Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-4477

Опубликовано: 09 мая 2016
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.4
CVSS3: 7.8

Описание

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

released

2.4-0ubuntu10
bionic

released

2.4-0ubuntu10
cosmic

released

2.4-0ubuntu10
devel

released

2.4-0ubuntu10
disco

released

2.4-0ubuntu10
eoan

released

2.4-0ubuntu10
esm-infra-legacy/trusty

released

2.1-0ubuntu1.5
esm-infra/bionic

released

2.4-0ubuntu10
esm-infra/focal

released

2.4-0ubuntu10
esm-infra/xenial

released

2.4-0ubuntu6.2

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

EPSS

Процентиль: 33%
0.0013
Низкий

4.4 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
почти 10 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

CVSS3: 7.8
nvd
больше 9 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

CVSS3: 7.8
debian
больше 9 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters ...

CVSS3: 7.8
github
больше 3 лет назад

wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

EPSS

Процентиль: 33%
0.0013
Низкий

4.4 Medium

CVSS2

7.8 High

CVSS3