CNNVD-ID编号 | CNNVD-200605-093 |
CVE编号 | CVE-2006-2213 |
发布时间 | 2006-05-05 |
更新时间 | 2006-05-08 |
漏洞类型 | 其他 |
漏洞来源 | The vendor originally discovered this issue. Matteo Rosi reported this issue to Debian. |
危险等级 | 中危 |
威胁类型 | 远程 |
厂 商 | hostapd |
Hostapd 0.3.7-2可以使远程攻击者借助EAPoL帧的key_data_length 字段中的不确定值,引起拒绝服务(分段故障)。
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
hostapd hostapd 0.3.7
Debian hostapd_0.3.7-2sarge1_alpha.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_alpha.deb
Debian hostapd_0.3.7-2sarge1_amd64.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_amd64.deb
Debian hostapd_0.3.7-2sarge1_arm.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_arm.deb
Debian hostapd_0.3.7-2sarge1_hppa.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_hppa.deb
Debian hostapd_0.3.7-2sarge1_i386.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_i386.deb
Debian hostapd_0.3.7-2sarge1_ia64.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_ia64.deb
Debian hostapd_0.3.7-2sarge1_m68k.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_m68k.deb
Debian hostapd_0.3.7-2sarge1_mips.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_mips.deb
Debian hostapd_0.3.7-2sarge1_mipsel.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_mipsel.deb
Debian hostapd_0.3.7-2sarge1_powerpc.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_powerpc.deb
Debian hostapd_0.3.7-2sarge1_s390.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_s390.deb
Debian hostapd_0.3.7-2sarge1_sparc.debDebian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/h/hostapd/hostapd_0.3.7-2
sarge1_sparc.deb
hostapd hostapd-0.3.9.tar.gz
http://hostap.epitest.fi/releases/hostapd-0.3.9.tar.gz
Mandriva hostapd-0.3.7-2.1.102dk.i586.rpmMandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/
Mandriva hostapd-0.3.7-2.1.102dk.x86_64.rpmMandriva Linux 10.2:
http://wwwnew.mandriva.com/en/downloads/
Mandriva hostapd-0.3.7-2.1.20060mdk.i586.rpmMandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/
Mandriva hostapd-0.3.7-2.1.20060mdk.x86_64.rpmMandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads/
来源: VUPEN
名称: ADV-2006-1657
来源: SECUNIA
名称: 19966
来源: MISC
来源: XF
名称: hostapd-eapol-dos(26239)
来源: BID
名称: 17846
来源: OSVDB
名称: 25233
来源: MANDRAKE
名称: MDKSA-2006:088
链接:http://www.mandriva.com/security/advisories?name=MDKSA-2006:088
来源: DEBIAN
名称: DSA-1065
来源: SECUNIA
名称: 20265
来源: SECUNIA
名称: 20195