Format: 1.8 Date: Tue, 13 Aug 2019 14:07:43 -0400 Source: wpa Binary: hostapd wpagui wpasupplicant wpasupplicant-udeb Architecture: s390x s390x_translations Version: 2:2.6-15ubuntu2.4 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Marc Deslauriers Description: hostapd - IEEE 802.11 AP and IEEE 802.1X/WPA/WPA2/EAP Authenticator wpagui - graphical user interface for wpa_supplicant wpasupplicant - client support for WPA and WPA2 (IEEE 802.11i) wpasupplicant-udeb - Client support for WPA and WPA2 (IEEE 802.11i) (udeb) Changes: wpa (2:2.6-15ubuntu2.4) bionic-security; urgency=medium . * SECURITY UPDATE: SAE/EAP-pwd side-channel attack w/Brainpool curves - debian/patches/CVE-2019-13377-2.patch: use const_time_memcmp() for pwd_value >= prime comparison in src/eap_common/eap_pwd_common.c. - debian/patches/CVE-2019-13377-3.patch: use BN_bn2binpad() or BN_bn2bin_padded() if available in src/crypto/crypto_openssl.c. - debian/patches/CVE-2019-13377-5.patch: run through prf result processing even if it >= prime in src/eap_common/eap_pwd_common.c. - debian/patches/CVE-2019-13377-pre6.patch: disallow ECC groups with a prime under 256 bits in src/eap_common/eap_pwd_common.c. - debian/patches/CVE-2019-13377-6.patch: disable use of groups using Brainpool curves in src/eap_common/eap_pwd_common.c. - CVE-2019-13377 Checksums-Sha1: a1800800f3b07d6db9c52382421ae6e99f0d580c 2141128 hostapd-dbgsym_2.6-15ubuntu2.4_s390x.ddeb 3c85136a52224e6ad5e689ab54c81e99c76e7c54 489768 hostapd_2.6-15ubuntu2.4_s390x.deb 902e52ad3f545f0b5bda8ac74a1f88796dbf4a1e 14960 wpa_2.6-15ubuntu2.4_s390x.buildinfo d915ca164f112d6e0e6ce21ed74e418b4a113498 5903 wpa_2.6-15ubuntu2.4_s390x_translations.tar.gz af6fdc702c43ef27c3ff9c4e771734a30cc1abf5 2444196 wpagui-dbgsym_2.6-15ubuntu2.4_s390x.ddeb a13d20560beb4199226c894e8265da53259e91a1 254628 wpagui_2.6-15ubuntu2.4_s390x.deb df2d6661c844d04c9127298e99ab363e8f162e0d 3572060 wpasupplicant-dbgsym_2.6-15ubuntu2.4_s390x.ddeb 4cc29e08bb892748f189ac579f0bc0d6accb4547 248844 wpasupplicant-udeb_2.6-15ubuntu2.4_s390x.udeb 859464fa5967eefbd3a969fbb7f5c19e57125d13 852760 wpasupplicant_2.6-15ubuntu2.4_s390x.deb Checksums-Sha256: d56d3e36b5ff8cb7dcebb26fa449040ebe5b327b8119749a97b33105d6fcf6f2 2141128 hostapd-dbgsym_2.6-15ubuntu2.4_s390x.ddeb 3d80d44b80c4651becf57171088a808aa0e6189ee66fc477167f83912202c567 489768 hostapd_2.6-15ubuntu2.4_s390x.deb b7457788138f6fe6f69087a1c532d82f7444f87c6bd6c23068e275665084ea40 14960 wpa_2.6-15ubuntu2.4_s390x.buildinfo ab9157ed52447ac82cb16716cd14a39132e523b47528be0dee1238071c93d450 5903 wpa_2.6-15ubuntu2.4_s390x_translations.tar.gz a2c7743bbc4d07d3f7b7a65c7825ca183564b51fb05e11a4f8afb31a70aebeb3 2444196 wpagui-dbgsym_2.6-15ubuntu2.4_s390x.ddeb 8388fc2a4767e4b8bb0fbd97f0a7c1d4a529d025014f0f9584c14a488fb7b60d 254628 wpagui_2.6-15ubuntu2.4_s390x.deb eb5813cf7c9ced128522f87ac7f27ed7a45ebdc2c378d554d035afc75fc7a446 3572060 wpasupplicant-dbgsym_2.6-15ubuntu2.4_s390x.ddeb b06e65f342a28379c47579932898715dbb75dcca36f982dad6936ce1a06f605e 248844 wpasupplicant-udeb_2.6-15ubuntu2.4_s390x.udeb d4f708fcb5d19cc085db4d791c2319f4bc4c382fb852066c330f29bb35010f2e 852760 wpasupplicant_2.6-15ubuntu2.4_s390x.deb Files: 9a1bae6a809343ce7e2bd9420524c001 2141128 debug optional hostapd-dbgsym_2.6-15ubuntu2.4_s390x.ddeb dd0e7ed30beadf00d97289069dc8ff19 489768 net optional hostapd_2.6-15ubuntu2.4_s390x.deb 260140da6d049032ef55828e9fd69f9f 14960 net optional wpa_2.6-15ubuntu2.4_s390x.buildinfo 48fab66c0e7cc620818752d3aa9acf7c 5903 raw-translations - wpa_2.6-15ubuntu2.4_s390x_translations.tar.gz 4750f2011680d8b38d09c57e98112005 2444196 debug optional wpagui-dbgsym_2.6-15ubuntu2.4_s390x.ddeb 1a5ae7cb02a014c30b0463b7eb14f993 254628 net optional wpagui_2.6-15ubuntu2.4_s390x.deb bdbbc752b47056676c5f9930e03b895f 3572060 debug optional wpasupplicant-dbgsym_2.6-15ubuntu2.4_s390x.ddeb e5df7ba76d7ed3fba9fcc73a8d1ae58e 248844 debian-installer standard wpasupplicant-udeb_2.6-15ubuntu2.4_s390x.udeb 6fe2cf3970c8c472f615479089d0bac9 852760 net optional wpasupplicant_2.6-15ubuntu2.4_s390x.deb Original-Maintainer: Debian wpasupplicant Maintainers