FlawAtlas
Search the atlas
SUSE-SU-2017:2745-1 Not scored

Security update for wpa_supplicant

This update for wpa_supplicant fixes the security issues: - Several vulnerabilities in standard conforming implementations of the WPA2 protocol have been discovered and published under the code name KRACK. This update remedies those issues in a backwards compatible manner, i.e. the updated wpa_supplicant can interface properly with both vulnerable and patched implementations of WPA2, but an attacker won't be able to exploit the KRACK weaknesses in those connections anymore even if the other party is still vulnerable. [bsc#1056061, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13087, CVE-2017-13088]

Exploit probability Not scored
Published October 17, 2017
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Desktop 12 SP2 wpa_supplicant
SUSE:Linux Enterprise Desktop 12 SP3 wpa_supplicant
SUSE:Linux Enterprise Server 12 SP1-LTSS wpa_supplicant
SUSE:Linux Enterprise Server 12 SP2 wpa_supplicant
SUSE:Linux Enterprise Server 12 SP3 wpa_supplicant
SUSE:Linux Enterprise Server 12-LTSS wpa_supplicant
SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2 wpa_supplicant
SUSE:Linux Enterprise Server for SAP Applications 12 SP1 wpa_supplicant
SUSE:Linux Enterprise Server for SAP Applications 12 SP2 wpa_supplicant
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 wpa_supplicant
SUSE:OpenStack Cloud 6 wpa_supplicant

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2017:2745-1

This update for wpa_supplicant fixes the security issues: - Several vulnerabilities in standard conforming implementations of the WPA2 protocol have been discovered and published under the code name KRACK. This update remedies those issues in a backwards compatible manner, i.e. the updated wpa_supplicant can interface properly with both vulnerable and patched implementations of WPA2, but an attacker won't be able to exploit the KRACK weaknesses in those connections anymore even if the other party is still vulnerable. [bsc#1056061, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13087, CVE-2017-13088]

View original source

05 / REFERENCES

Further evidence