrase parameters to prevent arbitrary library loading and potential privilege escalation or denial of service. As a temporary workaround, restrict access to the SET, SET CRED, and SET NETWORK commands to minimize the risk of exploitation. Avoid using the passphrase parameter with untrusted input in the affected commands until the issue is resolved.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4477
DLA-473-1
MGASA-2016-0199
OPENSUSE-SU-2024:10499-1
USN-3455-1

Affected Products

Ubuntu
Wpa Supplicant