Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2019-9496
HistoryApr 17, 2019 - 2:29 p.m.

CVE-2019-9496

2019-04-1714:29:03
Debian Security Bug Tracker
security-tracker.debian.org
9

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.011 Low

EPSS

Percentile

84.6%

An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.

OSVersionArchitecturePackageVersionFilename
Debian12allwpa< 2:2.7+git20190128+0c1e29f-4wpa_2:2.7+git20190128+0c1e29f-4_all.deb
Debian11allwpa< 2:2.7+git20190128+0c1e29f-4wpa_2:2.7+git20190128+0c1e29f-4_all.deb
Debian999allwpa< 2:2.7+git20190128+0c1e29f-4wpa_2:2.7+git20190128+0c1e29f-4_all.deb
Debian13allwpa< 2:2.7+git20190128+0c1e29f-4wpa_2:2.7+git20190128+0c1e29f-4_all.deb

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.011 Low

EPSS

Percentile

84.6%