You are here
Home > Preporuke > Sigurnosni propust programskog paketa wpa_supplicant

Sigurnosni propust programskog paketa wpa_supplicant

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

Fedora Update Notification
2015-04-26 07:27:35

Name : wpa_supplicant
Product : Fedora 21
Version : 2.0
Release : 13.fc21
Summary : WPA/WPA2/IEEE 802.1X Supplicant
Description :
wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support
for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA
component that is used in the client stations. It implements key negotiation
with a WPA Authenticator and it controls the roaming and IEEE 802.11
authentication/association of the wlan driver.

Update Information:

This update addresses a security vulnerability identified as CVE-2015-1863 . More information on this vulnerability is provided by upstream at . An extract:

Attacker (or a system controlled by the attacker) needs to be within radio range of the vulnerable system to send a suitably constructed management frame that triggers a P2P peer device information to be created or updated.

The vulnerability is easiest to exploit while the device has started an active P2P operation (e.g., has ongoing P2P_FIND or P2P_LISTEN control interface command in progress). However, it may be possible, though significantly more difficult, to trigger this even without any active P2P operation in progress.

* Thu Apr 23 2015 Adam Williamson <> – 1:2.0-13
– backport fix for CVE-2015-1863

This update can be installed with the “yum” update program. Use
su -c ‘yum update wpa_supplicant’ at the command line.
For more information, refer to “Managing Software with yum”,
available at

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list

AutorTomislav Protega
Cert idNCERT-REF-2015-04-0013-ADV
ID izvornikaFEDORA-2015-6860
More in Preporuke
Ranjivosti programskih paketa spatialite-tools i sqlite

Otkrivene se tri ranjivosti u programskim paketima spatialite-tools i sqlite za Fedoru. Ranjivosti su posljedica korištenja neinicijalizirane memorije prilikom uspoređivanja...