MGASA-2014-0429

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 28 Oct 2014, 11:33
Last modified:16 Apr 2026, 06:22

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Oct 2014, 11:33
Published
Vulnerability first disclosed
16 Apr 2026, 06:22
Last Modified
Vulnerability information updated

Description

Updated wpa_supplicant and hostapd packages fix security vulnerability A vulnerability was found in the mechanism wpa_cli and hostapd_cli use for executing action scripts. An unsanitized string received from a remote device can be passed to a system() call resulting in arbitrary command execution under the privileges of the wpa_cli/hostapd_cli process (which may be root in common use cases) (CVE-2014-3686). Using the Mageia wpa_supplicant package, systems are exposed to the vulnerability if operating as a WPS registrar. The Mageia hostapd package was not vulnerable with the configuration with which it was built, but if a sysadmin had rebuilt it with WPS enabled, it would be vulnerable.

Affected Systems

  • mageiahostapd

    < 1.1-2.1.mga3

  • mageiawpa_supplicant

    < 1.1-4.1.mga3

  • mageiahostapd

    < 2.0-2.1.mga4

  • mageiawpa_supplicant

    < 2.0-2.1.mga4

References (3)