-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 30 Apr 2024 22:45:18 +0000 Source: wpa Binary: eapoltest eapoltest-dbgsym hostapd hostapd-dbgsym libwpa-client-dev wpagui wpagui-dbgsym wpasupplicant wpasupplicant-dbgsym wpasupplicant-udeb Architecture: armel Version: 2:2.10-12+deb12u1 Distribution: bookworm Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Bastien Roucariès Description: eapoltest - EAPoL testing utility hostapd - access point and authentication server for Wi-Fi and Ethernet libwpa-client-dev - development files for WPA/WPA2 client support (IEEE 802.11i) wpagui - graphical user interface for wpa_supplicant wpasupplicant - client support for WPA and WPA2 (IEEE 802.11i) wpasupplicant-udeb - client support for WPA and WPA2 (IEEE 802.11i) (udeb) Closes: 1064061 Changes: wpa (2:2.10-12+deb12u1) bookworm; urgency=high . * Non-maintainer upload on behalf of the Security Team. * Fix CVE-2023-52160 (Closes: #1064061): The implementation of PEAP in wpa_supplicant allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks. Checksums-Sha1: e10b43535df2d81367790d0ff7837419627840f3 3957188 eapoltest-dbgsym_2.10-12+deb12u1_armel.deb 10f162665ffc709acc66fdd0b5a647f11a83034c 931560 eapoltest_2.10-12+deb12u1_armel.deb 73de938d3c46bd641c671b67040366cde2279ad9 2699896 hostapd-dbgsym_2.10-12+deb12u1_armel.deb 2755c8b175f6593fe55d21a9c8efbe4660f9ae7e 717504 hostapd_2.10-12+deb12u1_armel.deb 66ca4c8b3e742db05167c7e039ec855e6c7b8937 31236 libwpa-client-dev_2.10-12+deb12u1_armel.deb 9258788ca1a6539814a37e0a80e554fe0f6eb303 14839 wpa_2.10-12+deb12u1_armel-buildd.buildinfo 26e638c75be21dbdc52dd82724aa0687ffd9f711 2191816 wpagui-dbgsym_2.10-12+deb12u1_armel.deb 0260f22e9085567f83f868ef957f64d18e880a65 299136 wpagui_2.10-12+deb12u1_armel.deb 4fe7fa6826940e490f1494247ca44d313daaeb58 4451908 wpasupplicant-dbgsym_2.10-12+deb12u1_armel.deb 8a6bb46538ebc6230ba424dcb4b0803ba77d0f0f 303188 wpasupplicant-udeb_2.10-12+deb12u1_armel.udeb e85351381147fc637c88770c483ac26061ae6714 1172576 wpasupplicant_2.10-12+deb12u1_armel.deb Checksums-Sha256: 931594d341419ec3a646b2ff7113c0584ccc72ab8aed3052e7224eae4da38025 3957188 eapoltest-dbgsym_2.10-12+deb12u1_armel.deb 198d85f02ae0c7fc31ef35b52bbd2eed1fcb2af8596d63ff544c1acac74f5fbb 931560 eapoltest_2.10-12+deb12u1_armel.deb 79a39d60ebc3ebbf48f0de7c93b0624f9ea288712bedd2b4cfc3e9a5f3e8dc1d 2699896 hostapd-dbgsym_2.10-12+deb12u1_armel.deb 234e01318408fc7e356584f875786e2af02596b9fe8fb8c8d8030a95c51f1105 717504 hostapd_2.10-12+deb12u1_armel.deb 343aea33bc6264b5b82f63dc5d4fb46be1f462de575a35c9059d9296f798c6a5 31236 