SB2021122905 - Slackware update for wpa_supplicant
Published: December 29, 2021 Updated: August 7, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 secuirty vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2021-0326)
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the p2p_copy_client_info() function of p2p.c in wpa_suplicant. A remote attacker pass specially crafted input to the application, trigger out-of-bounds write and execute arbitrary code on the target system.
2) Use-after-free (CVE-ID: CVE-2021-0535)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in the wpas_ctrl_msg_queue_timeout() function of ctrl_iface_unix.c file in wpa_supplicant. A local user can pass specially crafted data to the application, trigger a use-after-free error and execute arbitrary code with elevated privileges.
3) Input validation error (CVE-ID: CVE-2020-12695)
The vulnerability allows a remote attacker to perform a distributed denial of service (DDoS) attack.
The vulnerability exists due to a CallStranger issue in the UPnP SUBSCRIBE functionality. A remote attacker can send traffic to arbitrary destinations, leading to amplified DDoS attacks and data exfiltration.
4) Input validation error (CVE-ID: CVE-2019-16275)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to the affected software allows an incorrect indication of disconnection in certain situations because source address validation is mishandled. A remote attacker in radio range of the access point can send a specially crafted 802.11 frame and cause a denial of service condition on target system.
5) Resource management error (CVE-ID: CVE-2021-27803)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources when processing P2P (Wi-Fi Direct) provision discovery requests in p2p/p2p_pd in wpa_supplicant. A remote attacker within radio range can send specially crafted request to the system and perform a denial of service (DoS) attack.
6) Input validation error (CVE-ID: CVE-2021-30004)
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to insufficient validation of user-supplied input in tls/pkcs1.c and tls/x509v3.c files in wpa_supplicant and hostapd when handling AlgorithmIdentifier parameters. A remote attacker can pass specially crafted input to the application and perform MitM attack.
Remediation
Install update from vendor's website.