Bug 23781

Summary: hostapd new security issue CVE-2018-14526
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Thomas Backlund <tmb>
Status: RESOLVED OLD QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: geiger.david68210, marja11, mhrambo3501, tmb
Version: 6   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Source RPM: hostapd-2.6-4.mga7.src.rpm CVE:
Status comment:

Description David Walser 2018-10-29 02:39:17 CET
+++ This bug was initially created as a clone of Bug #23412 +++

Upstream has issued an advisory today (August 8):
https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt

Patches are available in the same directory and it will be fixed in 2.7.

Mageia 6 is also affected.

We fixed this for wpa_supplicant, but hostapd is apparently affected too.

openSUSE has issued an advisory for this on October 27:
https://lists.opensuse.org/opensuse-updates/2018-10/msg00222.html
David Walser 2018-10-29 02:39:30 CET

Whiteboard: (none) => MGA6TOO

Comment 1 Marja Van Waes 2018-10-29 08:41:55 CET
Assigning to the registered maintainer.

Assignee: bugsquad => tmb
CC: (none) => marja11

Comment 2 David Walser 2019-01-01 01:46:35 CET
I updated it to 2.7 in Cauldron.

Whiteboard: MGA6TOO => (none)
Version: Cauldron => 6

Comment 3 Mike Rambo 2019-11-06 13:44:19 CET
Mageia 6 is EOL.

Resolution: (none) => OLD
CC: (none) => mrambo
Status: NEW => RESOLVED