ZeroHour

CVE-2019-10064

PoC ×3
CVSS 3.1
7.5 high
EPSS
4%p90
Published
()
Modified
Description

hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.

Vendors
w1.fidebian
Products
hostapd, debian linux
Weakness
CWE-331
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.