CVE-2015-4142: Buffer Overflow
Published May 31, 2015
·Updated
Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpasupplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read.
Other sources
Wi-Fi. This issue was addressed with improved checks.
— Apple
Credit
Kostya Kortchinsky(Google Security Team)
Affected Software
31 affected componentsFixes available
debian/wpa
2:2.7+git20190128+0c1e29f-6+deb10u32:2.9.0-212:2.10-122:2.10-15
w1.fi Wpa Supplicant=0.7.0
w1.fi Wpa Supplicant=0.7.1
w1.fi Wpa Supplicant=0.7.2
w1.fi Wpa Supplicant=0.7.3
w1.fi Wpa Supplicant=1.0
w1.fi Wpa Supplicant=1.1
w1.fi Wpa Supplicant=2.0
w1.fi Wpa Supplicant=2.1
w1.fi Wpa Supplicant=2.2
w1.fi Wpa Supplicant=2.3
w1.fi Wpa Supplicant=2.4
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Hpc Node=6.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Workstation=6.0
w1.fi hostapd=0.7.0
w1.fi hostapd=0.7.1
w1.fi hostapd=0.7.2
w1.fi hostapd=0.7.3
w1.fi hostapd=1.0
w1.fi hostapd=1.1
w1.fi hostapd=2.0
w1.fi hostapd=2.1
w1.fi hostapd=2.2
w1.fi hostapd=2.3
w1.fi hostapd=2.4
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Apple iOS<15.5
15.5
Apple iPadOS<15.5
15.5
Event History
May 31, 2015
Data Sourced
08:42 PM
SeverityAffected Software
Jun 15, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2022-26702
- CVE-2022-26751
- CVE-2022-26736
- CVE-2022-26737
- CVE-2022-26738
- CVE-2022-26739
- CVE-2022-26740
- CVE-2022-26763
- CVE-2022-32781
- CVE-2022-26744
- CVE-2022-26711
- CVE-2022-26701
- CVE-2022-26771
- CVE-2022-26714
- CVE-2022-26757
- CVE-2022-26764
- CVE-2022-26765
- CVE-2022-26706
- CVE-2022-26775
- CVE-2022-26708
- CVE-2022-32790
- CVE-2022-26776
- CVE-2022-23308
- CVE-2022-22673
- CVE-2022-26731
- CVE-2022-26766
- CVE-2022-26703
- CVE-2022-26704
- CVE-2022-26726
- CVE-2022-26700
- CVE-2022-26709
- CVE-2022-26710
- CVE-2022-26717
- CVE-2022-26716
- CVE-2022-26719
- CVE-2022-22677
- CVE-2022-26745
- CVE-2022-26760
- CVE-2015-4142
- CVE-2022-26762
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2015-4142.
2
What is the affected software?
The affected software is Apple iOS and Apple iPadOS versions up to 15.5.
3
How was this issue addressed?
This issue was addressed with improved checks.
4
Where can I find more information about this issue?
You can find more information about this issue at the following link: [https://support.apple.com/en-us/HT213258](https://support.apple.com/en-us/HT213258).