FS#42401 - [wpa_supplicant] CVE02014-3686 arbitrary command execution
Attached to Project:
Arch Linux
Opened by Levente Polyak (anthraxx) - Thursday, 16 October 2014, 10:03 GMT
Last edited by Thomas Bächler (brain0) - Sunday, 19 October 2014, 09:47 GMT
Opened by Levente Polyak (anthraxx) - Thursday, 16 October 2014, 10:03 GMT
Last edited by Thomas Bächler (brain0) - Sunday, 19 October 2014, 09:47 GMT
|
Details
Hello,
Summary: It has been reported [0] that wpa_supplicant is affected by a arbitrary command execution vulnerability tracked as CVE-2014-3686 [1]. Description: wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame. Mitigation: The problem has been fixed upstream [2] so its recommend to update as fast as possible. cheers Levente [0] http://www.openwall.com/lists/oss-security/2014/10/09/28 [1] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3686 |
This task depends upon
cheers Levente