PT-2019-4630 · Hostap+5 · Hostapd+5

Jouni Malinen

·

Published

2019-04-18

·

Updated

2024-06-15

·

CVE-2019-11555

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions hostapd versions prior to 2.8 wpa supplicant versions prior to 2.8
Description The issue is related to the EAP-pwd implementation, which does not properly validate fragmentation reassembly state. This could lead to process termination due to a NULL pointer dereference, resulting in a denial of service. The affected components are eap server/eap server pwd.c and eap peer/eap pwd.c.
Recommendations For hostapd versions prior to 2.8, update to version 2.8 or later to resolve the issue. For wpa supplicant versions prior to 2.8, update to version 2.8 or later to resolve the issue.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-2497
ALT-PU-2019-2498
ALT-PU-2019-2554
ALT-PU-2020-3139
ALT-PU-2022-1980
BDU:2020-00775
CVE-2019-11555
DLA-1867-1
DSA-4450-1
FREEBSD-SA-19_03
OPENSUSE-SU-2020:2053-1
OPENSUSE-SU-2020:2059-1
OPENSUSE-SU-2020_2053-1
OPENSUSE-SU-2020_2059-1
OPENSUSE-SU-2024:11515-1
SUSE-SU-2020:3380-1
SUSE-SU-2020:3424-1
SUSE-SU-2022:1853-1
USN-3969-1
USN-3969-2

Affected Products

Alt Linux
Freebsd
Suse
Ubuntu
Hostapd
Wpa Supplicant