Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Fedora 22: 2015-6898 Critical: wpa_supplicant P2P Security Issue

fedora
Calendar Grey April 28, 2015
Dist Fedora Esm H88
Essential patch released for wpa_supplicant resolves CVE-2015-1863 flaw affecting Wi-Fi operations in Fedora ecosystem.
This update addresses a security vulnerability identified as CVE-2015-1863

Summary

wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support

for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA

component that is used in the client stations. It implements key negotiation

with a WPA Authenticator and it controls the roaming and IEEE 802.11

authentication/association of the wlan driver.

Update Information:

This update addresses a security vulnerability identified as CVE-2015-1863 . More information on this vulnerability is provided by upstream at https://w1.fi/security/2015-1/wpa_supplicant-p2p-ssid-overflow.txt . An extract:

Attacker (or a system controlled by the attacker) needs to be within radio range of the vulnerable system to send a suitably constructed management frame that triggers a P2P peer device information to be created or updated.

The vulnerability is easiest to exploit while the device has started an active P2P operation (e.g., has ongoing P2P_FIND or P2P_LISTEN control interface command in progress). However, it may be possible, though significantly more difficult, to trigger this even without any active P2P operation in progress.

Change Log

References

Fedora Update Notification FEDORA-2015-6898 2015-04-26 07:32:47
Name : wpa_supplicant Product : Fedora 22 Version : 2.3 Release : 3.fc22 URL : http://w1.fi/wpa_supplicant/ Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver.

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update wpa_supplicant' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: wpa_supplicant
Product: Fedora 22
Version: 2.3
Release: 3.fc22
Summary: WPA/WPA2/IEEE 802.1X Supplicant

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here