Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

openSUSE Leap 15.2: 2021:0519-1 Important Hostapd Fix for Multiple Issues

opensuse
Calendar Grey April 9, 2021
Dist Opensuse Esm H88
A new update for hostapd has been released, focusing on resolving three critical problems in openSUSE Leap 15.2 that impact both security and overall system stability.
An update that fixes three vulnerabilities is now available

Description

This update for hostapd fixes the following issues:

- CVE-2021-30004: forging attacks may occur because AlgorithmIdentifier

parameters are mishandled in tls/pkcs1.c and tls/x509v3.c (boo#1184348)

- CVE-2020-12695: UPnP SUBSCRIBE misbehavior in hostapd WPS AP

(boo#1172700)

- CVE-2019-16275: AP mode PMF disconnection protection bypass (boo#1150934)

- added AppArmor profile (source apparmor-usr.sbin.hostapd)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-519=1

Package List

- openSUSE Leap 15.2 (x86_64):

hostapd-2.9-lp152.2.3.1

hostapd-debuginfo-2.9-lp152.2.3.1

hostapd-debugsource-2.9-lp152.2.3.1

References

https://www.suse.com/security/cve/CVE-2019-16275.html

https://www.suse.com/security/cve/CVE-2020-12695.html

https://www.suse.com/security/cve/CVE-2021-30004.html

https://bugzilla.suse.com/1150934

https://bugzilla.suse.com/1172700

https://bugzilla.suse.com/1184348

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0519-1
Rating: important
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here