Patch Krack #303

Closed
garro95 opened this Issue Oct 18, 2017 · 1 comment

Comments

Projects
None yet
3 participants

garro95 commented Oct 18, 2017

  • Device: All devices
  • Channel: All channels
  • Build: All builds

WPA2, the security mechanism used to access Wi-Fi networks and cypher Wi-Fi radio traffic, is affected by a serious bug that is called KRACK (Key Reinstallation AttaCKs, https://www.krackattacks.com/). Debian has already released a patch for that, so it should be sufficient to rebuild a fixed version of the package wpasupplicant for vivid. https://anonscm.debian.org/cgit/collab-maint/wpa.git/patch/?id=5e1d735e15aef8dc762761c5e938dec9db209bdd. Just apply this on the ubuntu vivid version of the wpa source package and rebuild. Should be fixed then, as long as the android part doesn't has to do something with this.

Apply the patch from Debian and send the security update to all devices in all channels ASAP.
This should be very high priority IMO.

@NeoTheThird NeoTheThird added the bug label Oct 19, 2017

@mariogrip mariogrip added this to the 15.04 OTA-3 milestone Oct 28, 2017

@Flohack74 Flohack74 added this to Accepted in Ubuntu Touch Oct 28, 2017

@mariogrip mariogrip moved this from Accepted to In Progress in Ubuntu Touch Nov 1, 2017

Owner

mariogrip commented Nov 1, 2017

Fix pushed: ubports/wpa@ba978fb

@mariogrip mariogrip moved this from In Progress to Waiting for Q/A in Ubuntu Touch Nov 1, 2017

@mariogrip mariogrip closed this Nov 1, 2017

@NeoTheThird NeoTheThird moved this from Quality Assurance to Release Candidate in Ubuntu Touch Dec 12, 2017

@NeoTheThird NeoTheThird removed this from Release Candidate in Ubuntu Touch Dec 28, 2017

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment