Oval Definition:oval:org.opensuse.security:def:80283
Revision Date:2015-12-07Version:1
Title:Security update for wpa_supplicant (Moderate)
Description:

wpa_supplicant was updated to fix two security issues.

These security issues were fixed: - CVE-2015-4142: Integer underflow in the WMM Action frame parser in hostapd and wpa_supplicant, when used for AP mode MLME/SME functionality, allowed remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read (bsc#930078). - CVE-2015-4141: The WPS UPnP function in hostapd, when using WPS AP, and wpa_supplicant, when using WPS external registrar (ER), allowed remote attackers to cause a denial of service (crash) via a negative chunk length, which triggered an out-of-bounds read or heap-based buffer overflow (bsc#930077).
Family:unixClass:patch
Status:Reference(s):930077
930078
CVE-2015-4141
CVE-2015-4142
SUSE-SU-2015:2221-1
Platform(s):SUSE Linux Enterprise Desktop 11 SP4
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Desktop 11 SP4 is installed
  • AND Package Information
  • wpa_supplicant-0.7.1-6.17.4 is installed
  • OR wpa_supplicant-gui-0.7.1-6.17.4 is installed
  • BACK