CVE-2016-4476 PUBLISHED

hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.

EPSS 0.61% · 69.6th percentile

Risk Scores

EPSS Score
0.61%
69.6th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSwpa0
Ubuntu:16.04:LTSwpa0, 2.4-0ubuntu3, 2.4-0ubuntu4
Ubuntu:14.04:LTSwpa2.1-0ubuntu1.2, 0, 2.1-0ubuntu1.4

Timeline

References

Open in Interactive Console →