ViewVC Help
View File | Revision Log | Show Annotations | Download File | View Changeset | Root Listing
root/src/trunk/UPDATING
(Generate patch)

Comparing trunk/UPDATING (file contents):
Revision 11927 by laffer1, Fri Jul 20 22:36:04 2018 UTC vs.
Revision 12008 by laffer1, Wed Aug 15 13:26:29 2018 UTC

# Line 1 | Line 1
1   Updating Information for MidnightBSD users.
2  
3 + 20180815:
4 +        When using WPA2, EAPOL-Key frames with the Encrypted flag and without the MIC
5 +        flag set, the data field was decrypted first without verifying the MIC.  When
6 +        the dta field was encrypted using RC4, for example, when negotiating TKIP as
7 +        a pairwise cipher, the unauthenticated but decrypted data was subsequently
8 +        processed.  This opened wpa_supplicant(8) to abuse by decryption and recovery
9 +        of sensitive information contained in EAPOL-Key messages.
10 +
11 +        See https://w1.fi/security/2018-1/unauthenticated-eapol-key-decryption.txt
12 +        for a detailed description of the bug.
13 +
14   20180720:
15          Pull in r211155 from upstream llvm trunk (by Tim Northover):
16  

Diff Legend

Removed lines
+ Added lines
< Changed lines
> Changed lines