CVE-2015-4142
hostapd - security update
EPSS 4.2%
描述
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
如何修補 CVE-2015-4142
要修補 CVE-2015-4142,請將受影響套件升級到下列已修補版本。
- Debian/hostapd—升級至 1:0.6.10-2+squeeze2 或更新版本
- Debian/wpa—升級至 2.3-2.2 或更新版本
CVE-2015-4142 正在被利用嗎?
低 — EPSS 為 4.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1:0.6.10-2+squeeze2
- from 0, < 2.3-2.2