Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: wpa_supplicant_ro_ssids

Found 1 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2024-5290
8.8 HIGH
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): LOW
  • Privileges required (PR): LOW
  • User interaction (UI): NONE
  • Scope (S): CHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): HIGH
created 6 months ago
An issue was discovered in Ubuntu wpa_supplicant that resulted in …

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.

Affected products

wpa
  • <2:2.6-15ubuntu2.8+esm1
  • <2:2.10-21ubuntu0.1
  • <2.4-0ubuntu6.8+esm1
  • <2:2.9-1ubuntu4.4
  • <2:2.10-6ubuntu2.1
  • <2.1-0ubuntu1.7+esm5
wpa_supplicant
  • <2:2.6-15ubuntu2.8+esm1
  • <2:2.10-21ubuntu0.1
  • <2.4-0ubuntu6.8+esm1
  • <2:2.9-1ubuntu4.4
  • <2:2.10-6ubuntu2.1
  • <2.1-0ubuntu1.7+esm5

Matching in nixpkgs

pkgs.wpaperd

Minimal wallpaper daemon for Wayland

  • nixos-unstable -

pkgs.cowpatty

Offline dictionary attack against WPA/WPA2 networks

  • nixos-unstable -

pkgs.vowpal-wabbit

Machine learning system focused on online reinforcement learning

  • nixos-unstable -

pkgs.python312Packages.vowpalwabbit

Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project

  • nixos-unstable -

pkgs.python313Packages.vowpalwabbit

Vowpal Wabbit is a fast machine learning library for online learning, and this is the python wrapper for the project

  • nixos-unstable -

Package maintainers