PT-2019-4630 · Hostap+5 · Hostapd+5

Jouni Malinen

·

Publicado

2019-04-18

·

Atualizado

2024-06-15

·

CVE-2019-11555

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions hostapd versions prior to 2.8 wpa supplicant versions prior to 2.8
Description The issue is related to the EAP-pwd implementation, which does not properly validate fragmentation reassembly state. This could lead to process termination due to a NULL pointer dereference, resulting in a denial of service. The affected components are eap server/eap server pwd.c and eap peer/eap pwd.c.
Recommendations For hostapd versions prior to 2.8, update to version 2.8 or later to resolve the issue. For wpa supplicant versions prior to 2.8, update to version 2.8 or later to resolve the issue.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2020-00775
CVE-2019-11555
DLA-1867-1
DSA-4450-1
FREEBSD-SA-19_03
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1
USN-3969-1
USN-3969-2

Produtos afetados

Alt Linux
Freebsd
Suse
Ubuntu
Hostapd
Wpa Supplicant