VDB
CVE-2012-4445
CVE-2012-4445
PUBLISHED
CVSS 4.300000190734863 MEDIUM
Heap-based buffer overflow in the eap_server_tls_process_fragment function in eap_server_tls_common.c in the EAP authentication server in hostapd 0.6 through 1.0 allows remote attackers to cause a denial of service (crash or abort) via a small "TLS Message Length" value in an EAP-TLS message with the "More Fragments" flag set.
EPSS 5.32% · 90.2th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
5.32%
90.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| w1.fi | hostapd | 0.6.3, 0.6.4, 0.6.7 |
| n/a | n/a | n/a |
Timeline
- Oct 10, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- http://www.pre-cert.de/advisories/PRE-SA-2012-07.txt url
- http://w1.fi/gitweb/gitweb.cgi?p=hostap.git%3Ba=commitdiff%3Bh=586c446e0ff42ae00315b014924ec669023bd8de url
- [oss-security] 20121008 [PRE-SA-2012-07] hostapd: Missing EAP-TLS message length validation mailing-list
- 50805 third-party-advisory
- DSA-2557 vendor-advisory
- 1027808 vdb
- MDVSA-2012:168 vendor-advisory
- 86051 vdb
- 55826 vdb
- FreeBSD-SA-12:07 vendor-advisory
- hostapd-eaptls-dos(79104) vdb
- 50888 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-4445 advisory
- http://w1.fi/gitweb/gitweb.cgi?p=hostap.git;a=commitdiff;h=586c446e0ff42ae00315b014924ec669023bd8de url