UBUNTU-CVE-2019-16275
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-16275
UBUNTU-CVE-2019-16275
Summary:
Details: hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection in certain situations because source address validation is mishandled. This is a denial of service that should have been prevented by PMF (aka management frame protection). The attacker must send a crafted 802.11 frame from a location that is within the 802.11 communications range. An attacker in radio range of the access point could inject a specially constructed unauthenticated IEEE 802.11 frame to the access point to cause associated stations to be disconnected and require a reconnection to the network.
References: https://ubuntu.com/security/CVE-2019-16275, https://w1.fi/security/2019-7/ap-mode-pmf-disconnection-protection-bypass.txt, https://www.openwall.com/lists/oss-security/2019/09/11/7, https://ubuntu.com/security/notices/USN-4136-1, https://ubuntu.com/security/notices/USN-4136-2, https://www.cve.org/CVERecord?id=CVE-2019-16275
Affected packages
Package
Name: wpa
Purl: pkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
