CVE-2015-5315: Buffer Overflow
The eappwdprocess function in eappeer/eappwd.c in wpasupplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for the final fragment when EAP-pwd is enabled in a network configuration profile, which allows remote attackers to cause a denial of service (process termination) via a large final fragment in an EAP-pwd message.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2015-5315.
What is the severity rating of CVE-2015-5315?
The severity rating of CVE-2015-5315 is medium (5.9).
How does CVE-2015-5315 impact wpa_supplicant?
CVE-2015-5315 allows remote attackers to cause a denial of service (process termination) in wpa_supplicant 2.x before 2.6 when EAP-pwd is enabled in a network configuration profile.
Is there a fix available for CVE-2015-5315?
Yes, the fix for CVE-2015-5315 is available in wpa_supplicant version 2.7 onwards.
Where can I find more information about CVE-2015-5315?
You can find more information about CVE-2015-5315 in the following references: [1] http://w1.fi/security/2015-7/eap-pwd-missing-last-fragment-length-validation.txt [2] http://www.openwall.com/lists/oss-security/2015/11/10/10 [3] http://www.ubuntu.com/usn/USN-2808-1