Vulnerability Details CVE-2015-4141
The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.0%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2015-4141
-
cpe:2.3:a:w1.fi:hostapd:0.7.0
-
cpe:2.3:a:w1.fi:hostapd:0.7.1
-
cpe:2.3:a:w1.fi:hostapd:0.7.2
-
cpe:2.3:a:w1.fi:hostapd:0.7.3
-
cpe:2.3:a:w1.fi:hostapd:1.0
-
cpe:2.3:a:w1.fi:hostapd:1.1
-
cpe:2.3:a:w1.fi:hostapd:2.0
-
cpe:2.3:a:w1.fi:hostapd:2.1
-
cpe:2.3:a:w1.fi:hostapd:2.2
-
cpe:2.3:a:w1.fi:hostapd:2.3
-
cpe:2.3:a:w1.fi:hostapd:2.4
-
cpe:2.3:a:w1.fi:wpa_supplicant:0.7.0
-
cpe:2.3:a:w1.fi:wpa_supplicant:0.7.1
-
cpe:2.3:a:w1.fi:wpa_supplicant:0.7.2
-
cpe:2.3:a:w1.fi:wpa_supplicant:0.7.3
-
cpe:2.3:a:w1.fi:wpa_supplicant:1.0
-
cpe:2.3:a:w1.fi:wpa_supplicant:1.1
-
cpe:2.3:a:w1.fi:wpa_supplicant:2.0
-
cpe:2.3:a:w1.fi:wpa_supplicant:2.1
-
cpe:2.3:a:w1.fi:wpa_supplicant:2.2
-
cpe:2.3:a:w1.fi:wpa_supplicant:2.3
-
cpe:2.3:a:w1.fi:wpa_supplicant:2.4
-
cpe:2.3:o:opensuse:opensuse:13.1
-
cpe:2.3:o:opensuse:opensuse:13.2