CVE Vulnerabilities

CVE-2019-10064

Insufficient Entropy

Published: Feb 28, 2020 | Modified: Jan 01, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
LOW

hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

Name Vendor Start Version End Version
Hostapd W1.fi * 2.6 (excluding)
Wpa Ubuntu esm-infra-legacy/trusty *
Wpa Ubuntu esm-infra/xenial *
Wpa Ubuntu trusty *
Wpa Ubuntu trusty/esm *
Wpa Ubuntu upstream *
Wpa Ubuntu xenial *

Potential Mitigations

References