CVE-2015-8041: Integer Overflow
Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpasupplicant before 2.5 allow remote attackers to cause a denial of service (process crash or infinite loop) via a large payload length field value in an (1) WPS or (2) P2P NFC NDEF record, which triggers an out-of-bounds read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8041?
CVE-2015-8041 has a high severity level due to its potential to cause denial of service.
How do I fix CVE-2015-8041?
To fix CVE-2015-8041, update to hostapd version 2.5 or higher and wpa_supplicant version 2.5 or higher.
What systems are affected by CVE-2015-8041?
CVE-2015-8041 affects versions of hostapd and wpa_supplicant prior to 2.5, as well as certain versions of openSUSE.
What types of records are exploited in CVE-2015-8041?
CVE-2015-8041 exploits vulnerabilities in WPS and P2P NFC NDEF records.
What are the consequences of exploiting CVE-2015-8041?
Exploitation of CVE-2015-8041 can lead to process crashes or infinite loops in affected systems.