High severity7.5NVD Advisory· Published Feb 28, 2020· Updated Jun 17, 2026
CVE-2019-10064
CVE-2019-10064
Description
hostapd before 2.6, in EAP mode, makes calls to the rand() and random() standard library functions without any preceding srand() or srandom() call, which results in inappropriate use of deterministic values. This was fixed in conjunction with CVE-2016-10743.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- hostapd/hostapddescription
Patches
Vulnerability mechanics
References
7- w1.fi/cgit/hostap/commit/nvdPatchThird Party Advisory
- packetstormsecurity.com/files/156573/Hostapd-Insufficient-Entropy.htmlnvdExploitThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2020/Feb/26nvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2020/02/27/1nvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2020/02/27/2nvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/03/msg00010.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/08/msg00013.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.