CVE-2015-4146: Medium severity wpa_supplicant vulnerability
The EAP-pwd peer implementation in hostapd and wpasupplicant 1.0 through 2.4 does not clear the L (Length) and M (More) flags before determining if a response should be fragmented, which allows remote attackers to cause a denial of service (crash) via a crafted message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-4146?
CVE-2015-4146 is classified as a denial of service vulnerability that can lead to a crash of the affected service.
How do I fix CVE-2015-4146?
To address CVE-2015-4146, update your wpa_supplicant or hostapd software to a version that is not vulnerable, such as versions after 2.4 or any patched release.
Which software is affected by CVE-2015-4146?
CVE-2015-4146 affects wpa_supplicant versions 1.0 through 2.4 and hostapd versions 1.0 through 2.4.
Can CVE-2015-4146 be exploited remotely?
Yes, CVE-2015-4146 can be exploited remotely by sending crafted messages to trigger the vulnerability.
What are the symptoms of an exploit for CVE-2015-4146?
Exploitation of CVE-2015-4146 may result in the affected service crashing, leading to a denial of service.