CVE-2015-4143: Buffer Overflow
The EAP-pwd server and peer implementation in hostapd and wpasupplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted (1) Commit or (2) Confirm message payload.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4143?
CVE-2015-4143 has been classified as a denial of service vulnerability that can lead to a crash.
How do I fix CVE-2015-4143?
To fix CVE-2015-4143, you should upgrade to the patched versions of hostapd and wpa_supplicant, specifically versions 2.7+git20190128+0c1e29f-6+deb10u3 or higher.
Which versions of software are affected by CVE-2015-4143?
CVE-2015-4143 affects hostapd and wpa_supplicant versions from 1.0 to 2.4.
Can CVE-2015-4143 be exploited remotely?
Yes, CVE-2015-4143 can be exploited by remote attackers through crafted Commit or Confirm message payloads.
What are the implications of an out-of-bounds read in CVE-2015-4143?
An out-of-bounds read in CVE-2015-4143 can lead to a denial of service by causing an application crash.