Total vulnerabilities in the database
The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.
Software | From | Fixed in |
---|---|---|
w1.fi / wpa_supplicant | 2.3 | 2.3.x |
w1.fi / wpa_supplicant | 0.7.1 | 0.7.1.x |
w1.fi / wpa_supplicant | 2.1 | 2.1.x |
w1.fi / wpa_supplicant | 2.2 | 2.2.x |
w1.fi / wpa_supplicant | 1.0 | 1.0.x |
w1.fi / wpa_supplicant | 2.4 | 2.4.x |
w1.fi / wpa_supplicant | 0.7.0 | 0.7.0.x |
w1.fi / wpa_supplicant | 0.7.3 | 0.7.3.x |
w1.fi / wpa_supplicant | 1.1 | 1.1.x |
w1.fi / wpa_supplicant | 0.7.2 | 0.7.2.x |
w1.fi / wpa_supplicant | 2.0 | 2.0.x |
w1.fi / hostapd | 1.1 | 1.1.x |
w1.fi / hostapd | 2.4 | 2.4.x |
w1.fi / hostapd | 2.0 | 2.0.x |
w1.fi / hostapd | 0.7.3 | 0.7.3.x |
w1.fi / hostapd | 1.0 | 1.0.x |
w1.fi / hostapd | 0.7.0 | 0.7.0.x |
w1.fi / hostapd | 2.3 | 2.3.x |
w1.fi / hostapd | 0.7.2 | 0.7.2.x |
w1.fi / hostapd | 2.2 | 2.2.x |
w1.fi / hostapd | 2.1 | 2.1.x |
w1.fi / hostapd | 0.7.1 | 0.7.1.x |
opensuse / opensuse | 13.1 | 13.1.x |
opensuse / opensuse | 13.2 | 13.2.x |