rpm package
suse/wpa_supplicant&distro=SUSE Linux Enterprise Desktop 12 SP1
pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2015-5310 | Med | 4.3 | < 2.2-14.2 | 2.2-14.2 | Jan 6, 2016 | The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service ( | |
| CVE-2015-8041 | — | < 2.2-14.2 | 2.2-14.2 | Nov 9, 2015 | Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a denial of service (process crash or infinite loop) via a large payload length field value in an (1) WPS or (2) P2P NFC NDEF record, which tri | ||
| CVE-2015-4143 | — | < 2.2-14.2 | 2.2-14.2 | Jun 15, 2015 | The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message payload. | ||
| CVE-2015-4142 | — | < 2.2-14.2 | 2.2-14.2 | Jun 15, 2015 | Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read | ||
| CVE-2015-4141 | — | < 2.2-14.2 | 2.2-14.2 | Jun 15, 2015 | The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer o |
- affected < 2.2-14.2fixed 2.2-14.2
The WNM Sleep Mode code in wpa_supplicant 2.x before 2.6 does not properly ignore key data in response frames when management frame protection (MFP) was not negotiated, which allows remote attackers to inject arbitrary broadcast or multicast packets or cause a denial of service (
- CVE-2015-8041Nov 9, 2015affected < 2.2-14.2fixed 2.2-14.2
Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a denial of service (process crash or infinite loop) via a large payload length field value in an (1) WPS or (2) P2P NFC NDEF record, which tri
- CVE-2015-4143Jun 15, 2015affected < 2.2-14.2fixed 2.2-14.2
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message payload.
- CVE-2015-4142Jun 15, 2015affected < 2.2-14.2fixed 2.2-14.2
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read
- CVE-2015-4141Jun 15, 2015affected < 2.2-14.2fixed 2.2-14.2
The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer o