Vulnerability Name:

CVE-2015-5316 (CCN-139831)

Assigned:2015-07-01
Published:2015-07-01
Updated:2018-03-21
Summary:The eap_pwd_perform_confirm_exchange function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6, when EAP-pwd is enabled in a network configuration profile, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an EAP-pwd Confirm message followed by the Identity exchange.
CVSS v3 Severity:5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2015-5316

Source: CONFIRM
Type: Mitigation, Patch, Vendor Advisory
http://w1.fi/security/2015-8/eap-pwd-unexpected-confirm.txt

Source: CCN
Type: oss-sec Mailing List, Tue, 10 Nov 2015 19:50:20 +0200
wpa_supplicant: EAP-pwd peer error path failure on unexpected Confirm message

Source: MLIST
Type: Mailing List, Mitigation, Patch, Third Party Advisory
[oss-security] 20151110 wpa_supplicant: EAP-pwd peer error path failure on unexpected Confirm message

Source: BID
Type: Third Party Advisory, VDB Entry
77538

Source: CCN
Type: BID-77538
wpa_supplicant CVE-2015-5316 Null Pointer Deference Denial of Service Vulnerability

Source: UBUNTU
Type: Broken Link
USN-2808-1

Source: XF
Type: UNKNOWN
wpasupplicant-cve20155316-dos(139831)

