EAP-pwd Message Buffer Vulnerability in Hostapd
CVE-2015-5314
5.9MEDIUM
What is CVE-2015-5314?
The eap_pwd_process function within the Hostapd software fails to ensure that the reassembly buffer has sufficient size for the final fragment when using an internal EAP server or a RADIUS server with EAP-pwd enabled. This oversight could be exploited by remote attackers, allowing them to send a large final fragment in an EAP-pwd message, potentially leading to the termination of the associated process and rendering the service unavailable.
