CVE-2015-4142
published 2015-06-15CVE-2015-4142: Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME…
PriorityP423medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.20%
89.8th percentile
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_15.5_and_ipados | — | — |
| debian | wpa | < wpa 2.3-2.2 (bookworm) | wpa 2.3-2.2 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | hostapd | — | — |
| w1.fi | wpa_supplicant | — | — |
| w1.fi | wpa_supplicant | — | — |
| w1.fi | wpa_supplicant | — | — |
| w1.fi | wpa_supplicant | — | — |
| w1.fi | wpa_supplicant | — | — |
| w1.fi | wpa_supplicant | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2015-4142: iOS 15.5 and iPadOS 15.5
vendor_apple·2022-05-16·CVSS 4.3
CVE-2015-4142 [MEDIUM] CVE-2015-4142: iOS 15.5 and iPadOS 15.5
Apple Security Update: About the security content of iOS 15.5 and iPadOS 15.5
Product: iOS 15.5 and iPadOS
Version: 15.5
CVE: CVE-2015-4142
Component: Wi-Fi
Impact: A remote attacker may be able to cause a denial of service
Description: This issue was addressed with improved checks.
Ubuntu
wpa_supplicant and hostapd vulnerabilities
vendor_ubuntu·2015-06-16·CVSS 4.3
CVE-2015-4141 [MEDIUM] wpa_supplicant and hostapd vulnerabilities
Title: wpa_supplicant and hostapd vulnerabilities
Summary: wpa_supplicant and hostapd could be made to crash if they received
specially crafted network traffic.
Kostya Kortchinsky discovered multiple flaws in wpa_supplicant and hostapd.
A remote attacker could use these issues to cause wpa_supplicant or hostapd
to crash, resulting in a denial of service. (CVE-2015-4141, CVE-2015-4142,
CVE-2015-4143, CVE-2015-4144, CVE-2015-4145, CVE-2015-4146)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
hostapd: integer underflow in AP mode WMM Action frame processing
vendor_redhat·2015-05-04·CVSS 4.3
CVE-2015-4142 [MEDIUM] CWE-190 hostapd: integer underflow in AP mode WMM Action frame processing
hostapd: integer underflow in AP mode WMM Action frame processing
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
An integer underflow flaw, leading to a buffer over-read, was found in the way wpa_supplicant handled WMM Action frames. A specially crafted frame could possibly allow an attacker within Wi-Fi radio range to cause wpa_supplicant to crash.
Package: wpa_supplicant (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2015-4142: wpa - Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 an...
vendor_debian·2015·CVSS 4.3
CVE-2015-4142 [MEDIUM] CVE-2015-4142: wpa - Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 an...
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
Scope: local
bookworm: resolved (fixed in 2.3-2.2)
bullseye: resolved (fixed in 2.3-2.2)
forky: resolved (fixed in 2.3-2.2)
sid: resolved (fixed in 2.3-2.2)
trixie: resolved (fixed in 2.3-2.2)
GHSA
GHSA-r4j8-fwxp-qfmx: Integer underflow in the WMM Action frame parser in hostapd 0
ghsa_unreviewed·2022-05-14
CVE-2015-4142 [MEDIUM] CWE-119 GHSA-r4j8-fwxp-qfmx: Integer underflow in the WMM Action frame parser in hostapd 0
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
OSV
wpa, wpasupplicant vulnerabilities
osv·2015-06-16·CVSS 4.3
CVE-2015-4141 [MEDIUM] wpa, wpasupplicant vulnerabilities
wpa, wpasupplicant vulnerabilities
Kostya Kortchinsky discovered multiple flaws in wpa_supplicant and hostapd.
A remote attacker could use these issues to cause wpa_supplicant or hostapd
to crash, resulting in a denial of service. (CVE-2015-4141, CVE-2015-4142,
CVE-2015-4143, CVE-2015-4144, CVE-2015-4145, CVE-2015-4146)
OSV
CVE-2015-4142: Integer underflow in the WMM Action frame parser in hostapd 0
osv·2015-06-15·CVSS 4.3
CVE-2015-4142 [MEDIUM] CVE-2015-4142: Integer underflow in the WMM Action frame parser in hostapd 0
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172608.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172655.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1090.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1439.htmlhttp://seclists.org/fulldisclosure/2022/May/34http://w1.fi/security/2015-3/integer-underflow-in-ap-mode-wmm-action-frame.txthttp://www.debian.org/security/2015/dsa-3397http://www.openwall.com/lists/oss-security/2015/05/09/5http://www.openwall.com/lists/oss-security/2015/05/31/6http://www.securitytracker.com/id/1032625http://www.ubuntu.com/usn/USN-2650-1https://security.gentoo.org/glsa/201606-17https://support.apple.com/kb/HT213258http://lists.fedoraproject.org/pipermail/package-announce/2015-November/171401.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172608.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-November/172655.htmlhttp://lists.opensuse.org/opensuse-updates/2015-06/msg00019.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1090.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1439.htmlhttp://seclists.org/fulldisclosure/2022/May/34http://w1.fi/security/2015-3/integer-underflow-in-ap-mode-wmm-action-frame.txthttp://www.debian.org/security/2015/dsa-3397http://www.openwall.com/lists/oss-security/2015/05/09/5http://www.openwall.com/lists/oss-security/2015/05/31/6http://www.securitytracker.com/id/1032625http://www.ubuntu.com/usn/USN-2650-1https://security.gentoo.org/glsa/201606-17https://support.apple.com/kb/HT213258
2015-06-15
Published