MGASA-2016-0199

    Dashboard / Vulnerabilities / MGASA-2016-0199

    MGASA-2016-0199

    Published: 21 May 2016Last Modified: 16 Apr 2026

    Summary: Updated wpa_supplicant packages fix security vulnerabilities

    Details: Updated wpa_suppliant packages fix security vulnerabilities: A vulnerability was found in how wpa_supplicant writes the configuration file update for the WPA/WPA2 passphrase parameter. If this parameter has been updated to include control characters either through a WPS operation (CVE-2016-4476) or through local configuration change over the wpa_supplicant control interface (CVE-2016-4477), the resulting configuration file may prevent the wpa_supplicant from starting when the updated file is used. In addition, it may be possible to load a local library file and execute code from there with the same privileges under which the wpa_supplicant process runs.

    Affected packages

    Package

    Name: wpa_supplicant

    Purl: pkg:rpm/mageia/wpa_supplicant?arch=source&distro=mageia-5

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.3-3.1.mga5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    MGASA-2016-0199 | CVE-DB