Fedora 30: hostapd FEDORA-2019-2265b5ae86

    Date09 Nov 2019
    CategoryFedora
    148
    Posted ByLinuxSecurity Advisories
    Fedora Large
    Security fix CVE-2019-16275 (AP mode PMF disconnection protection bypass)
    --------------------------------------------------------------------------------
    Fedora Update Notification
    FEDORA-2019-2265b5ae86
    2019-11-09 22:37:54.009125
    --------------------------------------------------------------------------------
    
    Name        : hostapd
    Product     : Fedora 30
    Version     : 2.9
    Release     : 2.fc30
    URL         : http://w1.fi/hostapd
    Summary     : IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator
    Description :
    hostapd is a user space daemon for access point and authentication servers. It
    implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP
    Authenticators and RADIUS authentication server.
    
    hostapd is designed to be a "daemon" program that runs in the back-ground and
    acts as the backend component controlling authentication. hostapd supports
    separate frontend programs and an example text-based frontend, hostapd_cli, is
    included with hostapd.
    
    --------------------------------------------------------------------------------
    Update Information:
    
    Security fix CVE-2019-16275 (AP mode PMF disconnection protection bypass)
    --------------------------------------------------------------------------------
    ChangeLog:
    
    * Wed Oct 30 2019 John W. Linville  - 2.9-2
    - Fix CVE-2019-16275 (AP mode PMF disconnection protection bypass)
    * Fri Aug  9 2019 John W. Linville  - 2.9-1
    - Update to version 2.9 from upstream
    * Thu Jul 25 2019 Fedora Release Engineering  - 2.8-3
    - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
    * Wed Jul  3 2019 Lubomir Rintel  - 2.8-2
    - Enable SAE
    * Wed May 15 2019 John W. Linville  - 2.8-1
    - Update to version 2.8 from upstream
    - Drop obsoleted patches
    * Fri Apr 12 2019 John W. Linville  - 2.7-2
    - Bump N-V-R for rebuild
    * Fri Apr 12 2019 John W. Linville  - 2.7-1
    - Update to version 2.7 from upstream
    - Remove obsolete patches for NL80211_ATTR_SMPS_MODE encoding and KRACK
    - Fix CVE-2019-9494 (cache attack against SAE)
    - Fix CVE-2019-9495 (cache attack against EAP-pwd)
    - Fix CVE-2019-9496 (SAE confirm missing state validation in hostapd/AP)
    - Fix CVE-2019-9497 (EAP-pwd server not checking for reflection attack)
    - Fix CVE-2019-9498 (EAP-pwd server missing commit validation for scalar/element)
    - Fix CVE-2019-9499 (EAP-pwd peer missing commit validation for scalar/element)
    --------------------------------------------------------------------------------
    References:
    
      [ 1 ] Bug #1767023 - CVE-2019-16275 wpa_supplicant: AP mode PMF disconnection protection bypass
            https://bugzilla.redhat.com/show_bug.cgi?id=1767023
    --------------------------------------------------------------------------------
    
    This update can be installed with the "dnf" update program. Use
    su -c 'dnf upgrade --advisory FEDORA-2019-2265b5ae86' at the command
    line. For more information, refer to the dnf documentation available at
    http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
    
    All packages are signed with the Fedora Project GPG key. More details on the
    GPG keys used by the Fedora Project can be found at
    https://fedoraproject.org/keys
    --------------------------------------------------------------------------------
    _______________________________________________
    package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it.
    To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it.
    Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
    List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
    List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it.
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"39","type":"x","order":"1","pct":50.65,"resources":[]},{"id":"88","title":"Should be more technical","votes":"11","type":"x","order":"2","pct":14.29,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"27","type":"x","order":"3","pct":35.06,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.