-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 22:45:18 +0000 Source: wpa Binary: eapoltest eapoltest-dbgsym hostapd hostapd-dbgsym libwpa-client-dev wpagui wpagui-dbgsym wpasupplicant wpasupplicant-dbgsym wpasupplicant-udeb Architecture: mipsel Version: 2:2.10-12+deb12u1 Distribution: bookworm Urgency: high Maintainer: mipsel Build Daemon (mipsel-osuosl-05) Changed-By: Bastien Roucariès Description: eapoltest - EAPoL testing utility hostapd - access point and authentication server for Wi-Fi and Ethernet libwpa-client-dev - development files for WPA/WPA2 client support (IEEE 802.11i) wpagui - graphical user interface for wpa_supplicant wpasupplicant - client support for WPA and WPA2 (IEEE 802.11i) wpasupplicant-udeb - client support for WPA and WPA2 (IEEE 802.11i) (udeb) Closes: 1064061 Changes: wpa (2:2.10-12+deb12u1) bookworm; urgency=high . * Non-maintainer upload on behalf of the Security Team. * Fix CVE-2023-52160 (Closes: #1064061): The implementation of PEAP in wpa_supplicant allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks. Checksums-Sha1: d6e3fd85e916a4fbbad0375de009792ca50c2188 4170352 eapoltest-dbgsym_2.10-12+deb12u1_mipsel.deb b64c28076f0dd29fe673593babbc24e737575cfb 1039164 eapoltest_2.10-12+deb12u1_mipsel.deb 9b6ef0d58aa4a9c53dbf8dedbe5785f800801743 2848604 hostapd-dbgsym_2.10-12+deb12u1_mipsel.deb adc0d55aa3ed905ea039152b1a8c8075739f86af 794252 hostapd_2.10-12+deb12u1_mipsel.deb c1f2af2b213181ab8b354b20f9d1a84baa568e3f 34492 libwpa-client-dev_2.10-12+deb12u1_mipsel.deb cdee66b45b1a9fdb7248d2535d624916565e2a09 14813 wpa_2.10-12+deb12u1_mipsel-buildd.buildinfo 6f59072d0b890f70919acbd31671d18cb946cd28 2268016 wpagui-dbgsym_2.10-12+deb12u1_mipsel.deb de9d98680e1cfc1dac4af5ef657ebcaf31ebf55c 303692 wpagui_2.10-12+deb12u1_mipsel.deb afd51b5cae9d0a5c40dbee1522956428ed38125a 4698556 wpasupplicant-dbgsym_2.10-12+deb12u1_mipsel.deb b53397fe43168a6e910be9582efd1e4f8fb03974 344000 wpasupplicant-udeb_2.10-12+deb12u1_mipsel.udeb c4fe2b3389bb0addf153b19c391fc4adbd31ac70 1292640 wpasupplicant_2.10-12+deb12u1_mipsel.deb Checksums-Sha256: 518e7a9c1c7096f2bda73a4e1a283d238598a240eddee7ec4ef21f1abadf17a7 4170352 eapoltest-dbgsym_2.10-12+deb12u1_mipsel.deb e0c2d400c60901c80a40f0012a0e003895be33b8aad981b31adc345640339095 1039164 eapoltest_2.10-12+deb12u1_mipsel.deb f8d077a713e10da321adac795c0ecfbf28555dd815dbcb4d194245b7f03c448a 2848604 hostapd-dbgsym_2.10-12+deb12u1_mipsel.deb 43a31d5258d8adc263d2f2e652b4f946d76df786dfdfa97dea2e0f3933cf011c 794252 hostapd_2.10-12+deb12u1_mipsel.deb e3af20fe63b0aa19fcc3e3ccd16411749fe5bbdba07eb896a51db3ec2af9b8be 34492 