Sicherheit: Denial of Service in hostapd
Aktuelle Meldungen Distributionen
Name: Denial of Service in hostapd
ID: FEDORA-2019-28d3ca93d2
Distribution: Fedora
Plattformen: Fedora 30
Datum: Fr, 7. Juni 2019, 07:13
Referenzen: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11555
Applikationen: hostapd


Fedora Update Notification
2019-06-07 00:57:55.622025

Name : hostapd
Product : Fedora 30
Version : 2.8
Release : 1.fc30
URL : http://w1.fi/hostapd
Summary : IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator
Description :
hostapd is a user space daemon for access point and authentication servers. It
implements IEEE 802.11 access point management, IEEE 802.1X/WPA/WPA2/EAP
Authenticators and RADIUS authentication server.

hostapd is designed to be a "daemon" program that runs in the
back-ground and
acts as the backend component controlling authentication. hostapd supports
separate frontend programs and an example text-based frontend, hostapd_cli, is
included with hostapd.

Update Information:

Update to version 2.8 from upstream, Security fix for [CVE-2019-11555]

* Wed May 15 2019 John W. Linville <linville@redhat.com> - 2.8-1
- Update to version 2.8 from upstream
- Drop obsoleted patches
* Fri Apr 12 2019 John W. Linville <linville@redhat.com> - 2.7-2
- Bump N-V-R for rebuild
* Fri Apr 12 2019 John W. Linville <linville@redhat.com> - 2.7-1
- Update to version 2.7 from upstream
- Remove obsolete patches for NL80211_ATTR_SMPS_MODE encoding and KRACK
- Fix CVE-2019-9494 (cache attack against SAE)
- Fix CVE-2019-9495 (cache attack against EAP-pwd)
- Fix CVE-2019-9496 (SAE confirm missing state validation in hostapd/AP)
- Fix CVE-2019-9497 (EAP-pwd server not checking for reflection attack)
- Fix CVE-2019-9498 (EAP-pwd server missing commit validation for
- Fix CVE-2019-9499 (EAP-pwd peer missing commit validation for scalar/element)

[ 1 ] Bug #1703417 - CVE-2019-11555 wpa_supplicant: NULL pointer dereference
due to improper fragmentation reassembly state validation in EAP-pwd implementation

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2019-28d3ca93d2' at the command
line. For more information, refer to the dnf documentation available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org
Traut euch!
Neue Nachrichten