CVE-2019-9494
published 2019-04-17CVE-2019-9494: The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access…
PriorityP334medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
3.74%
88.6th percentile
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | freeradius | < freeradius 3.0.20+dfsg-1 (bookworm) | freeradius 3.0.20+dfsg-1 (bookworm) |
| debian | wpa | < wpa 2:2.10-1 (bookworm) | wpa 2:2.10-1 (bookworm) |
| debian | wpa | < wpa 2:2.7+git20190128+0c1e29f-4 (bookworm) | wpa 2:2.7+git20190128+0c1e29f-4 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| freebsd | freebsd | — | — |
| freebsd | freebsd | — | — |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | >= 0 < 3.0.20+dfsg-1 | 3.0.20+dfsg-1 |
| freeradius | freeradius | 3.0.0 – 3.0.19 | — |
| msrc | cbl2_wpa_supplicant_2.10-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_wpa_supplicant_2.10-1_on_cbl_mariner_1.0 | — | — |
| opensuse | backports_sle | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| synology | radius_server | — | — |
| synology | router_manager | < 1.2.3-8017 | 1.2.3-8017 |
| synology | router_manager | < 1.2.3-8087 | 1.2.3-8087 |
| w1.fi | hostapd | < 2.10 | 2.10 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_msrc9.8CRITICAL
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
wpa_supplicant: SAE side channel attacks as a result of cache access patterns
vendor_redhat·2022-01-17·CVSS 5.9
CVE-2022-23303 [MEDIUM] CWE-924 wpa_supplicant: SAE side channel attacks as a result of cache access patterns
wpa_supplicant: SAE side channel attacks as a result of cache access patterns
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. The highest threat from this vulnerability is to availability, confidentiality and integrity.
Package: wpa_supplicant (Red Hat Enterprise Linux 6) - Out of support scope
Package: wpa_supplicant (Red Hat Enterprise Linux 7) - Not affected
Package: wpa_supplicant (Red Hat Enterprise Linux 8) - Not affected
Microsoft
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an inco
vendor_msrc·2022-01-11·CVSS 9.8
CVE-2022-23303 [MEDIUM] CWE-203 The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an inco
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is i
Debian
CVE-2022-23303: wpa - The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10...
vendor_debian·2022·CVSS 5.9
CVE-2022-23303 [MEDIUM] CVE-2022-23303: wpa - The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10...
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
Scope: local
bookworm: resolved (fixed in 2:2.10-1)
bullseye: resolved (fixed in 2:2.9.0-21+deb11u3)
forky: resolved (fixed in 2:2.10-1)
sid: resolved (fixed in 2:2.10-1)
trixie: resolved (fixed in 2:2.10-1)
Red Hat
freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
vendor_redhat·2019-08-03·CVSS 6.5
CVE-2019-13456 [MEDIUM] CWE-200 freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
An information leak was discovered in the implementation of EAP-pwd in freeradius. An attacker could initiate several EAP-pwd handshakes to leak information, which can then be used to recover the user's WiFi password by performing dictionary and brute-force attacks.
Statement: This issue did not affect the versions of freeradius as shipped with Red Ha
BSD
FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant
bsd_advisories·2019-05-14·CVSS 5.9
CVE-2019-11555 [MEDIUM] FreeBSD-SA-19:03.wpa: Multiple vulnerabilities in hostapd and wpa_supplicant
FreeBSD-SA-19:03.wpa Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in hostapd and wpa_supplicant
Category: contrib
Module: wpa
Announced: 2019-05-14
Affects: All supported versions of FreeBSD.
