Linux Security
    Linux Security
    Linux Security

    Fedora 30: hostapd Security Update

    Date
    107
    Posted By
    Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]
    --------------------------------------------------------------------------------
    Fedora Update Notification
    FEDORA-2019-28d3ca93d2
    2019-06-07 00:57:55.622025
    --------------------------------------------------------------------------------
    
    Name        : hostapd
    Product     : Fedora 30
    Version     : 2.8
    Release     : 1.fc30
    URL         : https://w1.fi/hostapd
    Summary     : IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator
    Description :
    hostapd is a user space daemon for access point and authentication servers. It
    implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP
    Authenticators and RADIUS authentication server.
    
    hostapd is designed to be a "daemon" program that runs in the back-ground and
    acts as the backend component controlling authentication. hostapd supports
    separate frontend programs and an example text-based frontend, hostapd_cli, is
    included with hostapd.
    
    --------------------------------------------------------------------------------
    Update Information:
    
    Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]
    --------------------------------------------------------------------------------
    ChangeLog:
    
    * Wed May 15 2019 John W. Linville  - 2.8-1
    - Update to version 2.8 from upstream
    - Drop obsoleted patches
    * Fri Apr 12 2019 John W. Linville  - 2.7-2
    - Bump N-V-R for rebuild
    * Fri Apr 12 2019 John W. Linville  - 2.7-1
    - Update to version 2.7 from upstream
    - Remove obsolete patches for NL80211_ATTR_SMPS_MODE encoding and KRACK
    - Fix CVE-2019-9494 (cache attack against SAE)
    - Fix CVE-2019-9495 (cache attack against EAP-pwd)
    - Fix CVE-2019-9496 (SAE confirm missing state validation in hostapd/AP)
    - Fix CVE-2019-9497 (EAP-pwd server not checking for reflection attack)
    - Fix CVE-2019-9498 (EAP-pwd server missing commit validation for scalar/element)
    - Fix CVE-2019-9499 (EAP-pwd peer missing commit validation for scalar/element)
    --------------------------------------------------------------------------------
    References:
    
      [ 1 ] Bug #1703417 - CVE-2019-11555 wpa_supplicant: NULL pointer dereference due to improper fragmentation reassembly state validation in EAP-pwd implementation
            https://bugzilla.redhat.com/show_bug.cgi?id=1703417
    --------------------------------------------------------------------------------
    
    This update can be installed with the "dnf" update program. Use
    su -c 'dnf upgrade --advisory FEDORA-2019-28d3ca93d2' at the command
    line. For more information, refer to the dnf documentation available at
    https://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
    
    All packages are signed with the Fedora Project GPG key. More details on the
    GPG keys used by the Fedora Project can be found at
    https://fedoraproject.org/keys
    --------------------------------------------------------------------------------
    _______________________________________________
    package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it.
    To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it.
    Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
    List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
    List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it.
    

    Advisories

    LinuxSecurity Poll

    How are you contributing to Open Source?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 4 answer(s).
    /main-polls/37-how-are-you-contributing-to-open-source?task=poll.vote&format=json
    37
    radio
    [{"id":"127","title":"I'm involved with the development of an open-source project(s).","votes":"1","type":"x","order":"1","pct":100,"resources":[]},{"id":"128","title":"I've reported vulnerabilities I've discovered in open-source code.","votes":"0","type":"x","order":"2","pct":0,"resources":[]},{"id":"129","title":"I've provided developers with feedback on their projects.","votes":"0","type":"x","order":"3","pct":0,"resources":[]},{"id":"130","title":"I've helped another community member get started contributing to Open Source.","votes":"0","type":"x","order":"4","pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350


    VIEW MORE POLLS

    bottom 200

    Please enable / Bitte aktiviere JavaScript!
    Veuillez activer / Por favor activa el Javascript![ ? ]

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.