Описание
Security update for connman
This update for connman fixes the following issues:
Update to 1.42
- Fix issue with iwd and signal strength calculation.
- Fix issue with iwd and handling service removal.
- Fix issue with iwd and handling new connections.
- Fix issue with handling default online check URL.
- Fix issue with handling nameservers refresh.
- Fix issue with handling proxy from DHCP lease. (boo#1210395 CVE-2023-28488)
- Fix issue with handling multiple proxies from PAC.
- Fix issue with handling manual time update changes.
- Fix issue with handling invalid gateway routes.
- Fix issue with handling hidden WiFi agent requests.
- Fix issue with handling WiFi SAE authentication failure.
- Fix issue with handling DNS Proxy and TCP server replies.
- Add support for regulatory domain following timezone.
- Add support for localtime configuration option.
Список пакетов
SUSE Package Hub 15 SP5
connman-1.42-bp155.4.3.1
connman-client-1.42-bp155.4.3.1
connman-devel-1.42-bp155.4.3.1
connman-doc-1.42-bp155.4.3.1
connman-nmcompat-1.42-bp155.4.3.1
connman-plugin-hh2serial-gps-1.42-bp155.4.3.1
connman-plugin-iospm-1.42-bp155.4.3.1
connman-plugin-l2tp-1.42-bp155.4.3.1
connman-plugin-openvpn-1.42-bp155.4.3.1
connman-plugin-polkit-1.42-bp155.4.3.1
connman-plugin-pptp-1.42-bp155.4.3.1
connman-plugin-tist-1.42-bp155.4.3.1
connman-plugin-vpnc-1.42-bp155.4.3.1
connman-plugin-wireguard-1.42-bp155.4.3.1
connman-test-1.42-bp155.4.3.1
openSUSE Leap 15.5
connman-1.42-bp155.4.3.1
connman-client-1.42-bp155.4.3.1
connman-devel-1.42-bp155.4.3.1
connman-doc-1.42-bp155.4.3.1
connman-nmcompat-1.42-bp155.4.3.1
connman-plugin-hh2serial-gps-1.42-bp155.4.3.1
connman-plugin-iospm-1.42-bp155.4.3.1
connman-plugin-l2tp-1.42-bp155.4.3.1
connman-plugin-openvpn-1.42-bp155.4.3.1
connman-plugin-polkit-1.42-bp155.4.3.1
connman-plugin-pptp-1.42-bp155.4.3.1
connman-plugin-tist-1.42-bp155.4.3.1
connman-plugin-vpnc-1.42-bp155.4.3.1
connman-plugin-wireguard-1.42-bp155.4.3.1
connman-test-1.42-bp155.4.3.1
Ссылки
- E-Mail link for openSUSE-SU-2023:0369-1
- SUSE Security Ratings
- SUSE Bug 1210395
- SUSE CVE CVE-2023-28488 page
Описание
client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.
Затронутые продукты
SUSE Package Hub 15 SP5:connman-1.42-bp155.4.3.1
SUSE Package Hub 15 SP5:connman-client-1.42-bp155.4.3.1
SUSE Package Hub 15 SP5:connman-devel-1.42-bp155.4.3.1
SUSE Package Hub 15 SP5:connman-doc-1.42-bp155.4.3.1
Ссылки
- CVE-2023-28488
- SUSE Bug 1210395