CVE-2005-0470: Buffer Overflow
Published Feb 19, 2005
·Updated
Buffer overflow in wpasupplicant before 0.2.7 allows remote attackers to cause a denial of service (segmentation fault) via invalid EAPOL-Key packet data.
Affected Software
10 affected components
Wpa Supplicant Wpa Supplicant=0.2.4
Wpa Supplicant Wpa Supplicant=0.2.5
Wpa Supplicant Wpa Supplicant=0.2.1
Wpa Supplicant Wpa Supplicant=0.2.2
Wpa Supplicant Wpa Supplicant=0.2
Wpa Supplicant Wpa Supplicant=0.2.6
Wpa Supplicant Wpa Supplicant=0.2.3
SUSE SuSE Linux=9.2
SUSE SuSE Linux=9.2
Gentoo Linux
Remediation
Patch Available
Patch Available
Event History
Feb 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0470?
CVE-2005-0470 has a high severity rating due to its potential to cause denial of service through remote exploitation.
2
How do I fix CVE-2005-0470?
To fix CVE-2005-0470, update wpa_supplicant to version 0.2.7 or later.
3
Which versions of wpa_supplicant are affected by CVE-2005-0470?
CVE-2005-0470 affects wpa_supplicant versions 0.2.1 to 0.2.6.
4
What kind of attack does CVE-2005-0470 enable?
CVE-2005-0470 enables remote attackers to execute a denial of service by sending crafted EAPOL-Key packet data.
5
Is CVE-2005-0470 present in any operating systems?
CVE-2005-0470 can be found in systems running vulnerable versions of wpa_supplicant, which may include certain distributions of Linux.