Files
meta-openembedded/meta-oe/recipes-connectivity
Yi Zhao 0f98d98e82 hostapd: Security fix for CVE-2023-52160
CVE-2023-52160:
The implementation of PEAP in wpa_supplicant through 2.10 allows
authentication bypass. For a successful attack, wpa_supplicant must be
configured to not verify the network's TLS certificate during Phase 1
authentication, and an eap_peap_decrypt vulnerability can then be abused
to skip Phase 2 authentication. The attack vector is sending an EAP-TLV
Success packet instead of starting Phase 2. This allows an adversary to
impersonate Enterprise Wi-Fi networks.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2023-52160

Patch from:
https://w1.fi/cgit/hostap/commit/?id=8e6485a1bcb0baffdea9e55255a81270b768439c

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2024-12-15 13:52:28 -05:00
..
2024-04-30 10:59:05 -07:00
2023-11-17 11:38:24 -08:00
2024-03-25 18:52:53 -07:00
2023-11-17 11:38:24 -08:00
2024-08-21 16:45:23 -04:00
2024-02-12 19:33:53 -08:00
2024-02-09 09:52:12 -08:00
2023-11-12 12:02:25 -08:00
2023-07-13 07:22:17 -07:00
2024-02-09 09:52:12 -08:00
2024-01-12 10:30:32 -08:00
2024-04-02 14:56:53 -07:00
2024-02-09 09:52:12 -08:00
2023-02-22 01:03:38 -08:00