Lucene search

K
cve[email protected]CVE-2006-5601
HistoryOct 28, 2006 - 1:07 a.m.

CVE-2006-5601

2006-10-2801:07:00
CWE-119
web.nvd.nist.gov
20
cve-2006-5601
eap_do_notify
xsupplicant
buffer overflow
security vulnerability

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.166 Low

EPSS

Percentile

96.1%

Stack-based buffer overflow in the eap_do_notify function in eap.c in xsupplicant before 1.2.6, and possibly other versions, allows remote authenticated users to execute arbitrary code via unspecified vectors.

Affected configurations

NVD
Node
xsupplicantxsupplicantRange1.2.5
OR
xsupplicantxsupplicantMatch0.5
OR
xsupplicantxsupplicantMatch0.6
OR
xsupplicantxsupplicantMatch0.7
OR
xsupplicantxsupplicantMatch0.8
OR
xsupplicantxsupplicantMatch0.8b
OR
xsupplicantxsupplicantMatch1.0
OR
xsupplicantxsupplicantMatch1.0.1
OR
xsupplicantxsupplicantMatch1.0pre1
OR
xsupplicantxsupplicantMatch1.0pre2
OR
xsupplicantxsupplicantMatch1.2
OR
xsupplicantxsupplicantMatch1.2.1
OR
xsupplicantxsupplicantMatch1.2.2
OR
xsupplicantxsupplicantMatch1.2.3
OR
xsupplicantxsupplicantMatch1.2.4
OR
xsupplicantxsupplicantMatch1.2pre1

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.166 Low

EPSS

Percentile

96.1%

Related for CVE-2006-5601