Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27803

Опубликовано: 25 фев. 2021
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.

A flaw was found in the wpa_supplicant, in the way it processes P2P (Wi-Fi Direct) provision discovery requests. This flaw allows an attacker who is within radio range of the device running P2P discovery to cause termination of the wpa_supplicant process or potentially cause code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Отчет

An attacker (or a system controlled by the attacker) needs to be within radio range of the vulnerable system to send a set of suitably constructed management frames that trigger the corner case to be reached in the management of the P2P peer table.

Меры по смягчению последствий

Disable the P2P (control interface command "P2P_SET disabled 1" or "p2p_disabled=1" in (each, if multiple interfaces used) wpa_supplicant configuration file)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wpa_supplicantNot affected
Red Hat Enterprise Linux 9wpa_supplicantNot affected
Red Hat Enterprise Linux 7wpa_supplicantFixedRHSA-2021:080810.03.2021
Red Hat Enterprise Linux 8wpa_supplicantFixedRHSA-2021:080911.03.2021
Red Hat Enterprise Linux 8.1 Extended Update Supportwpa_supplicantFixedRHSA-2021:081815.03.2021
Red Hat Enterprise Linux 8.2 Extended Update Supportwpa_supplicantFixedRHSA-2021:081615.03.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1933361wpa_supplicant: Use-after-free in P2P provision discovery processing

EPSS

Процентиль: 53%
0.00298
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.

CVSS3: 7.5
nvd
почти 5 лет назад

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.

CVSS3: 7.5
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.5
debian
почти 5 лет назад

A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant b ...

suse-cvrf
почти 5 лет назад

Security update for wpa_supplicant

EPSS

Процентиль: 53%
0.00298
Низкий

7.5 High

CVSS3