CVE-2015-4142 PUBLISHED

Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.

EPSS 7.07% · 91.4th percentile

Risk Scores

EPSS Score
7.07%
91.4th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSwpa0, 1.0-3ubuntu2, 1.0-3ubuntu3

Timeline

References

Open in Interactive Console →