CVE-2024-5290 (High) detected in https://source.codeaurora.org/quic/le/platform/external/hostap/hostap_2_10 #218
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2024-5290 - High Severity Vulnerability
Vulnerable Library - https://source.codeaurora.org/quic/le/platform/external/hostap/hostap_2_10
Library home page: https://source.codeaurora.org/quic/le/platform/external/hostap/
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branches: stable/3.2, master
Vulnerable Source Files (1)
/crypto/tls_openssl.c
Vulnerability Details
An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root).
Membership in the netdev group or access to the dbus interface of wpa_supplicant allow an unprivileged user to specify an arbitrary path to a module to be loaded by the wpa_supplicant process; other escalation paths might exist.
Publish Date: 2024-08-07
URL: CVE-2024-5290
CVSS 3 Score Details (8.8)
Base Score Metrics:
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: