[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2017:2911 -- centos 6 wpa_supplicant

ID: oval:org.secpod.oval:def:204575Date: (C)2017-10-19   (M)2023-07-28
Class: PATCHFamily: unix




The wpa_supplicant packages contain an 802.1X Supplicant with support for WEP, WPA, WPA2 , and various EAP authentication methods. They implement key negotiation with a WPA Authenticator for client stations and controls the roaming and IEEE 802.11 authentication and association of the WLAN driver. Security Fix: * A new exploitation technique called key reinstallation attacks affecting WPA2 has been discovered. A remote attacker within Wi-Fi range could exploit these attacks to decrypt Wi-Fi traffic or possibly inject forged Wi-Fi packets by manipulating cryptographic handshakes used by the WPA2 protocol. Red Hat would like to thank CERT for reporting these issues. Upstream acknowledges Mathy Vanhoef as the original reporter of these issues.

Platform:
CentOS 6
Product:
wpa_supplicant
Reference:
CESA-2017:2911
CVE-2017-13077
CVE-2017-13078
CVE-2017-13080
CVE-2017-13087
CVE    4
CVE-2017-13087
CVE-2017-13077
CVE-2017-13078
CVE-2017-13080
...
CPE    2
cpe:/o:centos:centos:6
cpe:/a:w1.fi:wpa_supplicant

© SecPod Technologies