CVE-2015-4142
Publication date 1 June 2015
Last updated 24 July 2024
Ubuntu priority
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
Status
Package | Ubuntu Release | Status |
---|---|---|
hostapd | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
wpa | ||
16.04 LTS xenial |
Fixed 2.1-0ubuntu8
|
|
14.04 LTS trusty |
Fixed 2.1-0ubuntu1.3
|
|
wpasupplicant | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
hostapd | |
wpa | |
wpasupplicant |
References
Related Ubuntu Security Notices (USN)
- USN-2650-1
- wpa_supplicant and hostapd vulnerabilities
- 16 June 2015