Back to search
CVE-2019-10064
Published: Feb 28, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20200227 Hostapd fails at seeding PRNGS, leading to insufficient entropy (CVE-2016-10743 and CVE-2019-10064)
mailing-list
x_refsource_FULLDISC
http://www.openwall.com/lists/oss-security/2020/02/27/1
x_refsource_MISC
[debian-lts-announce] 20200311 [SECURITY] [DLA 2138-1] wpa security update
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20200808 [SECURITY] [DLA 2318-1] wpa security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now