Security restrictions bypass in wpa_supplicant - CVE-2017-13080
Published: December 8, 2017 / Updated: April 30, 2018
Vulnerability identifier: #VU9591
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13080
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an adjacent attacker to write arbitrary files on the target system.
The weakness exists due to Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake. An adjacent attacker can replay frames from access points to clients.
The weakness exists due to Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake. An adjacent attacker can replay frames from access points to clients.
Affected software
wpa_supplicant
busybox (Alpine package)
wpa_supplicant (Alpine package)
hostapd (Alpine package)
supplicant (Red Hat package)
wpa_supplicant
hostapd
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - 4 Year Extended Update Support
Red Hat Enterprise Linux Server (for IBM Power LE) - 4 Year Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
busybox (Alpine package)
wpa_supplicant (Alpine package)
hostapd (Alpine package)
supplicant (Red Hat package)
wpa_supplicant
hostapd
wpa_supplicant-debuginfo
wpa_supplicant-debugsource
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Fedora
Red Hat Enterprise Linux Server for ARM
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - 4 Year Extended Update Support
Red Hat Enterprise Linux Server (for IBM Power LE) - 4 Year Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Opensuse
How to mitigate CVE-2017-13080
Install update from vendor's website.
wpa_supplicant (Alpine package) - update to 2.6-r2
hostapd (Alpine package) - addressed in versions 2.6-r1, 2.6-r2
supplicant (Red Hat package) - addressed in versions 0.7.3-9.el6_9.2, 2.6-5.el7_4.1
wpa_supplicant - addressed in versions 2.6-3.fc25.1, 2.6-11.fc26, 2.6-11.fc27
hostapd - addressed in versions 2.6-6.fc25, 2.6-6.fc26, 2.6-6.fc27, 2.6-7.el6, 2.6-7.el7
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1
hostapd (Alpine package) - addressed in versions 2.6-r1, 2.6-r2
supplicant (Red Hat package) - addressed in versions 0.7.3-9.el6_9.2, 2.6-5.el7_4.1
wpa_supplicant - addressed in versions 2.6-3.fc25.1, 2.6-11.fc26, 2.6-11.fc27
hostapd - addressed in versions 2.6-6.fc25, 2.6-6.fc26, 2.6-6.fc27, 2.6-7.el6, 2.6-7.el7
wpa_supplicant - update to 2.9-15.22.1
wpa_supplicant-debuginfo - update to 2.9-15.22.1
wpa_supplicant-debugsource - update to 2.9-15.22.1
External References
Related Security Bulletins
- Security restrictions bypass in wpa_supplicant
- Security restrictions bypass in wpa_supplicant (Alpine package)
- Security restrictions bypass in hostapd (Alpine package)
- Security restrictions bypass in busybox (Alpine package)
- OpenSUSE Linux update for hostapd
- SUSE update for wpa_supplicant
- Fedora 26 update for wpa_supplicant
- Fedora 25 update for wpa_supplicant
- Fedora 27 update for wpa_supplicant
- Fedora EPEL 7 update for hostapd
- Fedora EPEL 6 update for hostapd
- Fedora 26 update for hostapd
- Fedora 25 update for hostapd
- Fedora 27 update for hostapd
- Red Hat Enterprise Linux 7 update for wpa_supplicant
- Red Hat Enterprise Linux 6 update for wpa_supplicant