Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4477

Опубликовано: 09 мая 2016
Источник: nvd
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:o:google:android:4.4.4:*:*:*:*:*:*:*
cpe:2.3:o:google:android:5.0.2:*:*:*:*:*:*:*
cpe:2.3:o:google:android:5.1.1:*:*:*:*:*:*:*
cpe:2.3:o:google:android:6.0:*:*:*:*:*:*:*
cpe:2.3:o:google:android:6.0.1:*:*:*:*:*:*:*

EPSS

Процентиль: 33%
0.0013
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-19

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

CVSS3: 7
redhat
почти 10 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

CVSS3: 7.8
debian
больше 9 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters ...

CVSS3: 7.8
github
больше 3 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

EPSS

Процентиль: 33%
0.0013
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-19