PT-2016-5970 · Hostap+1 · Wpa Supplicant+1
Imre Rad
·
Published
2016-05-09
·
Updated
2024-06-15
·
CVE-2016-4477
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wpa supplicant versions 0.4.0 through 2.5
Description
The issue allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service, via a crafted command. This is possible because
wpa supplicant does not reject and r characters in passphrase parameters. Specifically, the vulnerability can be exploited through a crafted (1) SET, (2) SET CRED, or (3) SET NETWORK command.Recommendations
For wpa supplicant versions 0.4.0 through 2.5, consider updating to a version that rejects
and r characters in passphrase parameters to prevent arbitrary library loading and potential privilege escalation or denial of service. As a temporary workaround, restrict access to the SET, SET CRED, and SET NETWORK commands to minimize the risk of exploitation. Avoid using the passphrase parameter with untrusted input in the affected commands until the issue is resolved.Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ubuntu
Wpa Supplicant