Rory McNamara reported a local privilege escalation in wpasupplicant: A user able to escalate to the netdev group can load arbitrary shared object files in the context of the wpa_supplicant process running as root. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5739-1
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2581-1
security fix for CVE-2021-0326 see also: https://w1.fi/security/2020-2/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-5f268ab238 2021-02-07 01:31:59.042697 --------------------------------------------------------------------------------Name : wpa_supplicant Product : Fedora 33 Version : 2.9 Release : 7.fc33 URL : http://w1.fi/wpa_supplicant/ Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver. --------------------------------------------------------------------------------Update Information: security fix for CVE-2021-0326 see also: https://w1.fi/security/2020-2/ --------------------------------------------------------------------------------ChangeLog: * Thu Feb 4 2021 Davide Caratti - 1:2.9-7 - Fix copying of secondary device types for P2P group client (CVE-2021-0326) --------------------------------------------------------------------------------References: [ 1 ] Bug #1925152 - CVE-2021-0326 wpa_supplicant: P2P group information processing vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1925152 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-5f268ab238' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.