-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 14 Oct 2017 14:11:26 +0200 Source: wpa Binary: hostapd wpagui wpasupplicant wpasupplicant-udeb Architecture: source amd64 Version: 2.3-1+deb8u5 Distribution: jessie-security Urgency: high Maintainer: Debian wpasupplicant Maintainers <pkg-wpa-devel@lists.alioth.debian.org> Changed-By: Yves-Alexis Perez <corsac@debian.org> Description: hostapd - IEEE 802.11 AP and IEEE 802.1X/WPA/WPA2/EAP Authenticator wpagui - graphical user interface for wpa_supplicant wpasupplicant - client support for WPA and WPA2 (IEEE 802.11i) wpasupplicant-udeb - Client support for WPA and WPA2 (IEEE 802.11i) (udeb) Changes: wpa (2.3-1+deb8u5) jessie-security; urgency=high . * Non-maintainer upload by the Security Team. * Add patches to fix WPA protocol vulnerabilities (CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088): - hostapd: Avoid key reinstallation in FT handshake - Prevent reinstallation of an already in-use group key - Extend protection of GTK/IGTK reinstallation of WNM-Sleep Mode cases - Fix PTK rekeying to generate a new ANonce - TDLS: Reject TPK-TK reconfiguration - WNM: Ignore WNM-Sleep Mode Response if WNM-Sleep Mode has not been used - WNM: Ignore WNM-Sleep Mode Response without pending request - FT: Do not allow multiple Reassociation Response frames - TDLS: Ignore incoming TDLS Setup Response retries Checksums-Sha1: 007783f3da4e796e885d5dc79c23e66037b3051d 2165 wpa_2.3-1+deb8u5.dsc 7f2e644aff9fdf766cb00e612e0ec98e3d3cb806 92112 wpa_2.3-1+deb8u5.debian.tar.xz 0359cd5396897d58f54e2e59c14835eb01774177 539710 hostapd_2.3-1+deb8u5_amd64.deb 4dbabc2817ea994853108fd324d3a47c8d25c9db 345900 wpagui_2.3-1+deb8u5_amd64.deb c46f3889d0d91a0e5787ea3c1cf1fd99be6003aa 917858 wpasupplicant_2.3-1+deb8u5_amd64.deb 0a7e7d32abc9b0ea22ef88c45c8d2a83a8453bd1 222366 wpasupplicant-udeb_2.3-1+deb8u5_amd64.udeb Checksums-Sha256: 866661aa6fdd5a0560a23ca9992e4d2da101db71bb7f6eeb5b9bcd988b8d18ab 2165 wpa_2.3-1+deb8u5.dsc 5b5021d7a5e023a5e4ad464de974ad60194e80d04192db96408e52cf2290baf3 92112 wpa_2.3-1+deb8u5.debian.tar.xz b89c281f9be541322804e5005102a7ff25f2ac6052f723c7923fce840a157d11 539710 hostapd_2.3-1+deb8u5_amd64.deb bd1590857ff6745c6e7d5cb389e3a6014843a2f198a8ef772ad8793453236804 345900 wpagui_2.3-1+deb8u5_amd64.deb 765591ddb90cb525fcda58b232208d59cb5c78b0ebe5ea476ce0de395bda695e 917858 wpasupplicant_2.3-1+deb8u5_amd64.deb dc70f423bc86c3e8e3296024c4e4bb5c4043cc6e8763baf1bd5287f867be6e70 222366 wpasupplicant-udeb_2.3-1+deb8u5_amd64.udeb Files: 41aa54a5181fde83a5fcb45edf018695 2165 net optional wpa_2.3-1+deb8u5.dsc da8b95455ab7eded8ece38fdc16fe7a3 92112 net optional wpa_2.3-1+deb8u5.debian.tar.xz f16538061681a1fdb6cc6ab5d2632d30 539710 net optional hostapd_2.3-1+deb8u5_amd64.deb ba21904b5ab7df606ef55dc968ef1804 345900 net optional wpagui_2.3-1+deb8u5_amd64.deb 291aa57339de9104c1eb4ce7eb15ae5d 917858 net optional wpasupplicant_2.3-1+deb8u5_amd64.deb 418b3aed63b77262d3941d81a895cba8 222366 debian-installer standard wpasupplicant-udeb_2.3-1+deb8u5_amd64.udeb -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEEl0WwInMjgf6efq/1bdtT8qZ1wKUFAlniGrYACgkQbdtT8qZ1 wKUezAf9GprZWZmR0tw6sQT31fAN/+MfPiD5Mgf/nlTG+9oqtcVpk8Q2yCn6FFwC HVYPzthXLTkbbV7iqdzIiLtxDf7ZAweM/76gs15IrJZ2aX2CuNfrbA9/wNk4y+Pk x9dQwrRlmO2VYK3lDpKAnrvE65LK1jflFSvsesUVrS5IXq6B5zK/a7ujTRH70wRQ 8BhDht5RU31eo99eXLaJ3ipyGB4u+Q3C2F3gFgzhaeLourFD8Z7eJK0KuAbL4nMt r8kmwS58q2pDpqH6BEv8RgggFIWyB4tqD/JRsflUkBEepAsD89DCMKrOmdjJxsJE 3Ct05Q5eXDLt+qjUruZK3SVbWr0Szg== =PdIy -----END PGP SIGNATURE-----