4.3
CVSSv2

CVE-2015-4141

Published: 15/06/2015 Updated: 30/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 up to and including 2.4 allows remote malicious users to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

w1.fi wpa supplicant 1.1

w1.fi wpa supplicant 2.0

w1.fi wpa supplicant 0.7.3

w1.fi wpa supplicant 1.0

w1.fi wpa supplicant 0.7.1

w1.fi wpa supplicant 0.7.2

w1.fi wpa supplicant 2.3

w1.fi wpa supplicant 2.4

w1.fi wpa supplicant 0.7.0

w1.fi wpa supplicant 2.1

w1.fi wpa supplicant 2.2

w1.fi hostapd 0.7.2

w1.fi hostapd 0.7.3

w1.fi hostapd 2.4

w1.fi hostapd 0.7.0

w1.fi hostapd 0.7.1

w1.fi hostapd 2.2

w1.fi hostapd 2.3

w1.fi hostapd 2.0

w1.fi hostapd 2.1

w1.fi hostapd 1.0

w1.fi hostapd 1.1

opensuse opensuse 13.1

opensuse opensuse 13.2

Vendor Advisories

wpa_supplicant and hostapd could be made to crash if they received specially crafted network traffic ...
Debian Bug report logs - #787371 wpa: CVE-2015-4143 CVE-2015-4144 CVE-2015-4145 CVE-2015-4146: EAP-pwd missing payload length validation Package: src:wpa; Maintainer for src:wpa is Debian wpasupplicant Maintainers <wpa@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 31 May 2015 2 ...
Debian Bug report logs - #787372 wpa: CVE-2015-4141: WPS UPnP vulnerability with HTTP chunked transfer encoding Package: src:wpa; Maintainer for src:wpa is Debian wpasupplicant Maintainers <wpa@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 31 May 2015 20:42:02 UTC Severity: im ...
Debian Bug report logs - #795740 wpa: CVE-2015-8041: Incomplete WPS and P2P NFC NDEF record payload length validation Package: src:wpa; Maintainer for src:wpa is Debian wpasupplicant Maintainers <wpa@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 16 Aug 2015 14:45:02 UTC Severi ...
Debian Bug report logs - #787373 wpa: CVE-2015-4142: Integer underflow in AP mode WMM Action frame processing Package: src:wpa; Maintainer for src:wpa is Debian wpasupplicant Maintainers <wpa@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 31 May 2015 20:42:06 UTC Severity: impo ...
The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 070 through 24 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow ...