CVE-2015-1863 wpa_supplicant vulnerability

General discussion about Gargoyle, OpenWrt or anything else even remotely related to the project

Moderator: Moderators

Post Reply
chuckcol
Posts: 3
Joined: Thu Apr 23, 2015 3:48 pm

CVE-2015-1863 wpa_supplicant vulnerability

Post by chuckcol »

:o
A new vulnerability was just announced today relating to wifi security (SSID buffer processing overflow). See http://w1.fi/security/2015-1/wpa_suppli ... erflow.txt. It seems to be related to module wpa_supplicant, which I believe is used by Gargoyle.

I see a patch is being worked over at OpenWRT (search for CVE-2015-1863 at https://dev.openwrt.org). Can someone more knowledgeable (than me) give some guidance on whether this is indeed an issue for Gargoyle (1.6/1.7 series), and how we might find/apply a fix.

Thanks.

ispyisail
Moderator
Posts: 5185
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: CVE-2015-1863 wpa_supplicant vulnerability

Post by ispyisail »


Post Reply