{"schema_version":"1.7.3","id":"SUSE-SU-2017:2752-1","published":"2017-10-17T15:04:39Z","modified":"2026-02-04T03:54:14.503133Z","related":["CVE-2017-13078","CVE-2017-13079","CVE-2017-13080","CVE-2017-13081","CVE-2017-13087","CVE-2017-13088"],"upstream":["CVE-2017-13078","CVE-2017-13079","CVE-2017-13080","CVE-2017-13081","CVE-2017-13087","CVE-2017-13088"],"summary":"Security update for wpa_supplicant","details":"This update for wpa_supplicant fixes the following issues:\n\n- Several vulnerabilities in standard conforming implementations of the WPA2\n  protocol have been discovered and published under the code name KRACK. This\n  update remedies those issues in a backwards compatible manner, i.e. the\n  updated wpa_supplicant can interface properly with both vulnerable and\n  patched implementations of WPA2, but an attacker won't be able to exploit the\n  KRACK weaknesses in those connections anymore even if the other party is\n  still vulnerable. [bsc#1056061, CVE-2017-13078, CVE-2017-13079,\n  CVE-2017-13080, CVE-2017-13081, CVE-2017-13087, CVE-2017-13088]\n","affected":[{"package":{"name":"wpa_supplicant","ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.1-6.18.3.1"}]}],"ecosystem_specific":{"binaries":[{"wpa_supplicant":"0.7.1-6.18.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2752-1.json"}},{"package":{"name":"wpa_supplicant","ecosystem":"SUSE:Linux Enterprise Server 11 SP3-LTSS","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.1-6.18.3.1"}]}],"ecosystem_specific":{"binaries":[{"wpa_supplicant":"0.7.1-6.18.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2752-1.json"}},{"package":{"name":"wpa_supplicant","ecosystem":"SUSE:Linux Enterprise Server 11 SP3-TERADATA","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.1-6.18.3.1"}]}],"ecosystem_specific":{"binaries":[{"wpa_supplicant":"0.7.1-6.18.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2752-1.json"}},{"package":{"name":"wpa_supplicant","ecosystem":"SUSE:Linux Enterprise Server 11 SP4","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.1-6.18.3.1"}]}],"ecosystem_specific":{"binaries":[{"wpa_supplicant":"0.7.1-6.18.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2752-1.json"}},{"package":{"name":"wpa_supplicant","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 11 SP4","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.1-6.18.3.1"}]}],"ecosystem_specific":{"binaries":[{"wpa_supplicant":"0.7.1-6.18.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:2752-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20172752-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1056061"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13078"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13079"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13080"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13088"}]}