SUSE-SU-2017:2745-1

    Dashboard / Vulnerabilities / SUSE-SU-2017:2745-1

    SUSE-SU-2017:2745-1

    Published: 17 Oct 2017Last Modified: 4 Feb 2026

    Summary: Security update for wpa_supplicant

    Details: This update for wpa_supplicant fixes the security issues: - Several vulnerabilities in standard conforming implementations of the WPA2 protocol have been discovered and published under the code name KRACK. This update remedies those issues in a backwards compatible manner, i.e. the updated wpa_supplicant can interface properly with both vulnerable and patched implementations of WPA2, but an attacker won't be able to exploit the KRACK weaknesses in those connections anymore even if the other party is still vulnerable. [bsc#1056061, CVE-2017-13078, CVE-2017-13079, CVE-2017-13080, CVE-2017-13081, CVE-2017-13087, CVE-2017-13088]

    Affected packages

    Package

    Name: wpa_supplicant

    Purl: pkg:rpm/suse/wpa_supplicant&distro=SUSE%20OpenStack%20Cloud%206

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.2-15.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High