stable

hostapd-2.7-2.fc30

FEDORA-2019-eba1109acd created by linville 5 years ago for Fedora 30

Update to version 2.7 from upstream Security fix for CVE-2019-9494 (cache attack against SAE) Security fix for CVE-2019-9495 (cache attack against EAP-pwd) Security fix for CVE-2019-9496 (SAE confirm missing state validation in hostapd/AP) Security fix for CVE-2019-9497 (EAP-pwd server not checking for reflection attack) Security fix for CVE-2019-9498 (EAP-pwd server missing commit validation for scalar/element) Security fix for CVE-2019-9499 (EAP-pwd peer missing commit validation for scalar/element)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2019-eba1109acd

This update has been submitted for testing by linville.

5 years ago

This update has been pushed to testing.

5 years ago

This update has reached 3 days in testing and can be pushed to stable now if the maintainer wishes

5 years ago

This update has been submitted for batched by linville.

5 years ago

This update has been submitted for stable by bodhi.

5 years ago

This update has been pushed to stable.

5 years ago

Please login to add feedback.

Metadata
Type
security
Severity
high
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
5 years ago
in testing
5 years ago
in stable
5 years ago
BZ#1699141 CVE-2019-9494 wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake
0
0
BZ#1699144 CVE-2019-9494 hostapd: wpa_supplicant: SAE Timing-based and Cache-based side-channel attack against WPA3's Dragonfly handshake [fedora-all]
0
0
BZ#1699149 CVE-2019-9495 wpa_supplicant: EAP-pwd cache side-channel attack
0
0
BZ#1699152 CVE-2019-9495 hostapd: wpa_supplicant: EAP-pwd cache side-channel attack [fedora-all]
0
0
BZ#1699153 CVE-2019-9496 hostapd: SAE confirm missing state validation in hostapd/AP
0
0
BZ#1699154 CVE-2019-9496 hostapd: SAE confirm missing state validation in hostapd/AP [fedora-all]
0
0
BZ#1699164 CVE-2019-9497 wpa_supplicant: EAP-pwd server not checking for reflection attack
0
0
BZ#1699165 CVE-2019-9497 hostapd: wpa_supplicant: EAP-pwd server not checking for reflection attack [fedora-all]
0
0

Automated Test Results