hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hostapd | W1.fi | * | 2.6 (excluding) |
Wpa | Ubuntu | esm-infra-legacy/trusty | * |
Wpa | Ubuntu | esm-infra/xenial | * |
Wpa | Ubuntu | trusty | * |
Wpa | Ubuntu | trusty/esm | * |
Wpa | Ubuntu | upstream | * |
Wpa | Ubuntu | xenial | * |