UbuntuUpdates.org

Package "wpa"

Name: wpa

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • IEEE 802.11 AP and IEEE 802.1X/WPA/WPA2/EAP Authenticator
  • graphical user interface for wpa_supplicant

Latest version: 2.4-0ubuntu6.8
Release: xenial (16.04)
Level: security
Repository: universe

Links



Other versions of "wpa" in Xenial

Repository Area Version
base main 2.4-0ubuntu6
base universe 1:2.4-0ubuntu6
security main 2.4-0ubuntu6.8
updates universe 2.4-0ubuntu6.8
updates main 2.4-0ubuntu6.8

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2.4-0ubuntu6.3 2018-08-20 14:07:05 UTC

  wpa (2.4-0ubuntu6.3) xenial-security; urgency=medium

  * SECURITY UPDATE: Expose sensitive information
    - debian/patches/CVE-2018-14526.patch: fix in src/rsn_supp/wpa.c.
    - CVE-2018-14526

 -- <email address hidden> (Leonidas S. Barbosa) Thu, 09 Aug 2018 12:51:53 -0300

Source diff to previous version
CVE-2018-14526 An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not che

Version: 2.4-0ubuntu6.2 2017-10-16 17:06:50 UTC

  wpa (2.4-0ubuntu6.2) xenial-security; urgency=medium

  * SECURITY UPDATE: Multiple issues in WPA protocol
    - debian/patches/2017-1/*.patch: Add patches from Debian stretch
    - CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080,
      CVE-2017-13081, CVE-2017-13082, CVE-2017-13086, CVE-2017-13087,
      CVE-2017-13088
  * SECURITY UPDATE: Denial of service issues
    - debian/patches/2016-1/*.patch: Add patches from Debian stretch
    - CVE-2016-4476
    - CVE-2016-4477
  * This package does _not_ contain the changes from 2.4-0ubuntu6.1 in
    xenial-proposed.

 -- Marc Deslauriers <email address hidden> Mon, 16 Oct 2017 07:58:48 -0400

CVE-2017-1307 RESERVED
CVE-2017-1308 IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have acces
CVE-2016-4476 hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attac
CVE-2016-4477 wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library



About   -   Send Feedback to @ubuntu_updates