hostapd EAPOL Key Length 远程拒绝服务漏洞

漏洞信息详情

hostapd EAPOL Key Length 远程拒绝服务漏洞

漏洞简介

Hostapd 0.3.7-2可以使远程攻击者借助EAPoL帧的key_data_length 字段中的不确定值,引起拒绝服务(分段故障)。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

hostapd hostapd 0.3.7

Debian hostapd_0.3.7-2sarge1_alpha.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_alpha.deb

Debian hostapd_0.3.7-2sarge1_amd64.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_amd64.deb

Debian hostapd_0.3.7-2sarge1_arm.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_arm.deb

Debian hostapd_0.3.7-2sarge1_hppa.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_hppa.deb

Debian hostapd_0.3.7-2sarge1_i386.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_i386.deb

Debian hostapd_0.3.7-2sarge1_ia64.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_ia64.deb

Debian hostapd_0.3.7-2sarge1_m68k.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_m68k.deb

Debian hostapd_0.3.7-2sarge1_mips.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_mips.deb

Debian hostapd_0.3.7-2sarge1_mipsel.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_mipsel.deb

Debian hostapd_0.3.7-2sarge1_powerpc.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_powerpc.deb

Debian hostapd_0.3.7-2sarge1_s390.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_s390.deb

Debian hostapd_0.3.7-2sarge1_sparc.debDebian GNU/Linux 3.1 alias sarge

http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2

sarge1_sparc.deb

hostapd hostapd-0.3.9.tar.gz

http://hostap.epitest.fi/releases/hostapd-0.3.9.tar.gz

Mandriva hostapd-0.3.7-2.1.102dk.i586.rpmMandriva Linux 10.2:

http://wwwnew.mandriva.com/en/downloads/

Mandriva hostapd-0.3.7-2.1.102dk.x86_64.rpmMandriva Linux 10.2:

http://wwwnew.mandriva.com/en/downloads/

Mandriva hostapd-0.3.7-2.1.20060mdk.i586.rpmMandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads/

Mandriva hostapd-0.3.7-2.1.20060mdk.x86_64.rpmMandriva Linux 2006.0:

http://wwwnew.mandriva.com/en/downloads/

参考网址

来源: VUPEN

名称: ADV-2006-1657

链接:http://www.frsirt.com/english/advisories/2006/1657

来源: SECUNIA

名称: 19966

链接:http://secunia.com/advisories/19966

来源: MISC

链接:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=365897

来源: XF

名称: hostapd-eapol-dos(26239)

链接:http://xforce.iss.net/xforce/xfdb/26239

来源: BID

名称: 17846

链接:http://www.securityfocus.com/bid/17846

来源: OSVDB

名称: 25233

链接:http://www.osvdb.org/25233

来源: MANDRAKE

名称: MDKSA-2006:088

链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:088

来源: DEBIAN

名称: DSA-1065

链接:http://www.debian.org/security/2006/dsa-1065

来源: SECUNIA

名称: 20265

链接:http://secunia.com/advisories/20265

来源: SECUNIA

名称: 20195

链接:http://secunia.com/advisories/20195

来源: MANDRAKE

名称: MDKSA-2006:088

链接:http://frontal2.mandriva.com/security/advisories?name=MDKSA-2006:088

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享