CVE-2021-30004

Name
CVE-2021-30004
Description
In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tls/pkcs1.c and tls/x509v3.c.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://w1.fi/cgit/hostap/commit/?id=a0541334a6394f8237a4393b7372693cd7e96f15

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:w1.fi:hostapd:2.9:*:*:*:*:*:*:* hostapd == None == 2.9
cpe:2.3:a:w1.fi:wpa_supplicant:2.9:*:*:*:*:*:*:* wpa_supplicant == None == 2.9

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
wpa_supplicant 3.13-main 2.9-r11 Natanael Copa <ncopa@alpinelinux.org> fixed
wpa_supplicant 3.12-main 2.9-r8 Natanael Copa <ncopa@alpinelinux.org> fixed
hostapd 3.11-main 2.9-r3 Natanael Copa <ncopa@alpinelinux.org> fixed
wpa_supplicant 3.11-main 2.9-r8 Natanael Copa <ncopa@alpinelinux.org> fixed
wpa_supplicant 3.14-main 2.9-r14 Natanael Copa <ncopa@alpinelinux.org> fixed
wpa_supplicant 3.15-main 2.9-r17 Natanael Copa <ncopa@alpinelinux.org> fixed
hostapd 3.14-main 2.9-r4 Natanael Copa <ncopa@alpinelinux.org> fixed
hostapd 3.13-main 2.9-r4 Natanael Copa <ncopa@alpinelinux.org> fixed
hostapd 3.12-main 2.9-r4 Natanael Copa <ncopa@alpinelinux.org> fixed