Skip to content
Commit c21eddde authored by Peter Korsgaard's avatar Peter Korsgaard
Browse files

package/wpa_supplicant: add upstream 2019-5 security patches

Fixes the following security vulnerabilities:

EAP-pwd implementation in hostapd (EAP server) and wpa_supplicant (EAP
peer) was discovered not to validate fragmentation reassembly state
properly for a case where an unexpected fragment could be received. This
could result in process termination due to NULL pointer dereference.

For details, see the advisory:
https://w1.fi/security/2019-5/eap-pwd-message-reassembly-issue-with-unexpected-fragment.txt



Signed-off-by: default avatarPeter Korsgaard <peter@korsgaard.com>
parent b3adfacd
Loading
Loading
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment