SUSE-SU-2015:2221-1
Dashboard / Vulnerabilities / SUSE-SU-2015:2221-1
SUSE-SU-2015:2221-1
Summary: Security update for wpa_supplicant
Details: wpa_supplicant was updated to fix two security issues. These security issues were fixed: - CVE-2015-4142: Integer underflow in the WMM Action frame parser in hostapd and wpa_supplicant, when used for AP mode MLME/SME functionality, allowed remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read (bsc#930078). - CVE-2015-4141: The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), allowed remote attackers to cause a denial of service (crash) via a negative chunk length, which triggered an out-of-bounds read or heap-based buffer overflow (bsc#930077).
References: https://www.suse.com/support/update/announcement/2015/suse-su-20152221-1/, https://bugzilla.suse.com/930077, https://bugzilla.suse.com/930078, https://www.suse.com/security/cve/CVE-2015-4141, https://www.suse.com/security/cve/CVE-2015-4142
Affected packages
Package
Name: wpa_supplicant
Purl: pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Desktop%2011%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
