Denial of Service Vulnerability in WPA Supplicant by The Open Wireless Movement
CVE-2015-5315
5.9MEDIUM
What is CVE-2015-5315?
The eap_pwd_process function in the WPA Supplicant prior to version 2.6 does not adequately check the size of the reassembly buffer when handling EAP-pwd messages. This oversight can be exploited by remote attackers to send a large final fragment, resulting in process termination. This vulnerability highlights significant concerns for users configuring EAP-pwd in their network profiles, as it can lead to service interruptions.
