Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-30004

Опубликовано: 14 мар. 2021
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

A flaw was found in wpa_supplicant, in the way it handled digest algorithm parameters when validating a signature. This flaw could be exploited to perform potential forging attacks. The highest threat from this vulnerability is to data integrity.

Отчет

This issue only affects the "internal" TLS implementation. The versions of wpa_supplicant as shipped with Red Hat Enterprise Linux 6, 7, and 8 are not affected by this flaw, as they use the OpenSSL implementation by default. More specifically, the CONFIG_TLS=internal flag is not set at compile time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wpa_supplicantNot affected
Red Hat Enterprise Linux 7wpa_supplicantNot affected
Red Hat Enterprise Linux 8wpa_supplicantNot affected
Red Hat Enterprise Linux 9wpa_supplicantNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1946680wpa_supplicant: mishandled AlgorithmIdentifier parameters may lead to forging attacks

EPSS

Процентиль: 53%
0.00296
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 5 лет назад

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

CVSS3: 5.3
nvd
почти 5 лет назад

In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.

CVSS3: 5.3
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 5.3
debian
почти 5 лет назад

In wpa_supplicant and hostapd 2.9, forging attacks may occur because A ...

suse-cvrf
почти 5 лет назад

Security update for wpa_supplicant

EPSS

Процентиль: 53%
0.00296
Низкий

5.3 Medium

CVSS3