cbcvebase.
CVE-2015-4142
published 2015-06-15

CVE-2015-4142: Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME…

medium4.3CVSS 3.1
AVNACMAuNCNINAP
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
appleios_15.5_and_ipados
debianwpa< wpa 2.3-2.2 (bookworm)wpa 2.3-2.2 (bookworm)
opensuseopensuse
opensuseopensuse
redhatenterprise_linux_desktop
redhatenterprise_linux_hpc_node
redhatenterprise_linux_server
redhatenterprise_linux_workstation
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fihostapd
w1.fiwpa_supplicant
w1.fiwpa_supplicant
w1.fiwpa_supplicant
w1.fiwpa_supplicant
w1.fiwpa_supplicant
w1.fiwpa_supplicant

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM