Denial of Service Vulnerability in hostapd and wpa_supplicant by The Linux Foundation
CVE-2016-4476
7.5HIGH
What is CVE-2016-4476?
Certain versions of hostapd and wpa_supplicant do not properly handle carriage return and line feed characters in passphrase parameters. This oversight allows remote attackers to exploit the functionality through a malicious WPS operation, leading to a service outage of the daemon. It is imperative for users of these applications to ensure they are using updated versions to mitigate potential exploit risks.
