FS#70260 - [hostapd] [Security] signature forgery (CVE-2021-30004)
Attached to Project:
Community Packages
Opened by Jonas Witschel (diabonas) - Friday, 02 April 2021, 10:16 GMT
Last edited by Jonas Witschel (diabonas) - Friday, 02 April 2021, 13:06 GMT
Opened by Jonas Witschel (diabonas) - Friday, 02 April 2021, 10:16 GMT
Last edited by Jonas Witschel (diabonas) - Friday, 02 April 2021, 13:06 GMT
|
Details
Summary
======= The package hostapd is vulnerable to signature forgery via CVE-2021-30004. Guidance ======== Applying commit a0541334a6394f8237a4393b7372693cd7e96f15 referenced below fixes the issue. As a side note, this issue also exists in wpa_supplicant, see References ========== https://security.archlinux.org/AVG-1762 https://w1.fi/cgit/hostap/commit/?id=a0541334a6394f8237a4393b7372693cd7e96f15 |
This task depends upon
Closed by Jonas Witschel (diabonas)
Friday, 02 April 2021, 13:06 GMT
Reason for closing: Fixed
Additional comments about closing: hostapd 2.9-5
Friday, 02 April 2021, 13:06 GMT
Reason for closing: Fixed
Additional comments about closing: hostapd 2.9-5