[Secure-testing-team] Bug#878807: wpasupplicant: Please port the security fixes to 2.6 also

Eric Valette eric.valette at free.fr
Mon Oct 16 19:49:44 UTC 2017


Package: wpasupplicant
Version: 2:2.6-4
Severity: grave
Tags: upstream security
Justification: user security hole

Upstream patches patches for 2.6 are here
http://w1.fi/security/2017-1/

-- System Information:
Debian Release: buster/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.56 (SMP w/8 CPU cores; PREEMPT)
Locale: LANG=fr_FR.UTF8, LC_CTYPE=fr_FR.UTF8 (charmap=UTF-8), LANGUAGE= (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages wpasupplicant depends on:
ii  adduser           3.116
ii  libc6             2.25-0experimental3
ii  libdbus-1-3       1.11.20-1
ii  libnl-3-200       3.2.27-2
ii  libnl-genl-3-200  3.2.27-2
ii  libpcsclite1      1.8.22-1
ii  libreadline7      7.0-3
ii  libssl1.1         1.1.0f-5
ii  lsb-base          9.20170808

wpasupplicant recommends no packages.

Versions of packages wpasupplicant suggests:
pn  libengine-pkcs11-openssl  <none>
ii  wpagui                    2:2.6-4

-- no debconf information



More information about the Secure-testing-team mailing list