Denial of Service Vulnerability in wpa_supplicant by The WAP Forum
CVE-2015-5316
5.9MEDIUM
What is CVE-2015-5316?
The eap_pwd_perform_confirm_exchange function in wpa_supplicant versions prior to 2.6 can be exploited by attackers to trigger a denial of service. This occurs when EAP-pwd is active in the network profile, allowing attackers to send a malformed EAP-pwd Confirm message, leading to a NULL pointer dereference and subsequently crashing the daemon.