libwpa-client-dev_2.10-12+deb12u1_armel.deb 7a3d517291ab4848f481c2d1bb914d18b7d612c1444a3ae747e1d17580fbbfa9 14839 wpa_2.10-12+deb12u1_armel-buildd.buildinfo 3bea4b2a68ec34f9bc27a2948e43e8b99f82e7d63ec6a4d982f0951384d2646d 2191816 wpagui-dbgsym_2.10-12+deb12u1_armel.deb 4d742d74e1bea1c8af3b7c7b4da45b4fa0ff86963bb421c1204d5e6f9fc586a1 299136 wpagui_2.10-12+deb12u1_armel.deb 7e3a1264fe7c2d7b462477a11d00b3c4ebbf7772a9c2e4606f817351e6b7237b 4451908 wpasupplicant-dbgsym_2.10-12+deb12u1_armel.deb 685c3a15b365951b2b83c25aed3c54641f8fe087f8b742bc961a3536b1d38670 303188 wpasupplicant-udeb_2.10-12+deb12u1_armel.udeb 26e8e769adaf4cde23a7d524352cb6a5920ba1a3b9a7d4cecc1005350937e913 1172576 wpasupplicant_2.10-12+deb12u1_armel.deb Files: 1dd2e986f4f8819e5770c81a47d7c78c 3957188 debug optional eapoltest-dbgsym_2.10-12+deb12u1_armel.deb 3087913be95e933207828f773c7d7c76 931560 net optional eapoltest_2.10-12+deb12u1_armel.deb 3a7ae1d9c158a2d681e355367885a3c2 2699896 debug optional hostapd-dbgsym_2.10-12+deb12u1_armel.deb e85e5f526c175dd960f38ddbaf774a78 717504 net optional hostapd_2.10-12+deb12u1_armel.deb d80e6e4f47a31ec96f803d446840f20f 31236 libdevel optional libwpa-client-dev_2.10-12+deb12u1_armel.deb d6c54dec9a73f349f7b1078195620655 14839 net optional wpa_2.10-12+deb12u1_armel-buildd.buildinfo 53e3c0de2c755009ad215580eeadf86c 2191816 debug optional wpagui-dbgsym_2.10-12+deb12u1_armel.deb 3146a465fa881db0580a512d790a005a 299136 net optional wpagui_2.10-12+deb12u1_armel.deb 26356ff1446ff9f29bb5bdfbadc638df 4451908 debug optional wpasupplicant-dbgsym_2.10-12+deb12u1_armel.deb 3ee57a1cb004c55dbb96bd2eb726e900 303188 debian-installer standard wpasupplicant-udeb_2.10-12+deb12u1_armel.udeb f0893887514d642cfefb5489f0b8518a 1172576 net optional wpasupplicant_2.10-12+deb12u1_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEU81tY/BC8e+eAeWhLffeOnPnbLUFAmZ0fSEACgkQLffeOnPn bLVceQ/+Plc7hJbGIBHleuQBPyYPQIF7mlXsn9r7bktROZwHl3P8mLbWLMgsP1IO EnQ/0Tv0tfIHHW7GqhEwzAgqQ8Vvf8ptlgblrW3y/uVk3OMLxY4KtJptdxRwoivi zhSAMJFE0bL+VjJnuUurefltW+j/hubsQCNmt42XfUm867O5iQCuuxQX72Lb9468 +qs1aYvoHtVErOXSgB9HRjfOrMyBCVyN/i03UMbLn95i6yAuw04alBGUfS6pXp3H qF40OjSykY7QZUHI7uksBBXZpgusPPm4MlZWdEGSHWaUj0sT9L0uOSKKk8tFiGSz YQWgqbpPTNE/bd1X0yq/f97xhylw2PJrFUIDG6RE5or+5BF7wUX82H5mgCcZD7mg a4aF2Fr8npZJnxehCLrO+Mws/FJvUmCZFTWYHebFhWn2Hf9C16BzS4IvfdJjEJ/B DXXuOlW5JWN9iEOFmO7vQ9JQ+mEFmVtTqxe8CL1guSpap8bqjO9zX0x4Adv867sK ns1xpjhlkHgFkjlFRgAqRUJ96DPu8I1Bbq+7TgUNneRPIUakryB4Dk7Y09VRRNgk WSylH3ADX9UeOovhjyuhm3rI+1FZbUFwVq26SOiyYPln0hVCx/d/iT/6Fgr/WAR2 jrSM43B2ut+alPXKIGQINZ0bt9R7dmqubNIEePjEyv/7ILSu/7Y= =ZE4u -----END PGP SIGNATURE-----