CVE-2015-1863

Publication date 22 April 2015

Last updated 24 July 2024


Ubuntu priority

Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries.

Status

Package Ubuntu Release Status
wpa 15.04 vivid
Fixed 2.1-0ubuntu7.1
14.10 utopic
Fixed 2.1-0ubuntu4.1
14.04 LTS trusty
Fixed 2.1-0ubuntu1.2
12.04 LTS precise Not in release
10.04 LTS lucid Not in release
wpasupplicant 15.04 vivid Not in release
14.10 utopic Not in release
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid
Not affected

References

Related Ubuntu Security Notices (USN)

    • USN-2577-1
    • wpa_supplicant vulnerability
    • 23 April 2015

Other references