Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-1863

Опубликовано: 22 апр. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.

A buffer overflow flaw was found in the way wpa_supplicant handled SSID information in the Wi-Fi Direct / P2P management frames. A specially crafted frame could allow an attacker within Wi-Fi radio range to cause wpa_supplicant to crash or, possibly, execute arbitrary code.

Отчет

This issue did not affect the wpa_supplicant versions as shipped with Red Hat Enterprise Linux 5 and 6.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5wpa_supplicantNot affected
Red Hat Enterprise Linux 6wpa_supplicantNot affected
Red Hat Enterprise Linux 7wpa_supplicantFixedRHSA-2015:109011.06.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1211191wpa_supplicant: P2P SSID processing vulnerability

EPSS

Процентиль: 90%
0.05376
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.

nvd
больше 10 лет назад

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.

debian
больше 10 лет назад

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows re ...

github
больше 3 лет назад

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.

oracle-oval
около 10 лет назад

ELSA-2015-1090: wpa_supplicant security and enhancement update (IMPORTANT)

EPSS

Процентиль: 90%
0.05376
Низкий

6.8 Medium

CVSS2