Corrected: 2019-05-01 01:42:38 UTC (stable/12, 12.0-STABLE)
2019-05-14 22:57:29 UTC (releng/12.0, 12.0-RELEASE-p4)
2019-05-01 01:43:17 UTC (stable/11, 11.2-STABLE)
2019-05-14 22:59:32 UTC (releng/11.2, 11.2-RELEASE-p10)
CVE Name: CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499, CVE-2019-11555
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I. Background
Wi-Fi Protected Access II (WPA2) is a security protocol deve
Red Hat
wpa_supplicant: EAP-pwd cache side-channel attack
vendor_redhat·2019-04-10·CVSS 5.9
CVE-2019-9495 [MEDIUM] CWE-203 wpa_supplicant: EAP-pwd cache side-channel attack
wpa_supplicant: EAP-pwd cache side-channel attack
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
A flaw was found in wpa_supplicant. Side channel attacks were recently discovered in the SAE implementations used by b
Red Hat
wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake
vendor_redhat·2019-04-10·CVSS 5.9
CVE-2019-9494 [MEDIUM] CWE-385 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake
wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
Statement: This issue did not affect the versions of wpa_supplicant as shipped with Red Hat Enterprise Linux 5, 6 as they did not include support for SAE (Simultaneous
Authentication of Equals).
This issue did not affect the versions of wpa_supplicant as shipped with Red Hat Enterprise L
Debian
CVE-2019-13456: freeradius - In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes ...
vendor_debian·2019·CVSS 6.5
CVE-2019-13456 [MEDIUM] CVE-2019-13456: freeradius - In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes ...
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
Scope: local
bookworm: resolved (fixed in 3.0.20+dfsg-1)
bullseye: resolved (fixed in 3.0.20+dfsg-1)
forky: resolved (fixed in 3.0.20+dfsg-1)
sid: resolved (fixed in 3.0.20+dfsg-1)
trixie: resolved (fixed in 3.0.20+dfsg-1)
Debian
CVE-2019-9494: wpa - The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side ...
vendor_debian·2019·CVSS 5.9
CVE-2019-9494 [MEDIUM] CVE-2019-9494: wpa - The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side ...
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
Scope: local
bookworm: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
bullseye: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
forky: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
sid: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
trixie: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
Debian
CVE-2019-9495: wpa - The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to s...
vendor_debian·2019·CVSS 5.9
CVE-2019-9495 [MEDIUM] CVE-2019-9495: wpa - The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to s...
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
Scope: local
bookworm: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
bullseye: resolved (fixed in 2:2.7+git20190128+0c1e29f-4)
forky: resolved (fixed in 2:2.7+git201901
GHSA
GHSA-qwvf-9vg7-643x: In FreeRADIUS 3
ghsa_unreviewed·2022-05-24·CVSS 5.9
CVE-2019-13456 [MEDIUM] CWE-200 GHSA-qwvf-9vg7-643x: In FreeRADIUS 3
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
GHSA
GHSA-p694-q9qw-q238: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
ghsa_unreviewed·2022-05-13·CVSS 5.9
CVE-2019-9495 [MEDIUM] CWE-203 GHSA-p694-q9qw-q238: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
GHSA
GHSA-cvqc-p7v4-m9pm: The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache
ghsa_unreviewed·2022-05-13
CVE-2019-9494 [MEDIUM] CWE-203 GHSA-cvqc-p7v4-m9pm: The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
GHSA
GHSA-8v55-rm6p-87p5: The implementations of SAE in hostapd before 2
ghsa_unreviewed·2022-02-15·CVSS 5.9
CVE-2022-23303 [MEDIUM] CWE-203 GHSA-8v55-rm6p-87p5: The implementations of SAE in hostapd before 2
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
OSV
CVE-2022-23303: The implementations of SAE in hostapd before 2
osv·2022-01-17·CVSS 5.9
CVE-2022-23303 [MEDIUM] CVE-2022-23303: The implementations of SAE in hostapd before 2
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.
