Information disclosure in wpa_supplicant and hostapd - CVE-2019-13377

 

Information disclosure in wpa_supplicant and hostapd - CVE-2019-13377

Published: August 27, 2019 / Updated: September 30, 2019


Vulnerability identifier: #VU20415
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13377
CWE-ID: CWE-200
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct time-based side-channel attacks on a targeted system.

The vulnerability exists due to insufficient security restrictions during the WPA3's Dragonfly handshake process when using Brainpool curves. A remote in radio range of the access point can observe timing differences and cache access patterns, conduct a side-channel attack and access sensitive information that could be used for full password recovery.




Affected software

wpa_supplicant
hostapd
wpa (Debian package)
wpa (Ubuntu package)
hostapd (Alpine package)
wpa_supplicant (Alpine package)
wpa_supplicant-help
wpa_supplicant-gui
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
hostapd
Fedora
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
openEuler

How to mitigate CVE-2019-13377

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

wpa (Debian package) - update to 2:2.7+git20190128+0c1e29f-6+deb10u1
wpa (Ubuntu package) - addressed in versions 2:2.6-15ubuntu2.4, 2:2.6-21ubuntu3.2
hostapd (Alpine package) - addressed in versions 2.7-r4, 2.8-r1
wpa_supplicant (Alpine package) - update to 2.7-r4
wpa_supplicant-help - update to 2.6-27
wpa_supplicant-gui - update to 2.6-27
wpa_supplicant - update to 2.6-27
wpa_supplicant-debuginfo - update to 2.6-27
wpa_supplicant-debugsource - update to 2.6-27
hostapd - addressed in versions 2.9-1.el7, 2.9-1.fc30
wpa_supplicant-debugsource - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant - update to 2.9-15.22.1

External References

Related Security Bulletins