CVE-2016-10743

NameCVE-2016-10743
Descriptionhostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1733-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
wpa (PTS)jessie2.3-1+deb8u5vulnerable
jessie (security)2.3-1+deb8u9fixed
stretch, stretch (security)2:2.4-1+deb9u4vulnerable
buster, buster (security)2:2.7+git20190128+0c1e29f-6+deb10u1fixed
bullseye, sid2:2.9-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
wpasource(unstable)2:2.6-7unimportant
wpasourcejessie2.3-1+deb8u7DLA-1733-1

Notes

https://w1.fi/cgit/hostap/commit/?id=98a516eae8260e6fd5c48ddecf8d006285da7389
There was already a 2.6 upload late in 2016 but then reverted to a 2.4 based
version and only reuploaded as 2:2.6-7 to unstable.

Search for package or bug name: Reporting problems