SB2019081430 - Ubuntu update for wpa_supplicant and hostapd
Published: August 14, 2019 Updated: September 5, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2019-13377)
The vulnerability allows a remote attacker to conduct time-based side-channel attacks on a targeted system.
The vulnerability exists due to insufficient security restrictions during the WPA3's Dragonfly handshake process when using Brainpool curves. A remote in radio range of the access point can observe timing differences and cache access patterns, conduct a side-channel attack and access sensitive information that could be used for full password recovery.
Remediation
Install update from vendor's website.