CVE-2021-30004
Published: 02 April 2021
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
Priority
CVSS 3 base score: 5.3
Status
Package | Release | Status |
---|---|---|
wpa Launchpad, Ubuntu, Debian |
Upstream |
Needs triage
|
Ubuntu 21.04 (Hirsute Hippo) |
Not vulnerable
(code not compiled)
|
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(code not compiled)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(code not compiled)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(code not compiled)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Not vulnerable
(code not compiled)
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Not vulnerable
(code not compiled)
|
|
Patches: Upstream: https://w1.fi/cgit/hostap/commit/?id=a0541334a6394f8237a4393b7372693cd7e96f15 |
Notes
Author | Note |
---|---|
mdeslaur | this issue only affects the internal wpa ssl code. On Ubuntu, wpa is built with OpenSSL, so the affected files aren't used at all |