There are whole lot of new vulnerabilities in WPA2 [implementations?]: CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, CVE-2017-13087, CVE-2017-13088. Does anybody know, is FreeBSD (our WiFi stack + hostapd / wpa_supplicant) affected? -- // Lev Serebryakov -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 931 bytes Desc: OpenPGP digital signature URL: <http://lists.freebsd.org/pipermail/freebsd-security/attachments/20171016/24ac7ec4/attachment.sig>
Miroslav Lachman
2017-Oct-16 12:03 UTC
Re: WPA2 vulnerabilities — is FreeBSD-as-AP affected?
Lev Serebryakov wrote on 10/16/2017 13:56:> > There are whole lot of new vulnerabilities in WPA2 [implementations?]: > CVE-2017-13077, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, > CVE-2017-13081, CVE-2017-13082, CVE-2017-13084, CVE-2017-13086, > CVE-2017-13087, CVE-2017-13088. > > Does anybody know, is FreeBSD (our WiFi stack + hostapd / > wpa_supplicant) affected?Yes. it is discussed at current@ with patch https://lists.freebsd.org/pipermail/freebsd-current/2017-October/067193.html Miroslav Lachman