libwpa-client-dev_2.10-12+deb12u1_mipsel.deb fb491a9053b85ba396aae8ac0ef395d614e8924a5d17b31e6569351eb59a63f3 14813 wpa_2.10-12+deb12u1_mipsel-buildd.buildinfo a7e7f56c7b116360a222092c5f65fbe1fdb2c16a88cdcdb23f0aabd0a47b0c69 2268016 wpagui-dbgsym_2.10-12+deb12u1_mipsel.deb 5a8449a75c45d35ffb87260a34afc77b3be80cd5e3ea380a634db377be4c5e1f 303692 wpagui_2.10-12+deb12u1_mipsel.deb a3fd80f58dd78d3c069a61997ba8363e5c3ac7d29fb9b952d61631f7351e81a1 4698556 wpasupplicant-dbgsym_2.10-12+deb12u1_mipsel.deb 24b79ee73f5b179bd33c9c85b5574d1d845c56f427aaa1fbc3391e74e2bf5663 344000 wpasupplicant-udeb_2.10-12+deb12u1_mipsel.udeb 69464facb05c73397a67b802aa8a6730ae0fb3ebba846bc52803132644a27aee 1292640 wpasupplicant_2.10-12+deb12u1_mipsel.deb Files: 5b8fd58e46540a4949b7f8bcbe213e06 4170352 debug optional eapoltest-dbgsym_2.10-12+deb12u1_mipsel.deb 088a059326a7ce24cad50f8f7da8d89c 1039164 net optional eapoltest_2.10-12+deb12u1_mipsel.deb 6334ce605b973b02a84293560ad83b31 2848604 debug optional hostapd-dbgsym_2.10-12+deb12u1_mipsel.deb 351fe6534fe0a6f1d4464369e31b4a66 794252 net optional hostapd_2.10-12+deb12u1_mipsel.deb 518e59e5739708656b4764d14e7f96ef 34492 libdevel optional libwpa-client-dev_2.10-12+deb12u1_mipsel.deb 35c12e7db92ca4e41e78e1740569468a 14813 net optional wpa_2.10-12+deb12u1_mipsel-buildd.buildinfo 2ec545ba8ecfcccb1257466f0b8066f2 2268016 debug optional wpagui-dbgsym_2.10-12+deb12u1_mipsel.deb d97b26ecc0eccf1c2a7eb4df989429e5 303692 net optional wpagui_2.10-12+deb12u1_mipsel.deb fc49a47775a81f3baa45411911d551bf 4698556 debug optional wpasupplicant-dbgsym_2.10-12+deb12u1_mipsel.deb b11b7d1404e188ed117d512aa7ba8fd8 344000 debian-installer standard wpasupplicant-udeb_2.10-12+deb12u1_mipsel.udeb eafa7e600281af5135748f1f5975a456 1292640 net optional wpasupplicant_2.10-12+deb12u1_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEuQAPGkYIXAAfq7z1C2Vm2FYVKKAFAmZ0gKoACgkQC2Vm2FYV KKDxsBAAusvWuIOVazbq6XyRF1pnOGnAD4UgD0dvngbYQluV/mIiCZ1DnuwgYBcW HmV8Wu76NcY66+24JgVMdYbZBi8DsKx7JX929U2WQ1h+TrnpRRtUfLrsg9Je2Brs gmks/yPR4Bs0kKkhln2h8oIPcE3h4aiPPZ442lszQDcCdizP4OKxOt42VV/V+ENj pJYvZ7DJXhD1oQXw7PCqgkVBgUxvMp2SQ6LDziGZOa/5AIgP6y+EX968MhRNoWGo 5vbSOZjPKjWhNjSxtcs1sezFCKJLk3LrCLjgSuBZMWlz84TZUCXa0TcpKHgFfWRP S6knw8D5iTha2XbDfrCFTF04sntla27jJg6C16tukCkn/dqFgqo3alGTT4z6ayS/ kxhk+Mgmv2/x9fhWpZJXTpYvzWMWJDY/LnjWh08aEeHV9AKCrl/viRb2y49Znlz+ vEynzmcOD/kreX1Om8WDiWEvtUQRfZryDK0bGK4mUvCgL+zyaVwHGUjI131LrbGO oGS28vwydMkmf9QVNvSaMKQBmiFaEA9U9ne2EBzoew32sEuvz5s0F/OcQqLcHgbc LzvNuX0ppOZ+0sQXyZIUHWJd8gg85PeOpRoCwoeGb86EmVpLTtRn0YFzfpcSOblS y2LLiCUFyRqzs7wtVSO8FUFYUiPNslUEJbie+EFMvO3+ef422YM= =aD5l -----END PGP SIGNATURE-----