HIGH
Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplicant before 1.2.6, and possibly other versions, allows remote authenticated users to execute arbitrary code via unspecified vectors
Published Oct 28, 2006
9.0
HIGHCVSS 2.0
EPSS 4.21%
Description
Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplicant before 1.2.6, and possibly other versions, allows remote authenticated users to execute arbitrary code via unspecified vectors.
Affected products
No data.
OR
- ≤ 1.2.5
- 0.5
- 0.6
- 0.7
- 0.8
- 0.8b
- 1.0
- 1.0.1
- 1.0pre1
- 1.0pre2
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.4
- 1.2pre1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- http://open1x.cvs.sourceforge.net/open1x/xsupplicant/src/eap.c?r1=1.135&r2=1.136 x_refsource_CONFIRM
- http://secunia.com/advisories/22612 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/22641 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:189 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_01_sr.html vendor-advisoryx_refsource_SUSE
- http://www.securityfocus.com/bid/20775 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2006/4233 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29902 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://open1x.cvs.sourceforge.net/open1x/xsupplicant/src/eap.c?r1=1.135&r2=1.136 | x_refsource_CONFIRM | |
| http://secunia.com/advisories/22612 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/22641 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.mandriva.com/security/advisories?name=MDKSA-2006:189 | vendor-advisoryx_refsource_MANDRIVA | |
| http://www.novell.com/linux/security/advisories/2007_01_sr.html | vendor-advisoryx_refsource_SUSE | |
| http://www.securityfocus.com/bid/20775 | vdb-entryx_refsource_BIDPatch | |
| http://www.vupen.com/english/advisories/2006/4233 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/29902 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 28, 2006
Updated Aug 7, 2024
Reserved Oct 27, 2006
Link CVE-2006-5601
CISA Vulnrichment
Updated n/a