漏洞信息详情
WPA_Supplicant 缓冲区溢出漏洞
- CNNVD编号:CNNVD-200503-104
- 危害等级: 中危
- CVE编号:
CVE-2005-0470
- 漏洞类型:
缓冲区溢出
- 发布时间:
2005-03-14
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
wpa_supplicant - 漏洞来源:
The individual or … -
漏洞简介
wpa_supplicant 0.2.7之前版本中存在缓冲区溢出,远程攻击者可以通过无效的EAPOL-Key分组数据实施拒绝服务攻击(分段故障)。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
wpa_supplicant wpa_supplicant 0.2
wpa_supplicant wpa_supplicant 0.2.7
http://hostap.epitest.fi/releases/wpa_supplicant-0.2.7.tar.gz
wpa_supplicant wpa_supplicant 0.2.1
wpa_supplicant wpa_supplicant 0.2.7
http://hostap.epitest.fi/releases/wpa_supplicant-0.2.7.tar.gz
wpa_supplicant wpa_supplicant 0.2.2
wpa_supplicant wpa_supplicant 0.2.7
http://hostap.epitest.fi/releases/wpa_supplicant-0.2.7.tar.gz
wpa_supplicant wpa_supplicant 0.2.3
wpa_supplicant wpa_supplicant 0.2.7
http://hostap.epitest.fi/releases/wpa_supplicant-0.2.7.tar.gz
wpa_supplicant wpa_supplicant 0.2.4
SuSE wpa_supplicant-0.2.4-5.2.i586.rpm
ftp://ftp.suse.com/pub/suse/i386/update/9.2/rpm/i586/wpa_supplicant-0.2.4-5.2.i586.rpm
SuSE wpa_supplicant-0.2.4-5.2.x86_64.rpm
ftp://ftp.suse.com/pub/suse/x86_64/update/9.2/rpm/x86_64/wpa_supplicant-0.2.4-5.2.x86_64.rpm
wpa_supplicant wpa_supplicant 0.2.7
http://hostap.epitest.fi/releases/wpa_supplicant-0.2.7.tar.gz
wpa_supplicant wpa_supplicant 0.2.5
wpa_supplicant wpa_supplicant 0.2.7
http://hostap.epitest.fi/releases/wpa_supplicant-0.2.7.tar.gz
wpa_supplicant wpa_supplicant 0.2.6
wpa_supplicant wpa_supplicant 0.2.7
http://hostap.epitest.fi/releases/wpa_supplicant-0.2.7.tar.gz
参考网址
来源: XF
名称: wpasupplicant-bo(19357)
链接:http://xforce.iss.net/xforce/xfdb/19357
来源: GENTOO
名称: GLSA-200502-22
链接:http://www.gentoo.org/security/en/glsa/glsa-200502-22.xml
来源: SECUNIA
名称: 14313
链接:http://secunia.com/advisories/14313
来源: SECTRACK
名称: 1013226
链接:http://securitytracker.com/id?1013226
来源: MLIST
名称: [HostAP] 20050213 wpa_supplicant – new stable releases v0.3.8 and v0.2.7
链接:http://lists.shmoo.com/pipermail/hostap/2005-February/009465.html