Security update for wpa_supplicant
This update for wpa_supplicant fixes the following issues: - Several vulnerabilities in standard conforming implementations of the WPA2 protocol have been discovered and published under the code name KRACK. This update remedies those issues in a backwards compatible manner, i.e. the updated wpa_supplicant can interface properly with both vulnerable and patched implementations of WPA2, but an attacker won't be able to exploit the KRACK weaknesses in those connections anymore even if the other party is still vulnerable. [bsc#1056061, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13087, CVE-2017-13088]
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for wpa_supplicant fixes the following issues: - Several vulnerabilities in standard conforming implementations of the WPA2 protocol have been discovered and published under the code name KRACK. This update remedies those issues in a backwards compatible manner, i.e. the updated wpa_supplicant can interface properly with both vulnerable and patched implementations of WPA2, but an attacker won't be able to exploit the KRACK weaknesses in those connections anymore even if the other party is still vulnerable. [bsc#1056061, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13087, CVE-2017-13088]
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1056061
- https://www.suse.com/security/cve/CVE-2017-13078
- https://www.suse.com/security/cve/CVE-2017-13079
- https://www.suse.com/security/cve/CVE-2017-13080
- https://www.suse.com/security/cve/CVE-2017-13081
- https://www.suse.com/security/cve/CVE-2017-13087
- https://www.suse.com/security/cve/CVE-2017-13088
- https://www.suse.com/support/update/announcement/2017/suse-su-20172752-1/