Debian Wpa vulnerabilities
46 known vulnerabilities affecting debian/wpa.
Total CVEs
46
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM30LOW3
Vulnerabilities
Page 2 of 3
CVE-2017-13086P4MEDIUMCVSS 6.8fixed in wpa 2:2.4-1.1 (bookworm)2017
CVE-2017-13086 [MEDIUM] CVE-2017-13086: wpa - Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Dire...
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames.
Scope: local
bookworm: resolved (fixed in 2:2.4-1.1)
bullseye: resolved (fixed in 2:2.4-1.1)
forky: resolved (fixed in 2:2.4-1.1)
sid: resolved (fixed
debian
CVE-2019-13377P4MEDIUMCVSS 5.9fixed in wpa 2:2.9-1 (bookworm)2019
CVE-2019-13377 [MEDIUM] CVE-2019-13377: wpa - The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through...
The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
Scope: local
bookwor
debian
CVE-2016-4477P4HIGHCVSS 7.8fixed in wpa 2.3-2.4 (bookworm)2016
CVE-2016-4477 [HIGH] CVE-2016-4477: wpa - wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphr...
wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.
Scope: local
bookworm: resolved (fixed in 2.3-2.4)
bullseye: resolved (
debian
CVE-2019-11555P4MEDIUMCVSS 5.9fixed in wpa 2:2.7+git20190128+0c1e29f-5 (bookworm)2019
CVE-2019-11555 [MEDIUM] CVE-2019-11555: wpa - The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant...
The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/
debian
CVE-2018-14526P4MEDIUMCVSS 6.5fixed in wpa 2:2.6-18 (bookworm)2018
CVE-2018-14526 [MEDIUM] CVE-2018-14526: wpa - An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Und...
An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.
Scope: local
bookworm: resolved (fixed in 2:2.6-18)
bullseye: res
debian
CVE-2017-13079P4MEDIUMCVSS 5.3fixed in firmware-nonfree 20180825-1 (bookworm)2017
CVE-2017-13079 [MEDIUM] CVE-2017-13079: firmware-nonfree - Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstal...
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 20180825-1)
bullseye: resolved (fixed in 20180825-1)
forky: resolve
debian
CVE-2017-13088P4MEDIUMCVSS 5.3fixed in wpa 2:2.4-1.1 (bookworm)2017
CVE-2017-13088 [MEDIUM] CVE-2017-13088: wpa - Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation...
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 2:2.4-1.1)
bullseye: resolved (fixed
debian
CVE-2017-13087P4MEDIUMCVSS 5.3fixed in wpa 2:2.4-1.1 (bookworm)2017
CVE-2017-13087 [MEDIUM] CVE-2017-13087: wpa - Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation...
Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 2:2.4-1.1)
bullseye: resolved (fixed in 2:2.4-1.
debian
CVE-2017-13078P4MEDIUMCVSS 5.3fixed in firmware-nonfree 20180825-1 (bookworm)2017
CVE-2017-13078 [MEDIUM] CVE-2017-13078: firmware-nonfree - Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Tempora...
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 20180825-1)
bullseye: resolved (fixed in 20180825-1)
forky: resolved (fixed in 20180825-1)
sid: resolved
debian
CVE-2015-5315P4MEDIUMCVSS 5.9fixed in wpa 2.3-2.3 (bookworm)2015
CVE-2015-5315 [MEDIUM] CVE-2015-5315: wpa - The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before ...
The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration profile, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd message.
Scope: local
debian
CVE-2015-5314P4MEDIUMCVSS 5.9fixed in wpa 2.3-2.3 (bookworm)2015
CVE-2015-5314 [MEDIUM] CVE-2015-5314: wpa - The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x befor...
The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when used with (1) an internal EAP server or (2) a RADIUS server and EAP-pwd is enabled in a runtime configuration, which allows remote attackers to cause a denial of service (process termination) via a
debian
CVE-2017-13080P4MEDIUMCVSS 5.3fixed in firmware-nonfree 20180825-1 (bookworm)2017
CVE-2017-13080 [MEDIUM] CVE-2017-13080: firmware-nonfree - Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Tempora...
Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 20180825-1)
bullseye: resolved (fixed in 20180825-1)
forky: resolved (fixed in 20180825-1)
sid: resolve
debian
CVE-2017-13081P4MEDIUMCVSS 5.3fixed in firmware-nonfree 20180825-1 (bookworm)2017
CVE-2017-13081 [MEDIUM] CVE-2017-13081: firmware-nonfree - Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstal...
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
Scope: local
bookworm: resolved (fixed in 20180825-1)
bullseye: resolved (fixed in 20180825-1)
forky: resolv
debian
CVE-2015-5316P4MEDIUMCVSS 5.9fixed in wpa 2.3-2.3 (bookworm)2015
CVE-2015-5316 [MEDIUM] CVE-2015-5316: wpa - The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_suppl...
The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an EAP-pwd Confirm message followed by the Identity exchange.
Scope: local
bookworm: resolved (fixed in 2.3-2
debian
CVE-2019-16275P4MEDIUMCVSS 6.5fixed in wpa 2:2.9-2 (bookworm)2019
CVE-2019-16275 [MEDIUM] CVE-2019-16275: wpa - hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication...
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communicati
debian
CVE-2012-4445P4MEDIUMCVSS 4.3fixed in wpa 1.0-3 (bookworm)2012
CVE-2012-4445 [MEDIUM] CVE-2012-4445: wpa - Heap-based buffer overflow in the eap_server_tls_process_fragment function in ea...
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
Scope: local
bookworm: resolved (fixed in 1
debian
CVE-2019-5061P4LOWCVSS 6.5fixed in wpa 2:2.9+git20200213+877d9a0-1 (bookworm)2019
CVE-2019-5061 [MEDIUM] CVE-2019-5061: wpa - An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where ...
An exploitable denial-of-service vulnerability exists in the hostapd 2.6, where an attacker could trigger AP to send IAPP location updates for stations, before the required authentication process has completed. This could lead to different denial of service scenarios, either by causing CAM table attacks, or by leading to traffic flapping if faking already existing clien
debian
CVE-2015-4141P4MEDIUMCVSS 4.3fixed in wpa 2.3-2.2 (bookworm)2015
CVE-2015-4141 [MEDIUM] CVE-2015-4141: wpa - The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when us...
The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.3-2.2)
bullseye: resolved (fixed in 2.3
debian
CVE-2015-4143P4MEDIUMCVSS 5.0fixed in wpa 2.3-2.2 (bookworm)2015
CVE-2015-4143 [MEDIUM] CVE-2015-4143: wpa - The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 thr...
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message payload.
Scope: local
bookworm: resolved (fixed in 2.3-2.2)
bullseye: resolved (fixed in 2.3-2.2)
forky: resolved (fixed in 2.3-2.2)
sid: resolved (fix
debian
CVE-2015-4144P4MEDIUMCVSS 5.0fixed in wpa 2.3-2.2 (bookworm)2015
CVE-2015-4144 [MEDIUM] CVE-2015-4144: wpa - The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 thr...
The EAP-pwd server and peer implementation in hostapd and wpa_supplicant 1.0 through 2.4 does not validate that a message is long enough to contain the Total-Length field, which allows remote attackers to cause a denial of service (crash) via a crafted message.
Scope: local
bookworm: resolved (fixed in 2.3-2.2)
bullseye: resolved (fixed in 2.3-2.2)
forky: resolved (fixe
debian