6.8

CVE-2014-3686

wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
W1.Fi ≫ Hostapd Version 0.7.2
W1.Fi ≫ Hostapd Version 1.0
W1.Fi ≫ Hostapd Version 1.1
W1.Fi ≫ Hostapd Version 2.0
W1.Fi ≫ Hostapd Version 2.1
W1.Fi ≫ Hostapd Version 2.2
W1.Fi ≫ Wpa Supplicant Version 0.72
W1.Fi ≫ Wpa Supplicant Version 1.0
W1.Fi ≫ Wpa Supplicant Version 1.1
W1.Fi ≫ Wpa Supplicant Version 2.0
W1.Fi ≫ Wpa Supplicant Version 2.1
W1.Fi ≫ Wpa Supplicant Version 2.2
Canonical ≫ Ubuntu Linux Version 10.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 12.04 Update - Edition lts
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Debian ≫ Debian Linux Version 6.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.95% 0.91
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://advisories.mageia.org/MGASA-2014-0429.html
http://lists.opensuse.org/opensuse-security-announce/2014-11/msg00000.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00027.html
http://lists.opensuse.org/opensuse-updates/2014-10/msg00028.html
http://rhn.redhat.com/errata/RHSA-2014-1956.html
http://secunia.com/advisories/60366
http://secunia.com/advisories/60428
http://secunia.com/advisories/61271
http://w1.fi/security/2014-1/
http://www.debian.org/security/2014/dsa-3052
http://www.mandriva.com/security/advisories?name=MDVSA-2015:120
http://www.openwall.com/lists/oss-security/2014/10/09/28
http://www.securityfocus.com/bid/70396
http://www.ubuntu.com/usn/USN-2383-1
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1151259
https://security.gentoo.org/glsa/201606-17