Martin Weinelt
3e9f3a3ebd
hostapd: apply patch for CVE-2019-16275
...
AP mode PMF disconnection protection bypass
Published: September 11, 2019
Identifiers:
- CVE-2019-16275
Latest version available from: https://w1.fi/security/2019-7/
Vulnerability
hostapd (and wpa_supplicant when controlling AP mode) did not perform
sufficient source address validation for some received Management frames
and this could result in ending up sending a frame that caused
associated stations to incorrectly believe they were disconnected from
the network even if management frame protection (also known as PMF) was
negotiated for the association. This could be considered to be a denial
of service vulnerability since PMF is supposed to protect from this type
of issues. It should be noted that if PMF is not enabled, there would be
no protocol level protection against this type of denial service
attacks.
An attacker in radio range of the access point could inject a specially
constructed unauthenticated IEEE 802.11 frame to the access point to
cause associated stations to be disconnected and require a reconnection
to the network.
Vulnerable versions/configurations
All hostapd and wpa_supplicants versions with PMF support
(CONFIG_IEEE80211W=y) and a runtime configuration enabled AP mode with
PMF being enabled (optional or required). In addition, this would be
applicable only when using user space based MLME/SME in AP mode, i.e.,
when hostapd (or wpa_supplicant when controlling AP mode) would process
authentication and association management frames. This condition would
be applicable mainly with drivers that use mac80211.
Possible mitigation steps
- Merge the following commit to wpa_supplicant/hostapd and rebuild:
AP: Silently ignore management frame from unexpected source address
This patch is available from https://w1.fi/security/2019-7/
- Update to wpa_supplicant/hostapd v2.10 or newer, once available
2020-04-25 14:35:20 +02:00
Maximilian Bosch
61c95a2eec
iwd: 1.6 -> 1.7
2020-04-25 12:13:01 +02:00
Maximilian Bosch
74fcd4f2d6
ell: 0.30 -> 0.31
2020-04-25 12:12:54 +02:00
Maximilian Bosch
a194de9a9d
diffoscope: 138 -> 142
2020-04-25 12:07:38 +02:00
Maximilian Bosch
aefb4d3dc9
dmenu-wayland: 2020-02-28 -> 2020-04-03
2020-04-25 12:07:38 +02:00
lewo and GitHub
fcf547d0e2
Merge pull request #85813 from johnae/fix-k3s-systemd-units
...
The systemd unit for k3s should differ between agents and servers
2020-04-25 09:45:49 +02:00
sternenseemann and Vincent Laporte
79e6d13a4a
ocamlPackages.cow: 2.2.0 -> 2.4.0
2020-04-25 09:45:22 +02:00
Frederik Rietdijk and Frederik Rietdijk
93a9ac696b
playonlinux: fix build
2020-04-25 08:00:03 +02:00
Frederik Rietdijk and Frederik Rietdijk
6f873e98f4
Python integration tests: disable for older python 3 versions
...
because the package that is used as part of the test does not support
older versions.
2020-04-25 07:59:37 +02:00
Frederik Rietdijk and Frederik Rietdijk
71171b3225
Python tests: test venv from a nix env with Python 3.8
...
This test was disabled because it did not function yet, however,
apparently it does with 3.8.
2020-04-25 07:59:37 +02:00
Ryan Mulligan and GitHub
e7460e9412
Merge pull request #84309 from r-ryantm/auto-update/micronaut
...
micronaut: 1.3.2 -> 1.3.4
2020-04-24 21:42:42 -07:00
Konrad Borowski and Jon
df81d9a41c
clementineUnfree: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
1e802d70af
clementine: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
f527f9db3a
snakemake: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
5054133224
serviio: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
1659c302dd
scribusUnstable: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
6d8e791b28
rtptools: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
7a29abc75c
restya-board: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
40dd2c27c6
rink: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
56a7c4f056
remarkjs: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
f284354712
rambox: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
77ab79cb4b
pythonPackages.untangle: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
41268500ae
pythonPackages.subdownloader: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
2f49365ab9
pythonPackages.scikitlearn: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
ed1136b879
pythonPackages.geopandas: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
a55b6f1d06
pythonPackages.evernote: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
e538248f69
pythonPackages.certifi: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
79a11bd310
pcg-c: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
cedcfede5e
p0f: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
5fac10ccb1
lv2: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
308636a84c
lirc: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
25180cd2d5
pgf: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
47dc4104d4
libpgf: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
cfa5b41053
elm-instrument: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
16b7e0c909
darling-dmg: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
4f62d1f0b0
ciopfs: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
8998be8efb
AgdaStdlib: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
02af438989
libdislocator: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Konrad Borowski and Jon
58d59e58d2
afl: update homepage link to use HTTPS
2020-04-24 19:44:59 -07:00
Lily Ballard and Jon
19b77d4ad1
jazzy: 0.13.1 -> 0.13.3
2020-04-24 19:40:00 -07:00
worldofpeace
9d73d28580
pantheon.switchboard-plug-pantheon-shell: 2.8.3 -> 2.8.4
2020-04-24 21:22:20 -04:00
Alexandre-Xavier Labonté-Lamoureux and Cray Elliott
134f200cef
chocolate-doom: 2.3.0 -> 3.0.0
2020-04-24 18:21:25 -07:00
worldofpeace and GitHub
594b74c476
typora: drop me from maintainers
2020-04-24 21:05:59 -04:00
Ben Wolsieffer and Jon
bc93f123ea
mavproxy: 1.8.18 -> 1.8.19
2020-04-24 18:03:57 -07:00
Ben Wolsieffer and Jon
746ee6f4b4
pythonPackages.pymavlink: 2.4.6 -> 2.4.8
2020-04-24 18:03:57 -07:00
misuzu and Jon
8c0c24bf93
nix-simple-deploy: init at 0.1.1
2020-04-24 17:19:01 -07:00
worldofpeace and GitHub
d17a130290
Merge pull request #85944 from xfix/remove-slimrat
...
slimrat: remove
2020-04-24 20:15:22 -04:00
Mario Rodas and GitHub
2083e4720b
Merge pull request #85615 from Frostman/prom-2.17.2
...
prometheus: 2.17.1 -> 2.17.2
2020-04-24 19:15:05 -05:00
Benjamin Hipple and GitHub
719df72a71
Merge pull request #85942 from kevinastock/master
...
Replace ftp with https for ftp.gnu.org
2020-04-24 20:14:51 -04:00
Lisa Ugray and Jon
dea7a90ccc
vimPlugins: update
2020-04-24 17:01:03 -07:00