|
|
| |
|
| |
hostapd: denial of service
| Package(s): | hostapd |
CVE #(s): | CVE-2012-4445
|
| Created: | October 8, 2012 |
Updated: | October 19, 2012 |
| Description: |
From the Debian advisory:
Timo Warns discovered that the internal authentication server of hostapd,
a user space IEEE 802.11 AP and IEEE 802.1X/WPA/WPA2/EAP Authenticator,
is vulnerable to a buffer overflow when processing fragmented EAP-TLS
messages. As a result, an internal overflow checking routine terminates
the process. An attacker can abuse this flaw to conduct denial of service
attacks via crafted EAP-TLS messages prior to any authentication. |
| Alerts: |
|
( Log in to post comments)
|
|
|