Vulnerability Name:

CVE-2016-4477 (CCN-112895)

Assigned:2016-05-03
Published:2016-05-03
Updated:2017-10-23
Summary:wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.
CVSS v3 Severity:7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:4.4 Medium (CVSS v2 Vector: AV:L/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-19
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2016-4477

Source: CCN
Type: oss-sec Mailing List, Tue, 3 May 2016 01:29:28 -0400 (EDT)
Re: hostapd/wpa_supplicant - psk configuration parameter update allowing arbitrary data to be written

Source: CONFIRM
Type: Vendor Advisory
http://source.android.com/security/bulletin/2016-05-01.html

Source: CCN
Type: W1.Fi Web site
hostapd and wpa_supplicant

Source: MLIST
Type: UNKNOWN
[oss-security] 20160503 Re: hostapd/wpa_supplicant - psk configuration parameter update allowing arbitrary data to be written

Source: UBUNTU
Type: UNKNOWN
USN-3455-1

Source: XF
Type: UNKNOWN
wpasupplicant-cve20164477-priv-esc(112895)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-4477

Vulnerable Configuration:Configuration 1:
  • cpe:/o:google:android:4.4.4:*:*:*:*:*:*:*
  • OR cpe:/o:google:android:5.0.2:*:*:*:*:*:*:*
  • OR cpe:/o:google:android:5.1.1:*:*:*:*:*:*:*
  • OR cpe:/o:google:android:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:google:android:6.0.1:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:w1.fi:wpa_supplicant:2.5:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20164477
    V
    CVE-2016-4477
    2023-06-22
    oval:org.opensuse.security:def:7703
    P
    libxslt-devel-1.1.34-150400.3.3.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7681
    P
    libtidy5-5.4.0-3.2.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7829
    P
    wpa_supplicant-2.10-150500.1.3 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:587
    P
    Security update for nodejs16 (Important)
    2022-07-21
    oval:org.opensuse.security:def:3222
    P
    libopenssl-devel-1.0.2p-1.13 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3398
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3820
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94852
    P
    wpa_supplicant-2.9-4.33.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:914
    P
    Security update for webkit2gtk3 (Important)
    2022-06-14
    oval:org.opensuse.security:def:291
    P
    python3-salt-3002.2-6.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:333
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:386
    P
    wpa_supplicant-2.9-4.33.1 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:113586
    P
    wpa_supplicant-2.6-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:8726
    P
    Security update for apache2 (Important) (in QA)
    2022-01-10
    oval:org.opensuse.security:def:8883
    P
    Security update for log4j (Important)
    2021-12-17
    oval:org.opensuse.security:def:7012
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15 SP1) (Important)
    2021-12-14
    oval:org.opensuse.security:def:6722
    P
    Security update for the Linux Kernel (Important)
    2021-12-07
    oval:org.opensuse.security:def:49301
    P
    Security update for python-Pygments (Important)
    2021-11-29
    oval:org.opensuse.security:def:100683
    P
    (Important)
    2021-11-22
    oval:org.opensuse.security:def:8864
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:8849
    P
    Security update for strongswan (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:6979
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-10-14
    oval:org.opensuse.security:def:106972
    P
    wpa_supplicant-2.6-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71417
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89831
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103486
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71187
    P
    gdk-pixbuf-devel-2.36.11-3.19 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61676
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96796
    P
    wpa_supplicant-2.6-4.11.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:1262
    P
    Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:9034
    P
    Security update for openssl-1_1 (Low)
    2021-09-07
    oval:org.opensuse.security:def:9025
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:9016
    P
    Security update for nodejs8 (Important)
    2021-08-20
    oval:org.opensuse.security:def:6954
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2021-08-17
    oval:org.opensuse.security:def:93970
    P
    (Important)
    2021-08-17
    oval:org.opensuse.security:def:48339
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47273
    P
    gpgme-1.5.1-1.11 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47873
    P
    qemu-2.11.2-4.14 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47123
    P
    perl-Config-IniFiles-2.82-3.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47809
    P
    libvte9-0.28.2-19.7 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48265
    P
    perl-DBD-mysql-4.021-12.5.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46948
    P
    ghostscript-9.15-6.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47727
    P
    libjbig2-2.0-12.13 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48040
    P
    gzip-1.10-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:15219
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47569
    P
    busybox-1.21.1-3.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48169
    P
    libpcre1-32bit-8.39-8.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47365
    P
    libjson-c2-0.11-2.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47938
    P
    ImageMagick-config-6-SUSE-6.8.8.1-71.126.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47244
    P
    dracut-044-113.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48023
    P
    gnome-settings-daemon-3.20.1-50.16.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48336
    P
    vsftpd-3.0.2-40.11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47141
    P
    qemu-2.6.1-27.15 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47811
    P
    libwireshark9-2.4.9-48.29.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47109
    P
    opensc-0.13.0-1.107 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47661
    P
    lftp-4.7.4-3.3.20 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48234
    P
    libzypp-16.20.0-2.39.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47108
    P
    ntp-4.2.8p8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47513
    P
    tar-1.27.1-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47969
    P
