Files
meta-openembedded/meta-oe/recipes-connectivity
Yi Zhao 9f598082ed hostapd: Security fix for CVE-2023-52160
CVE-2023-52160:
The implementation of PEAP in wpa_supplicant through 2.10 allows
authentication bypass. For a successful attack, wpa_supplicant must be
configured to not verify the network's TLS certificate during Phase 1
authentication, and an eap_peap_decrypt vulnerability can then be abused
to skip Phase 2 authentication. The attack vector is sending an EAP-TLV
Success packet instead of starting Phase 2. This allows an adversary to
impersonate Enterprise Wi-Fi networks.

Reference:
https://nvd.nist.gov/vuln/detail/CVE-2023-52160

Patch from:
https://w1.fi/cgit/hostap/commit/?id=8e6485a1bcb0baffdea9e55255a81270b768439c

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2024-12-08 15:02:39 -05:00
..
2021-08-03 10:21:25 -07:00
2022-03-29 08:28:38 -07:00
2022-03-31 11:54:44 -07:00
2024-09-22 09:59:21 -04:00
2022-03-03 23:07:50 -08:00
2022-03-03 23:07:50 -08:00
2022-07-21 07:17:15 -07:00
2024-02-07 18:41:41 -05:00
2023-09-23 13:06:57 -04:00