Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:4003-1

Опубликовано: 13 дек. 2021
Источник: suse-cvrf

Описание

Security update for bcm43xx-firmware

This update for bcm43xx-firmware fixes the following issues:

  • CVE-2019-15126: Fixed a bug which could have allowed unauthorized decryption of some WPA2-encrypted traffic (bsc#1167162).

Список пакетов

SUSE Linux Enterprise Server 12 SP4-LTSS
bcm43xx-firmware-20180314-4.6.1
SUSE Linux Enterprise Server 12 SP5
bcm43xx-firmware-20180314-4.6.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
bcm43xx-firmware-20180314-4.6.1

Описание

An issue was discovered on Broadcom Wi-Fi client devices. Specifically timed and handcrafted traffic can cause internal errors (related to state transitions) in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete set of traffic, a different vulnerability than CVE-2019-9500, CVE-2019-9501, CVE-2019-9502, and CVE-2019-9503.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP4-LTSS:bcm43xx-firmware-20180314-4.6.1
SUSE Linux Enterprise Server 12 SP5:bcm43xx-firmware-20180314-4.6.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5:bcm43xx-firmware-20180314-4.6.1

Ссылки
Уязвимость SUSE-SU-2021:4003-1