Mageia alert MGASA-2024-0053 (wpa_supplicant)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2024-0053: Updated wpa_supplicant packages fix security vulnerabilities | |
| Date: | Wed, 06 Mar 2024 17:54:30 +0100 | |
| Message-ID: | <20240306165430.7F8069FB1A@duvel.mageia.org> | |
| Archive-link: | Article |
MGASA-2024-0053 - Updated wpa_supplicant packages fix security vulnerabilities Publication date: 06 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0053.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-52160 Description: The updated packages fix a security vulnerability: The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks. (CVE-2023-52160) References: - https://bugs.mageia.org/show_bug.cgi?id=32911 - https://lists.fedoraproject.org/archives/list/package-ann... - https://lists.debian.org/debian-lts-announce/2024/02/msg0... - http://www.slackware.com/security/viewer.php?l=slackware-... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5... SRPMS: - 9/core/wpa_supplicant-2.10-3.1.mga9
