| Summary: | wpa_supplicant new security issue CVE-2018-14526 | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | normal | ||
| Priority: | Normal | CC: | geiger.david68210, marja11, sysadmin-bugs, tmb |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | mga6-64-ok, mga6-32-ok | ||
| Source RPM: | wpa_supplicant-2.6-5.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-08-09 03:53:59 CEST
David Walser
2018-08-09 03:54:11 CEST
Whiteboard:
(none) =>
MGA6TOO Assigning to the registered maintainer. Assignee:
bugsquad =>
tmb Fedora has issued an advisory for this today (August 16): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PEFP3OPDXRDJ2KHPPUJVDHUNXFNZFN7Q/ Done for Cauldron! For mga6 can I sync it with Cauldron one to switch the gui to Qt5? CC:
(none) =>
geiger.david68210 (In reply to David GEIGER from comment #3) > Done for Cauldron! > Thanks. > For mga6 can I sync it with Cauldron one to switch the gui to Qt5? Go ahead. So done also for mga6 adding the patch and porting the gui to Qt5! Advisory: ======================== Updated wpa_supplicant packages fix security vulnerability: An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information (CVE-2018-14526). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14526 https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/PEFP3OPDXRDJ2KHPPUJVDHUNXFNZFN7Q/ ======================== Updated packages in core/updates_testing: ======================== wpa_supplicant-2.6-1.2.mga6 wpa_supplicant-gui-2.6-1.2.mga6 from wpa_supplicant-2.6-1.2.mga6.src.rpm CC:
(none) =>
tmb Works here on x86_64 Whiteboard:
(none) =>
MGA6-64-OK
Thomas Backlund
2018-08-17 23:11:39 CEST
Keywords:
(none) =>
advisory works on 32bit too, validating Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0348.html Resolution:
(none) =>
FIXED |