PT-2020-5620 · Hostap+1 · Hostapd+1
Jonathan Brossard
·
Published
2016-12-23
·
Updated
2022-01-01
·
CVE-2019-10064
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
hostapd versions prior to 2.6
Description
The issue is related to the use of deterministic values due to missing calls to srand() or srandom() before using rand() and random() standard library functions in EAP mode. This results in inappropriate use of deterministic values. The vulnerability is also related to a lack of entropy in PIN selection for WPA wireless network device certification, which can be exploited by a remote attacker to cause a denial of service.
Recommendations
For hostapd versions prior to 2.6, update to version 2.6 or later to resolve the issue.
As a temporary workaround, consider disabling the use of rand() and random() functions in EAP mode until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Hostapd