Permissions, Privileges, and Access Controls in wpa_supplicant and hostapd - CVE-2019-9498
Published: January 6, 2020
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. A remote attacker can use invalid scalar/element values to complete authentication.
This vulnerability affects the following products:
- hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.4
- hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7
Affected software
hostapd
busybox (Alpine package)
hostapd (Alpine package)
hostapd
wpa_supplicant
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Fedora
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux
Opensuse
How to mitigate CVE-2019-9498
hostapd - update to 2.8
hostapd (Alpine package) - update to 2.7-r4
hostapd - addressed in versions 2.7-1.el7, 2.7-2.fc28, 2.7-2.fc29, 2.7-2.fc30
wpa_supplicant - update to 2.7-5.fc30
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/
- https://seclists.org/bugtraq/2019/May/40
- https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.asc
- https://w1.fi/security/2019-4/
- https://www.synology.com/security/advisory/Synology_SA_19_16
Related Security Bulletins
- Multiple vulnerabilities in WPA3 hostapd and wpa_supplicant
- OpenSUSE Linux update for hostapd
- Permissions, Privileges, and Access Controls in hostapd (Alpine package)
- Permissions, Privileges, and Access Controls in busybox (Alpine package)
- SUSE update for wpa_supplicant
- Fedora 30 update for wpa_supplicant
- Fedora 30 update for hostapd
- Fedora 29 update for hostapd
- Fedora 28 update for hostapd
- Fedora EPEL 7 update for hostapd