LWN.net Logo

hostapd: denial of service

Package(s):hostapd CVE #(s):CVE-2012-4445
Created:October 8, 2012 Updated:October 19, 2012
Description: From the Debian advisory:

Timo Warns discovered that the internal authentication server of hostapd, a user space IEEE 802.11 AP and IEEE 802.1X/WPA/WPA2/EAP Authenticator, is vulnerable to a buffer overflow when processing fragmented EAP-TLS messages. As a result, an internal overflow checking routine terminates the process. An attacker can abuse this flaw to conduct denial of service attacks via crafted EAP-TLS messages prior to any authentication.

Alerts:
Debian DSA-2557-1 2012-10-08
Mageia MGASA-2012-0291 2012-10-11
Fedora FEDORA-2012-15748 2012-10-18
Fedora FEDORA-2012-15759 2012-10-18
openSUSE openSUSE-SU-2012:1371-1 2012-10-19
Mandriva MDVSA-2012:168 2012-10-22

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds