FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

FreeBSD -- EAP-pwd missing commit validation

Affected packages
12.0 <= FreeBSD < 12.0_3
11.2 <= FreeBSD < 11.2_9
wpa_supplicant < 2.8
hostapd < 2.8

Details

VuXML ID 2da3cb25-6571-11e9-8e67-206a8a720317
Discovery 2019-04-10
Entry 2019-04-23
Modified 2019-07-30

Problem Description:

EAP-pwd implementation in hostapd (EAP server) and wpa_supplicant (EAP peer) does not to validate the received scalar and element values in EAP-pwd-Commit messages properly. This could result in attacks that would be able to complete EAP-pwd authentication exchange without the attacker having to know the used password.

See https://w1.fi/security/2019-4/eap-pwd-missing-commit-validation.txt for a detailed description of the bug.

Impact:

All wpa_supplicant and hostapd versions with EAP-pwd support.

References

CVE Name CVE-2019-9497
CVE Name CVE-2019-9498
CVE Name CVE-2019-9499
FreeBSD Advisory SA-19:03.wpa