UBUNTU-CVE-2019-11555
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-11555
UBUNTU-CVE-2019-11555
Summary:
Details: The EAP-pwd implementation in hostapd (EAP server) before 2.8 and wpa_supplicant (EAP peer) before 2.8 does not validate fragmentation reassembly state properly for a case where an unexpected fragment could be received. This could result in process termination due to a NULL pointer dereference (denial of service). This affects eap_server/eap_server_pwd.c and eap_peer/eap_pwd.c.
References: https://ubuntu.com/security/CVE-2019-11555, https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt, http://www.openwall.com/lists/oss-security/2019/04/26/1, https://www.openwall.com/lists/oss-security/2019/04/18/6, https://ubuntu.com/security/notices/USN-3969-1, https://ubuntu.com/security/notices/USN-3969-2, https://www.cve.org/CVERecord?id=CVE-2019-11555
Affected packages
Package
Name: wpa
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
