Jouni Malinen discovered that a string supplied from a remote device could be supplied to a system() call in wpacli or hostapdcli when running an action script (with the "-a" option), resulting in arbitrary command execution. This issue could also be triggered by an attacker within radio range.
Patches are available from the following:
http://w1.fi/security/2014-1/
Based on the information about affected configurations in the upstream advisory, Red Hat Enterprise Linux 5 is likely to be not vulnerable, but Red Hat Enterprise Linux 6 and 7 are likely to be vulnerable.
Acknowledgements:
Red Hat would like to thank Jouni Malinen for reporting this issue.
References:
http://w1.fi/security/2014-1/ http://www.openwall.com/lists/oss-security/2014/10/09/28
The WPS UPnP function in hostapd, when using WPS AP, and wpasupplicant, when using WPS external registrar (ER), 0.7.0 through 2.4 allows remote attackers to cause a denial of service (crash) via a negative chunk length, which triggers an out-of-bounds read or heap-based buffer overflow.
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpasupplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.