auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.
References
Link | Resource |
---|---|
https://roy.marples.name/git/dhcpcd.git/commit/?id=cfde89ab66cb4e5957b1c4b68ad6a9449e2784da | Third Party Advisory |
https://roy.marples.name/git/dhcpcd.git/commit/?id=aee631aadeef4283c8a749c1caf77823304acf5e | Patch Third Party Advisory |
https://roy.marples.name/git/dhcpcd.git/commit/?id=7121040790b611ca3fbc400a1bbcd4364ef57233 | Patch Third Party Advisory |
https://roy.marples.name/archives/dhcpcd-discuss/0002415.html | Third Party Advisory |
http://www.securityfocus.com/bid/108090 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2019-04-28 09:29
Updated : 2021-07-21 04:39
NVD link : CVE-2019-11578
Mitre link : CVE-2019-11578
JSON object : View
CWE
CWE-203
Observable Discrepancy
Products Affected
dhcpcd_project
- dhcpcd