UBUNTU-CVE-2019-13377
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-13377
UBUNTU-CVE-2019-13377
Summary:
Details: The implementations of SAE and EAP-pwd in hostapd and wpa_supplicant 2.x through 2.8 are vulnerable to side-channel attacks as a result of observable timing differences and cache access patterns when Brainpool curves are used. An attacker may be able to gain leaked information from a side-channel attack that can be used for full password recovery.
References: https://ubuntu.com/security/CVE-2019-13377, https://wpa3.mathyvanhoef.com/#new, https://w1.fi/security/2019-6/sae-eap-pwd-side-channel-attack-update.txt, https://ubuntu.com/security/notices/USN-4098-1, https://www.cve.org/CVERecord?id=CVE-2019-13377
Affected packages
Package
Name: wpa
Purl: pkg:deb/ubuntu/wpa@2:2.6-15ubuntu2.4?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
