Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian Security Update DSA-3999-1: Serious WPA Authentication Issue

debian
Calendar Grey October 16, 2017
Debian Logo
Uncover various weaknesses in the WPA protocol impacting Wi-Fi security and enhance your networks.
Mathy Vanhoef of the imec-DistriNet research group of KU Leuven discovered multiple vulnerabilities in the WPA protocol, used for authentication in wireless networks

Summary

An attacker exploiting the vulnerabilities could force the vulnerable system to
reuse cryptographic session keys, enabling a range of cryptographic attacks
against the ciphers used in WPA1 and WPA2.

More information can be found in the researchers's paper, Key Reinstallation
Attacks: Forcing Nonce Reuse in WPA2.

CVE-2017-13077: reinstallation of the pairwise key in the Four-way handshake
CVE-2017-13078: reinstallation of the group key in the Four-way handshake
CVE-2017-13079: reinstallation of the integrity group key in the Four-way
handshake
CVE-2017-13080: reinstallation of the group key in the Group Key handshake
CVE-2017-13081: reinstallation of the integrity group key in the Group Key
handshake
CVE-2017-13082: accepting a retransmitted Fast BSS Transition Reassociation
Request and reinstalling the pairwise key while processing it
CVE-2017-13086: reinstallation of the Tunneled Direct-Link Setup (TDLS) PeerKey
(TPK) key in the TDL...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: wpa
CVE ID: CVE-2017-13077 CVE-2017-13078 CVE-2017-13079 CVE-2017-13080

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here