PT-2020-5620 · Hostap+1 · Hostapd+1

Jonathan Brossard

·

Published

2016-12-23

·

Updated

2022-01-01

·

CVE-2019-10064

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions hostapd versions prior to 2.6
Description The issue is related to the use of deterministic values due to missing calls to srand() or srandom() before using rand() and random() standard library functions in EAP mode. This results in inappropriate use of deterministic values. The vulnerability is also related to a lack of entropy in PIN selection for WPA wireless network device certification, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For hostapd versions prior to 2.6, update to version 2.6 or later to resolve the issue. As a temporary workaround, consider disabling the use of rand() and random() functions in EAP mode until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2481
BDU:2021-01305
CVE-2019-10064
DLA-2138-1
DLA-2318-1

Affected Products

Alt Linux
Hostapd