MGASA-2014-0429
Dashboard / Vulnerabilities / MGASA-2014-0429
Summary: Updated wpa_supplicant and hostapd packages fix security vulnerability
Details: A vulnerability was found in the mechanism wpa_cli and hostapd_cli use for executing action scripts. An unsanitized string received from a remote device can be passed to a system() call resulting in arbitrary command execution under the privileges of the wpa_cli/hostapd_cli process (which may be root in common use cases) (CVE-2014-3686). Using the Mageia wpa_supplicant package, systems are exposed to the vulnerability if operating as a WPS registrar. The Mageia hostapd package was not vulnerable with the configuration with which it was built, but if a sysadmin had rebuilt it with WPS enabled, it would be vulnerable.
References: https://advisories.mageia.org/MGASA-2014-0429.html, https://bugs.mageia.org/show_bug.cgi?id=14262, http://w1.fi/security/2014-1/wpacli-action-scripts.txt
Affected packages
Package
Name: wpa_supplicant
Purl: pkg:rpm/mageia/wpa_supplicant?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
