From: Marius Bakke <mbakke@fastmail.com>
To: 35563@debbugs.gnu.org
Subject: [bug#35563] WPA Supplicant 2.8
Date: Sat, 04 May 2019 18:26:42 +0200 [thread overview]
Message-ID: <87sgtudw3h.fsf@fastmail.com> (raw)
[-- Attachment #1.1: Type: text/plain, Size: 251 bytes --]
Hello!
Attached is a security update for WPA Supplicant.
The new version toggles a lot of build-time options to more closely
resemble what Debian and Arch do. Unfortunately the new defaults
appears to require OpenSSL instead of GnuTLS.
Thoughts?
[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1.2: 0001-gnu-wpa_supplicant-Update-to-2.8-security-fixes.patch --]
[-- Type: text/x-patch, Size: 3178 bytes --]
From 194bb2914a0724587f04dd03cb4dd40465887248 Mon Sep 17 00:00:00 2001
From: Marius Bakke <mbakke@fastmail.com>
Date: Tue, 30 Apr 2019 00:05:36 +0200
Subject: [PATCH] gnu: wpa_supplicant: Update to 2.8 [security fixes].
This release fixes CVE-2019-9494, CVE-2019-9495, CVE-2019-9496, CVE-2019-9497,
CVE-2019-9498, CVE-2019-9499, and CVE-2019-11555.
* gnu/packages/admin.scm (wpa-supplicant-minimal): Update to 2.8.
[source](snippet): New field. Disable D-Bus.
[arguments]: Remove now-default CONFIG_DEBUG_SYSLOG=y. Change CONFIG_TLS to
use OpenSSL rather than GnuTLS.
[inputs]: Remove GNUTLS and LIBGCRYPT. Add OPENSSL-NEXT.
(wpa-supplicant)[arguments]: Remove obsolete CONFIG_CTRL_IFACE_DBUS=y.
---
gnu/packages/admin.scm | 24 +++++++++++++-----------
1 file changed, 13 insertions(+), 11 deletions(-)
diff --git a/gnu/packages/admin.scm b/gnu/packages/admin.scm
index 275ce8bb2f..e0fc1c54c9 100644
--- a/gnu/packages/admin.scm
+++ b/gnu/packages/admin.scm
@@ -1198,16 +1198,23 @@ commands and their arguments.")
(define-public wpa-supplicant-minimal
(package
(name "wpa-supplicant-minimal")
- (version "2.7")
+ (version "2.8")
(source (origin
(method url-fetch)
(uri (string-append
"https://w1.fi/releases/wpa_supplicant-"
- version
- ".tar.gz"))
+ version ".tar.gz"))
(sha256
(base32
- "0x1hqyahq44jyla8jl6791nnwrgicrhidadikrnqxsm2nw36pskn"))))
+ "15ixzm347n8w6gdvi3j3yks3i15qmp6by9ayvswm34d929m372d6"))
+ (modules '((guix build utils)))
+ (snippet
+ '(begin
+ (substitute* "wpa_supplicant/defconfig"
+ ;; Disable D-Bus by default.
+ (("^CONFIG_CTRL_IFACE_DBUS_" line _)
+ (string-append "#" line)))
+ #t))))
(build-system gnu-build-system)
(arguments
'(#:phases
@@ -1218,10 +1225,7 @@ commands and their arguments.")
(copy-file "defconfig" ".config")
(let ((port (open-file ".config" "al")))
(display "
- CONFIG_DEBUG_SYSLOG=y
-
- # Choose GnuTLS (the default is OpenSSL.)
- CONFIG_TLS=gnutls
+ CONFIG_TLS=openssl
CONFIG_DRIVER_NL80211=y
CFLAGS += $(shell pkg-config libnl-3.0 --cflags)
@@ -1255,8 +1259,7 @@ commands and their arguments.")
(inputs
`(("readline" ,readline)
("libnl" ,libnl)
- ("gnutls" ,gnutls)
- ("libgcrypt" ,libgcrypt))) ;needed by crypto_gnutls.c
+ ("openssl" ,openssl-next)))
(native-inputs
`(("pkg-config" ,pkg-config)))
(home-page "https://w1.fi/wpa_supplicant/")
@@ -1289,7 +1292,6 @@ command.")
(lambda _
(let ((port (open-file ".config" "al")))
(display "
- CONFIG_CTRL_IFACE_DBUS=y
CONFIG_CTRL_IFACE_DBUS_NEW=y
CONFIG_CTRL_IFACE_DBUS_INTRO=y\n" port)
(close-port port))
--
2.21.0
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 487 bytes --]
next reply other threads:[~2019-05-04 16:27 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-05-04 16:26 Marius Bakke [this message]
2019-05-06 8:10 ` [bug#35563] WPA Supplicant 2.8 Ludovic Courtès
2019-05-06 13:20 ` Marius Bakke
2019-05-07 15:21 ` Ludovic Courtès
2019-05-09 15:35 ` bug#35563: " Marius Bakke
2019-05-10 7:52 ` [bug#35563] " Ludovic Courtès
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://guix.gnu.org/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87sgtudw3h.fsf@fastmail.com \
--to=mbakke@fastmail.com \
--cc=35563@debbugs.gnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://git.savannah.gnu.org/cgit/guix.git
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).