OSV
CVE-2019-13456: In FreeRADIUS 3
osv·2019-12-03·CVSS 6.5
CVE-2019-13456 [MEDIUM] CVE-2019-13456: In FreeRADIUS 3
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
OSV
CVE-2019-9494: The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache
osv·2019-04-17·CVSS 5.9
CVE-2019-9494 [MEDIUM] CVE-2019-9494: The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE support and wpa_supplicant with SAE support prior to and including version 2.7 are affected.
OSV
CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
osv·2019-04-17·CVSS 5.9
CVE-2019-9495 [MEDIUM] CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache. Weak passwords may be cracked. Versions of hostapd/wpa_supplicant 2.7 and newer, are not vulnerable to the timing attack described in CVE-2019-9494. Both hostapd with EAP-pwd support and wpa_supplicant with EAP-pwd support prior to and including version 2.7 are affected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack
bugzilla·2019-04-11·CVSS 5.9
CVE-2019-9495 [MEDIUM] CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack
CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack
A number of potential side channel attacks were recently discovered in the SAE implementations used by both hostapd and wpa_supplicant (see CVE-2019-9494). EAP-pwd uses a similar design for deriving PWE from the password and while a specific attack against EAP-pwd is not yet known to be tested, there is no reason to believe that the EAP-pwd implementation would be immune against the type of cache attack that was identified for the SAE implementation. Since the EAP-pwd implementation in hostapd (EAP server) and wpa_supplicant (EAP peer) does not support MODP groups, the timing attack described against SAE is not applicable for the EAP-pwd implementation.
References:
https://wpa3.mathyvanhoef.com/
https://w1.fi/security/2019-
Bugzilla
CVE-2019-9494 hostapd: wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [epel-all]
bugzilla·2019-04-11·CVSS 5.9
CVE-2019-9494 [MEDIUM] CVE-2019-9494 hostapd: wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [epel-all]
CVE-2019-9494 hostapd: wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit mess
Bugzilla
CVE-2019-9494 hostapd: wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [fedora-all]
bugzilla·2019-04-11·CVSS 5.9
CVE-2019-9494 [MEDIUM] CVE-2019-9494 hostapd: wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [fedora-all]
CVE-2019-9494 hostapd: wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2019-9494 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake
bugzilla·2019-04-11·CVSS 5.9
CVE-2019-9494 [MEDIUM] CVE-2019-9494 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake
CVE-2019-9494 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake
A number of potential side channel (Cache and Timing) attacks were discovered in the SAE implementations used by both hostapd (AP) and wpa_supplicant (infrastructure BSS station/mesh station). SAE (Simultaneous Authentication of Equals) is also known as WPA3-Personal. The discovered side channel attacks may be able to leak information about the used password based on observable timing differences and cache access patterns. This might result in full password recovery when combined with an offline dictionary attack and if the password is not strong enough to protect against dictionary attacks.
References:
https://w1.fi/security/2019-1/sae-side-channel-attacks.txt
https://w
Bugzilla
CVE-2019-9494 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [fedora-all]
bugzilla·2019-04-11·CVSS 5.9
CVE-2019-9494 [MEDIUM] CVE-2019-9494 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [fedora-all]
CVE-2019-9494 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.htmlhttp://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/https://seclists.org/bugtraq/2019/May/40https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.aschttps://w1.fi/security/2019-1/https://www.synology.com/security/advisory/Synology_SA_19_16http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00021.htmlhttp://packetstormsecurity.com/files/152914/FreeBSD-Security-Advisory-FreeBSD-SA-19-03.wpa.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/56OBBOJJSKRTDGEXZOVFSTP4HDSDBLAE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVMJOFEYBGXZLFF5IOLW67SSOPKFEJP3/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TDOZGR3T7FVO5JSZWK2QPR7AOFIEJTIZ/https://seclists.org/bugtraq/2019/May/40https://security.FreeBSD.org/advisories/FreeBSD-SA-19:03.wpa.aschttps://w1.fi/security/2019-1/https://www.synology.com/security/advisory/Synology_SA_19_16
2019-04-17
Published