Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14526

Опубликовано: 08 авг. 2018
Источник: debian
EPSS Низкий

Описание

An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wpafixed2:2.6-18package
wpafixed2:2.4-1+deb9u2stretchpackage

Примечания

  • https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt

  • https://w1.fi/security/2018-1/0001-WPA-Ignore-unauthenticated-encrypted-EAPOL-Key-data.patch

  • https://w1.fi/security/2018-1/rebased-v2.6-0001-WPA-Ignore-unauthenticated-encrypted-EAPOL-Key-data.patch

EPSS

Процентиль: 78%
0.01138
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.

CVSS3: 8.3
redhat
больше 7 лет назад

An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.

CVSS3: 6.5
nvd
больше 7 лет назад

An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.

suse-cvrf
больше 6 лет назад

Security update for wpa_supplicant

suse-cvrf
около 7 лет назад

Security update for wpa_supplicant

EPSS

Процентиль: 78%
0.01138
Низкий