USN-3944-1
Dashboard / Vulnerabilities / USN-3944-1
USN-3944-1
Summary: wpa vulnerabilities
Details: It was discovered that wpa_supplicant and hostapd were vulnerable to a side channel attack against EAP-pwd. A remote attacker could possibly use this issue to recover certain passwords. (CVE-2019-9495) Mathy Vanhoef discovered that wpa_supplicant and hostapd incorrectly validated received scalar and element values in EAP-pwd-Commit messages. A remote attacker could possibly use this issue to perform a reflection attack and authenticate without the appropriate password. (CVE-2019-9497, CVE-2019-9498, CVE-2019-9499) It was discovered that hostapd incorrectly handled obtaining random numbers. In rare cases where the urandom device isn't available, it would fall back to using a low-quality PRNG. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-10743)
References: https://ubuntu.com/security/notices/USN-3944-1, https://ubuntu.com/security/CVE-2016-10743, https://ubuntu.com/security/CVE-2019-9495, https://ubuntu.com/security/CVE-2019-9497, https://ubuntu.com/security/CVE-2019-9498, https://ubuntu.com/security/CVE-2019-9499
Affected packages
Package
Name: wpa
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
