Описание
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
hardy | ignored | end of life |
lucid | ignored | end of life |
natty | released | 0.6.10-2+squeeze1build0.11.04.1 |
oneiric | ignored | end of life |
precise | released | 1:0.7.3-4ubuntu1.1 |
quantal | DNE | |
raring | DNE | |
saucy | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 1.0-3ubuntu1 |
esm-infra-legacy/trusty | not-affected | 1.0-3ubuntu1 |
hardy | DNE | |
lucid | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
quantal | ignored | end of life |
raring | not-affected | 1.0-3ubuntu1 |
saucy | not-affected | 1.0-3ubuntu1 |
Показывать по
Ссылки на источники
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
Heap-based buffer overflow in the eap_server_tls_process_fragment func ...
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации
EPSS
4.3 Medium
CVSS2