    ceph-common-12.2.12+git.1568024032.02236657ca-2.39.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47437
    P
    libyaml-0-2-0.1.6-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48107
    P
    libevent-2_0-5-2.0.21-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:62351
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101109
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72092
    P
    wpa_supplicant-2.9-4.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:69901
    P
    Security update for nodejs8 (Important)
    2021-08-05
    oval:org.opensuse.security:def:8983
    P
    Security update for xterm (Important)
    2021-06-18
    oval:org.opensuse.security:def:61380
    P
    wpa_supplicant-2.6-2.50 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46813
    P
    perl-Config-IniFiles-2.82-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48678
    P
    kernel-default-extra-3.12.28-4.6 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46812
    P
    perl-32bit-5.18.2-3.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46827
    P
    python-imaging-1.1.7-21.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71074
    P
    perl-XML-LibXML-2.0132-1.20 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71121
    P
    wpa_supplicant-2.6-2.50 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48732
    P
    libfbembed2_5-2.5.2.26539-13.42 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:8958
    P
    Security update for curl (Moderate)
    2021-05-31
    oval:org.opensuse.security:def:9707
    P
    Security update for the Linux Kernel (Important)
    2021-05-18
    oval:org.opensuse.security:def:64487
    P
    Security update for bind (Important)
    2021-05-04
    oval:org.opensuse.security:def:9685
    P
    Security update for umoci (Important)
    2021-04-09
    oval:org.opensuse.security:def:8734
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:70006
    P
    Security update for glib2 (Important)
    2021-03-19
    oval:org.opensuse.security:def:6730
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15) (Important)
    2021-03-17
    oval:org.opensuse.security:def:7021
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-03-17
    oval:org.opensuse.security:def:9047
    P
    Security update for java-11-openjdk (Important)
    2021-02-09
    oval:org.opensuse.security:def:8802
    P
    Security update for nodejs8 (Moderate)
    2021-01-26
    oval:org.opensuse.security:def:8756
    P
    Security update for tcmu-runner (Important)
    2021-01-18
    oval:org.opensuse.security:def:6879
    P
    Security update for the Linux Kernel (Important)
    2021-01-14
    oval:org.opensuse.security:def:6845
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP1) (Important)
    2020-12-07
    oval:org.opensuse.security:def:67734
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15) (Important)
    2020-12-07
    oval:org.opensuse.security:def:13211
    P
    wpa_supplicant-2.6-15.10.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49028
    P
    libplist++3-1.12-20.3.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116907
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71744
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107349
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48974
    P
    argyllcms-1.6.3-3.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62003
    P
    wpa_supplicant-2.6-4.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:37616
    P
    logrotate on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37835
    P
    krb5-appl-clients on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7030
    P
    libdmx1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66650
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36977
    P
    openslp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73223
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37366
    P
    yast2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37763
    P
    curl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38473
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36976
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67834
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37208
    P
    libipa_hbac0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6752
    P
    libreoffice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37675
    P
    sblim-sfcb on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64400
    P
    libvorbis-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7043
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49355
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36988
    P
    pcsc-ccid on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37456
    P
    gtk2-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6860
    P
    vorbis-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37791
    P
    gdk-pixbuf-lang on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38515
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66558
    P
    libxkbcommon-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37309
    P
    procmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6798
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37724
    P
    alsa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73341
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37072
    P
    augeas on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.cosmic:def:201644770000000
    V
    CVE-2016-4477 on Ubuntu 18.10 (cosmic) - low.
    2016-05-09
    oval:com.ubuntu.artful:def:20164477000
    V
    CVE-2016-4477 on Ubuntu 17.10 (artful) - low.
    2016-05-09
    oval:com.ubuntu.trusty:def:20164477000
    V
    CVE-2016-4477 on Ubuntu 14.04 LTS (trusty) - low.
    2016-05-09
    oval:com.ubuntu.bionic:def:201644770000000
    V
    CVE-2016-4477 on Ubuntu 18.04 LTS (bionic) - low.
    2016-05-09
    oval:com.ubuntu.bionic:def:20164477000
    V
    CVE-2016-4477 on Ubuntu 18.04 LTS (bionic) - low.
    2016-05-09
    oval:com.ubuntu.xenial:def:20164477000
    V
    CVE-2016-4477 on Ubuntu 16.04 LTS (xenial) - low.
    2016-05-09
    oval:com.ubuntu.xenial:def:201644770000000
    V
    CVE-2016-4477 on Ubuntu 16.04 LTS (xenial) - low.
    2016-05-09
    oval:com.ubuntu.cosmic:def:20164477000
    V
    CVE-2016-4477 on Ubuntu 18.10 (cosmic) - low.
    2016-05-09
    oval:com.ubuntu.disco:def:201644770000000
    V
    CVE-2016-4477 on Ubuntu 19.04 (disco) - low.
    2016-05-09
    oval:com.ubuntu.precise:def:20164477000
    V
    CVE-2016-4477 on Ubuntu 12.04 LTS (precise) - low.
    2016-05-09
    BACK
    google android 4.4.4
    google android 5.0.2
    google android 5.1.1
    google android 6.0
    google android 6.0.1
    w1.fi wpa supplicant 2.5