CVE-2012-4445
hostapd - denial of service
EPSS 4.2%
描述
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
如何修補 CVE-2012-4445
要修補 CVE-2012-4445,請將受影響套件升級到下列已修補版本。
- Debian/hostapd—升級至 1:0.6.10-2+squeeze1 或更新版本
- Debian/wpa—升級至 1.0-3 或更新版本
CVE-2012-4445 正在被利用嗎?
低 — EPSS 為 4.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1:0.6.10-2+squeeze1
- from 0, < 1.0-3