Oval Definition:oval:org.mitre.oval:def:18360
Revision Date:2014-06-23Version:5
Title:DSA-2557-1 hostapd - denial of service
Description:Timo Warns discovered that the internal authentication server of hostapd, a user space IEEE 802.11 AP and IEEE 802.1X/WPA/WPA2/EAP Authenticator, is vulnerable to a buffer overflow when processing fragmented EAP-TLS messages. As a result, an internal overflow checking routine terminates the process. An attacker can abuse this flaw to conduct denial of service attacks via crafted EAP-TLS messages prior to any authentication.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2012-4445
DSA-2557-1
Platform(s):Debian GNU/kFreeBSD 6.0
Debian GNU/Linux 6.0
Product(s):hostapd
Definition Synopsis
  • Debian 6.0 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND hostapd DPKG is earlier than 1:0.6.10-2+squeeze1
  • BACK