lp://staging/ubuntu/trusty-security/wpa
- Get this branch:
- bzr branch lp://staging/ubuntu/trusty-security/wpa
Branch merges
Branch information
Recent revisions
- 15. By Marc Deslauriers
-
* SECURITY UPDATE: denial of service via WPS UPnP
- debian/patches/ CVE-2015- 4141.patch: check chunk size in
src/wps/httpread. c.
- CVE-2015-4141
* SECURITY UPDATE: denial of service via AP mode WMM Action frame
- debian/patches/ CVE-2015- 4142.patch: check length in src/ap/wmm.c.
- CVE-2015-4142
* SECURITY UPDATE: denial of service via EAP-pwd
- debian/patches/ CVE-2015- 4143-4146. patch: check lengths in
src/eap_peer/ eap_pwd. c, src/eap_ server/ eap_server_ pwd.c.
- CVE-2015-4143
- CVE-2015-4144
- CVE-2015-4145
- CVE-2015-4146 - 14. By Marc Deslauriers
-
* SECURITY UPDATE: memcpy overflow in P2P functionality
- debian/patches/ CVE-2015- 1863.patch: validate SID element length in
src/p2p/p2p.c.
- CVE-2015-1863 - 13. By Marc Deslauriers
-
* SECURITY UPDATE: arbitrary command execution via unsanitized string
passed to action scripts by wpa_cli and hostapd_cli
- debian/patches/ CVE-2014- 3686.patch: added os_exec() helper to
src/utils/os.h, src/utils/os_unix. c, src/utils/ os_win32. c,
use instead of system() in wpa_supplicant/wpa_cli. c,
hostapd/hostapd_ cli.c.
- CVE-2014-3686 - 12. By Mathieu Trudel-Lapierre
-
* New upstream release (LP: #1099755)
* debian/get-orig- source: update for new git repository for the current
hostap/wpasupplicant versions.
* Dropped patches due to being applied upstream and included in the current
source tarball:
- debian/patches/ 11_wpa_ gui_ftbfs_ gcc_4_7. patch
- debian/patches/ 13_human_ readable_ signal. patch
- debian/patches/ git_deinit_ p2p_context_ on_mgmt_ remove_ ff1f9c8. patch
- debian/patches/ libnl3- includes. patch
* debian/patches/ git_accept_ client_ cert_from_ server. patch: revert the commit:
"OpenSSL: Do not accept SSL Client certificate for server", which breaks
many AAA servers that include both client and server EKUs. Cherry-picked
from hostap git commit b62d5b5. - 11. By Mathieu Trudel-Lapierre
-
debian/
patches/ git_deinit_ p2p_context_ on_mgmt_ remove_ ff1f9c8. patch:
deinitialize the P2P context when the management interface gets removed for
whatever reason, such as a suspend/resume cycle. (LP: #1210785) - 9. By Mathieu Trudel-Lapierre
-
* debian/
config/ wpasupplicant/ linux:
- Enable CONFIG_AP_MODE (AP mode support) (LP: #1209511).
- Enable CONFIG_P2P (Wi-Fi Direct support). - 8. By Logan Rosen
-
* Merge from Debian unstable. Remaining changes:
- Enable CONFIG_IBSS_RSN, so that we can turn back on "secure" adhoc
support in NetworkManager using IBSS RSN (WPA2).
- debian/wpasupplicant. postinst, debian/ hostapd. postinst: Only move
sendsigs.omit.d/ *.pid if the target isn't the same as the source (as is
the case when /lib/init/rw is a symlink to /run)
- debian/patches/ dbus-activation -cmdline. patch: have wpasupplicant create
a pid file in /run/sendsigs.omit.d when activated by DBus.
- debian/patches/ session- ticket. patch: disable the TLS Session Ticket
extension to fix auth with 802.1x PEAP on some hardware. - 7. By Mathieu Trudel-Lapierre
-
debian/
patches/ session- ticket. patch: disable the TLS Session Ticket
extension to fix auth with 802.1x PEAP on some hardware. (LP: #969343) - 6. By Mathieu Trudel-Lapierre
-
Enable CONFIG_IBSS_RSN, so that we can turn back on "secure" adhoc support
in NetworkManager using IBSS RSN (WPA2). (LP: #1046918)
Branch metadata
- Branch format:
- Branch format 7
- Repository format:
- Bazaar repository format 2a (needs bzr 1.16 or later)
- Stacked on:
- lp://staging/ubuntu/utopic/wpa