Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade wpa_supplicant | Aug 30, 2017 | Apr 28, 2015 |
| Centos_linux | — | Upgrade wpa_supplicant | Dec 1, 2016 | Apr 28, 2015 |
| Debian | — | Upgrade wpa | Jul 30, 2024 | Apr 28, 2015 |
| Freebsd | — | Upgrade wpa_supplicant | Dec 10, 2025 | Apr 25, 2015 |
| Gentoo Linux | — | Upgrade net-wireless/hostapd.Upgrade net-wireless/wpa_supplicant. | Oct 30, 2017 | Apr 28, 2015 |
| Oracle_linux | — | Upgrade wpa_supplicant | Oct 16, 2024 | Apr 28, 2015 |
| Suse | — | Upgrade wpa_supplicant | Dec 18, 2015 | Apr 28, 2015 |
| Ubuntu | — | Upgrade wpasupplicant | Nov 8, 2024 | Apr 28, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub