CVE-2019-10064
wpa - security update
7.5
HIGH
CVSS 3.1
EPSS 1.4%
Description
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.
How to fix CVE-2019-10064
To remediate CVE-2019-10064, upgrade the affected package to a fixed version below.
- Debian/wpa—upgrade to 2:2.6-7 or later
- —upgrade to 2.3-1+deb8u10 or later
- —upgrade to 2:2.4-1+deb9u7 or later
Is CVE-2019-10064 being exploited?
Low — EPSS is 1.4%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2:2.6-7
- from 0, < 2.3-1+deb8u10
- from 0, < 2:2.4-1+deb9u7
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |