Total vulnerabilities in the database
hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.
Software | From | Fixed in |
---|---|---|
w1.fi / wpa_supplicant | 0.6.7 | 2.5.x |
w1.fi / hostapd | 0.6.7 | 2.5.x |
canonical / ubuntu_linux | 16.04 | 16.04.x |
canonical / ubuntu_linux | 17.04 | 17.04.x |
canonical / ubuntu_linux | 14.04 | 14.04.x |