auth.c in dhcpcd before 7.2.1 allowed attackers to infer secrets by performing latency attacks.
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Link | Tags |
---|---|
https://roy.marples.name/archives/dhcpcd-discuss/0002415.html | third party advisory |
https://roy.marples.name/git/dhcpcd.git/commit/?id=7121040790b611ca3fbc400a1bbcd4364ef57233 | third party advisory patch |
https://roy.marples.name/git/dhcpcd.git/commit/?id=cfde89ab66cb4e5957b1c4b68ad6a9449e2784da | third party advisory |
https://roy.marples.name/git/dhcpcd.git/commit/?id=aee631aadeef4283c8a749c1caf77823304acf5e | third party advisory patch |
http://www.securityfocus.com/bid/108090 | vdb entry third party advisory |