Jouni Malinen discovered that a string supplied from a remote device could be supplied to a system() call in wpacli or hostapdcli when running an action script (with the "-a" option), resulting in arbitrary command execution. This issue could also be triggered by an attacker within radio range.
Patches are available from the following:
http://w1.fi/security/2014-1/
Based on the information about affected configurations in the upstream advisory, Red Hat Enterprise Linux 5 is likely to be not vulnerable, but Red Hat Enterprise Linux 6 and 7 are likely to be vulnerable.
Acknowledgements:
Red Hat would like to thank Jouni Malinen for reporting this issue.
References:
http://w1.fi/security/2014-1/ http://www.openwall.com/lists/oss-security/2014/10/09/28