Source: CCN
Type: wpa_supplicant Web site
Linux WPA/WPA2/IEEE 802.1X Supplicant

Source: DEBIAN
Type: Third Party Advisory
DSA-3397

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-5316

Vulnerable Configuration:Configuration 1:
  • cpe:/a:w1.fi:wpa_supplicant:*:*:*:*:*:*:*:* (Version >= 2.0 and < 2.6)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:w1.fi:wpa_supplicant:2.4:*:*:*:*:*:*:*
  • OR cpe:/a:w1.fi:wpa_supplicant:2.3:*:*:*:*:*:*:*
  • OR cpe:/a:w1.fi:wpa_supplicant:2.2:*:*:*:*:*:*:*
  • OR cpe:/a:w1.fi:wpa_supplicant:2.1:*:*:*:*:*:*:*
  • OR cpe:/a:w1.fi:wpa_supplicant:2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20155316
    V
    CVE-2015-5316
    2023-06-22
    oval:org.opensuse.security:def:7703
    P
    libxslt-devel-1.1.34-150400.3.3.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7681
    P
    libtidy5-5.4.0-3.2.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7829
    P
    wpa_supplicant-2.10-150500.1.3 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:587
    P
    Security update for nodejs16 (Important)
    2022-07-21
    oval:org.opensuse.security:def:3222
    P
    libopenssl-devel-1.0.2p-1.13 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3820
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94852
    P
    wpa_supplicant-2.9-4.33.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:914
    P
    Security update for webkit2gtk3 (Important)
    2022-06-14
    oval:org.opensuse.security:def:291
    P
    python3-salt-3002.2-6.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:333
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:386
    P
    wpa_supplicant-2.9-4.33.1 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:113586
    P
    wpa_supplicant-2.6-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:8726
    P
    Security update for apache2 (Important) (in QA)
    2022-01-10
    oval:org.opensuse.security:def:8883
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:7012
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP1) (Important)
    2021-12-14
    oval:org.opensuse.security:def:6722
    P
    Security update for the Linux Kernel (Important)
    2021-12-07
    oval:org.opensuse.security:def:49301
    P
    Security update for python-Pygments (Important)
    2021-11-29
    oval:org.opensuse.security:def:100683
    P
    (Important)
    2021-11-22
    oval:org.opensuse.security:def:8864
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:8849
    P
    Security update for strongswan (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:6979
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-10-14
    oval:org.opensuse.security:def:106972
    P
    wpa_supplicant-2.6-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:96796
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71417
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89831
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103486
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71187
    P
    gdk-pixbuf-devel-2.36.11-3.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61676
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:1262
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:9034
    P
    Security update for openssl-1_1 (Low)
    2021-09-07
    oval:org.opensuse.security:def:9025
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:9016
    P
    Security update for nodejs8 (Important)
    2021-08-20
    oval:org.opensuse.security:def:6954
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2021-08-17
    oval:org.opensuse.security:def:93970
    P
    (Important)
    2021-08-17
    oval:org.opensuse.security:def:48107
    P
    libevent-2_0-5-2.0.21-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48339
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47273
    P
    gpgme-1.5.1-1.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47873
    P
    qemu-2.11.2-4.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47123
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47809
    P
    libvte9-0.28.2-19.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48265
    P
    perl-DBD-mysql-4.021-12.5.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46948
    P
    ghostscript-9.15-6.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47727
    P
    libjbig2-2.0-12.13 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48040
    P
    gzip-1.10-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:15219
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47569
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48169
    P
    libpcre1-32bit-8.39-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47365
    P
    libjson-c2-0.11-2.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47938
    P
    ImageMagick-config-6-SUSE-6.8.8.1-71.126.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47244
    P
    dracut-044-113.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48023
    P
    gnome-settings-daemon-3.20.1-50.16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48336
    P
    vsftpd-3.0.2-40.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47141
    P
    qemu-2.6.1-27.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47811
    P
    libwireshark9-2.4.9-48.29.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47109
    P
    opensc-0.13.0-1.107 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47661
    P
    lftp-4.7.4-3.3.20 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48234
    P
    libzypp-16.20.0-2.39.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47108
    P
    ntp-4.2.8p8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47513
    P
    tar-1.27.1-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47969
    P
    ceph-common-12.2.12+git.1568024032.02236657ca-2.39.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47437
    P
    libyaml-0-2-0.1.6-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:62351
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101109
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72092
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:69901
    P
    Security update for nodejs8 (Important)
    2021-08-05
    oval:org.opensuse.security:def:8983
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:61380
    P
    wpa_supplicant-2.6-2.50 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46813
    P
    perl-Config-IniFiles-2.82-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48678
    P
    kernel-default-extra-3.12.28-4.6 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46812
    P
    perl-32bit-5.18.2-3.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46827
    P
    python-imaging-1.1.7-21.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71074
    P
    perl-XML-LibXML-2.0132-1.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71121
    P
    wpa_supplicant-2.6-2.50 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48732
    P
    libfbembed2_5-2.5.2.26539-13.42 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:8958
    P
    Security update for curl (Moderate)
    2021-05-31
    oval:org.opensuse.security:def:9707
    P
    Security update for the Linux Kernel (Important)
    2021-05-18
    oval:org.opensuse.security:def:64487
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:9685
    P
    Security update for umoci (Important)
    2021-04-09
    oval:org.opensuse.security:def:8734
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:70006
    P
    Security update for glib2 (Important)
    2021-03-19
    oval:org.opensuse.security:def:6730
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-03-17
    oval:org.opensuse.security:def:7021
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-03-17
    oval:org.opensuse.security:def:9047
    P
    Security update for java-11-openjdk (Important)
    2021-02-09
    oval:org.opensuse.security:def:8802
    P
    Security update for nodejs8 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:8756
    P
    Security update for tcmu-runner (Important)
    2021-01-18
    oval:org.opensuse.security:def:6879
    P
    Security update for the Linux Kernel (Important)
    2021-01-14
    oval:org.opensuse.security:def:67734
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15) (Important)
    2020-12-07
    oval:org.opensuse.security:def:6845
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP1) (Important)
    2020-12-07
    oval:org.opensuse.security:def:13211
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49028
    P
    libplist++3-1.12-20.3.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116907
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71744
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107349
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48974
    P
    argyllcms-1.6.3-3.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62003
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:37072
    P
    augeas on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37616
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37835
    P
    krb5-appl-clients on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7030
    P
    libdmx1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66650
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36977
    P
    openslp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73223
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37366
    P
    yast2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37763
    P
    curl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38473
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36976
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67834
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37208
    P
    libipa_hbac0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6752
    P
    libreoffice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37675
    P
    sblim-sfcb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64400
    P
    libvorbis-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7043
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49355
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36988
    P
    pcsc-ccid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37456
    P
    gtk2-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6860
    P
    vorbis-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37791
    P
    gdk-pixbuf-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38515
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66558
    P
    libxkbcommon-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37309
    P
    procmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6798
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37724
    P
    alsa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73341
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.trusty:def:20155316000
    V
    CVE-2015-5316 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-02-21
    oval:org.cisecurity:def:296
    P
    DSA-3397-1 wpa -- security update
    2016-02-08
    oval:com.ubuntu.precise:def:20155316000
    V
    CVE-2015-5316 on Ubuntu 12.04 LTS (precise) - medium.
    2015-11-10
    BACK
    w1.fi wpa supplicant *
    debian debian linux 8.0
    w1.fi wpa supplicant 2.4
    w1.fi wpa supplicant 2.3
    w1.fi wpa supplicant 2.2
    w1.fi wpa supplicant 2.1
    w1.fi wpa supplicant 2.0