VYPR

rpm package

suse/wpa_supplicant&distro=SUSE Linux Enterprise Server 11 SP4

pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4

Vulnerabilities (9)

  • CVE-2017-13088MedOct 17, 2017
    affected < 0.7.1-6.18.3.1fixed 0.7.1-6.18.3.1

    Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points t

  • CVE-2017-13087MedOct 17, 2017
    affected < 0.7.1-6.18.3.1fixed 0.7.1-6.18.3.1

    Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.

  • CVE-2017-13081MedOct 17, 2017
    affected < 0.7.1-6.18.3.1fixed 0.7.1-6.18.3.1

    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.

  • CVE-2017-13080MedOct 17, 2017
    affected < 0.7.1-6.18.3.1fixed 0.7.1-6.18.3.1

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.

  • CVE-2017-13079MedOct 17, 2017
    affected < 0.7.1-6.18.3.1fixed 0.7.1-6.18.3.1

    Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.

  • CVE-2017-13078MedOct 17, 2017
    affected < 0.7.1-6.18.3.1fixed 0.7.1-6.18.3.1

    Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.

  • CVE-2015-0210MedAug 28, 2017
    affected < 0.7.1-6.18.6.1fixed 0.7.1-6.18.6.1

    wpa_supplicant 2.0-16 does not properly check certificate subject name, which allows remote attackers to cause a man-in-the-middle attack.

  • CVE-2015-4142Jun 15, 2015
    affected < 0.7.1-6.17.4fixed 0.7.1-6.17.4

    Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read

  • CVE-2015-4141Jun 15, 2015
    affected < 0.7.1-6.17.4fixed 0.7.1-6.17.4

    The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer o