* bsc#1240893 Cross-References: * CVE-2025-31492 . # Security update for apache2-mod_auth_openidc Announcement ID: SUSE-SU-2025:1465-1 Release Date: 2025-05-05T21:04:41Z Rating: important References: * bsc#1240893 Cross-References: * CVE-2025-31492 CVSS scores: * CVE-2025-31492 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-31492 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-31492 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for apache2-mod_auth_openidc fixes the following issues: * CVE-2025-31492: Fixed a bug where OIDCProviderAuthRequestMethod POSTs can leak protected data. (bsc#1240893) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-1465=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1465=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * apache2-mod_auth_openidc-debugsource-2.4.0-7.19.1 * apache2-mod_auth_openidc-2.4.0-7.19.1 * apache2-mod_auth_openidc-debuginfo-2.4.0-7.19.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) *apache2-mod_auth_openidc-debugsource-2.4.0-7.19.1 * apache2-mod_auth_openidc-2.4.0-7.19.1 * apache2-mod_auth_openidc-debuginfo-2.4.0-7.19.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31492.html * https://bugzilla.suse.com/show_bug.cgi?id=1240893 . Patch for CVE-2025-31492 in apache2-mod_auth_openidc available for SUSE users. Urgent update recommended to prevent potential data breach.. apache2-mod_auth_openidc, SUSE Linux, CVE-2025-31492, security patch, authentication issue. . Severity: Important. LinuxSecurity.com Team
Update to version 2.9 from upstream Security fix for CVE-2019-13377. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-97e9040197 2019-08-19 01:01:06.548650 --------------------------------------------------------------------------------Name : hostapd Product : Fedora 30 Version : 2.9 Release : 1.fc30 URL : http://w1.fi/hostapd/ Summary : IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator Description : hostapd is a user space daemon for access point and authentication servers. It implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP Authenticators and RADIUS authentication server. hostapd is designed to be a "daemon" program that runs in the back-ground and acts as the backend component controlling authentication. hostapd supports separate frontend programs and an example text-based frontend, hostapd_cli, is included with hostapd. --------------------------------------------------------------------------------Update Information: Update to version 2.9 from upstream Security fix for CVE-2019-13377 --------------------------------------------------------------------------------ChangeLog: * Fri Aug 9 2019 John W. Linville - 2.9-1 - Update to version 2.9 from upstream * Thu Jul 25 2019 Fedora Release Engineering - 2.8-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Wed Jul 3 2019 Lubomir Rintel - 2.8-2 - Enable SAE * Wed May 15 2019 John W. Linville - 2.8-1 - Update to version 2.8 from upstream - Drop obsoleted patches * Fri Apr 12 2019 John W. Linville - 2.7-2 - Bump N-V-R for rebuild * Fri Apr 12 2019 John W. Linville - 2.7-1 - Update to version 2.7 from upstream - Remove obsolete patches for NL80211_ATTR_SMPS_MODE encoding and KRACK - Fix CVE-2019-9494 (cache attack against SAE) - Fix CVE-2019-9495 (cache attack against EAP-pwd) - Fix CVE-2019-9496 (SAE confirm missing state validation in hostapd/AP) -Fix CVE-2019-9497 (EAP-pwd server not checking for reflection attack) - Fix CVE-2019-9498 (EAP-pwd server missing commit validation for scalar/element) - Fix CVE-2019-9499 (EAP-pwd peer missing commit validation for scalar/element) --------------------------------------------------------------------------------References: [ 1 ] Bug #1737665 - CVE-2019-13377 wpa_supplicant: Timing-based side-channel attack against WPA3's Dragonfly handshake when using Brainpool curves https://bugzilla.redhat.com/show_bug.cgi?id=1737665 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-97e9040197' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-28d3ca93d2 2019-06-07 00:57:55.622025 --------------------------------------------------------------------------------Name : hostapd Product : Fedora 30 Version : 2.8 Release : 1.fc30 URL : http://w1.fi/hostapd/ Summary : IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator Description : hostapd is a user space daemon for access point and authentication servers. It implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP Authenticators and RADIUS authentication server. hostapd is designed to be a "daemon" program that runs in the back-ground and acts as the backend component controlling authentication. hostapd supports separate frontend programs and an example text-based frontend, hostapd_cli, is included with hostapd. --------------------------------------------------------------------------------Update Information: Update to version 2.8 from upstream, Security fix for [CVE-2019-11555] --------------------------------------------------------------------------------ChangeLog: * Wed May 15 2019 John W. Linville - 2.8-1 - Update to version 2.8 from upstream - Drop obsoleted patches * Fri Apr 12 2019 John W. Linville - 2.7-2 - Bump N-V-R for rebuild * Fri Apr 12 2019 John W. Linville - 2.7-1 - Update to version 2.7 from upstream - Remove obsolete patches for NL80211_ATTR_SMPS_MODE encoding and KRACK - Fix CVE-2019-9494 (cache attack against SAE) - Fix CVE-2019-9495 (cache attack against EAP-pwd) - Fix CVE-2019-9496 (SAE confirm missing state validation in hostapd/AP) - Fix CVE-2019-9497 (EAP-pwd server not checking for reflection attack) - Fix CVE-2019-9498 (EAP-pwd server missing commit validation for scalar/element) - Fix CVE-2019-9499 (EAP-pwd peer missing commit validation forscalar/element) --------------------------------------------------------------------------------References: [ 1 ] Bug #1703417 - CVE-2019-11555 wpa_supplicant: NULL pointer dereference due to improper fragmentation reassembly state validation in EAP-pwd implementation https://bugzilla.redhat.com/show_bug.cgi?id=1703417 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-28d3ca93d2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.