SB2014102317 - Fedora EPEL 6 update for hostapd
Published: October 23, 2014 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2014-3686)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.
Remediation
Install update from vendor's website.