Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.892318
Kategorie:Debian Local Security Checks
Titel:Debian LTS: Security Advisory for wpa (DLA-2318-1)
Zusammenfassung:The remote host is missing an update for the 'wpa'; package(s) announced via the DLA-2318-1 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'wpa'
package(s) announced via the DLA-2318-1 advisory.

Vulnerability Insight:
The following CVE(s) have been reported against src:wpa.

CVE-2019-10064

hostapd before 2.6, in EAP mode, makes calls to the rand()
and random() standard library functions without any preceding
srand() or srandom() call, which results in inappropriate
use of deterministic values. This was fixed in conjunction
with CVE-2016-10743.

CVE-2020-12695

The Open Connectivity Foundation UPnP specification before
2020-04-17 does not forbid the acceptance of a subscription
request with a delivery URL on a different network segment
than the fully qualified event-subscription URL, aka the
CallStranger issue.

Affected Software/OS:
'wpa' package(s) on Debian Linux.

Solution:
For Debian 9 stretch, these problems have been fixed in version
2:2.4-1+deb9u7.

We recommend that you upgrade your wpa packages.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:N/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-10743
Common Vulnerability Exposure (CVE) ID: CVE-2019-10064
Common Vulnerability Exposure (CVE) ID: CVE-2020-12695
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.