FreeBSD Bugzilla – Attachment 157334 Details for
Bug 200567
net/hostapd: [security] multiple vulnerabilities
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
net/hostapd: security update
hostapd-2.4_1.diff (text/plain), 8.15 KB, created by
Jason Unovitch
on 2015-06-01 10:12:52 UTC
(
hide
)
Description:
net/hostapd: security update
Filename:
MIME Type:
Creator:
Jason Unovitch
Created:
2015-06-01 10:12:52 UTC
Size:
8.15 KB
patch
obsolete
>Index: net/hostapd/Makefile >=================================================================== >--- net/hostapd/Makefile (revision 388209) >+++ net/hostapd/Makefile (working copy) >@@ -3,6 +3,7 @@ > > PORTNAME= hostapd > PORTVERSION= 2.4 >+PORTREVISION= 1 > CATEGORIES= net > MASTER_SITES= http://w1.fi/releases/ > >Index: net/hostapd/files/patch-src_ap_wmm.c >=================================================================== >--- net/hostapd/files/patch-src_ap_wmm.c (revision 0) >+++ net/hostapd/files/patch-src_ap_wmm.c (working copy) >@@ -0,0 +1,12 @@ >+--- src/ap/wmm.c.orig 2015-03-15 17:30:39 UTC >++++ src/ap/wmm.c >+@@ -274,6 +274,9 @@ void hostapd_wmm_action(struct hostapd_d >+ return; >+ } >+ >++ if (left < 0) >++ return; /* not a valid WMM Action frame */ >++ >+ /* extract the tspec info element */ >+ if (ieee802_11_parse_elems(pos, left, &elems, 1) == ParseFailed) { >+ hostapd_logger(hapd, mgmt->sa, HOSTAPD_MODULE_IEEE80211, > >Property changes on: net/hostapd/files/patch-src_ap_wmm.c >___________________________________________________________________ >Added: fbsd:nokeywords >## -0,0 +1 ## >+yes >\ No newline at end of property >Added: svn:eol-style >## -0,0 +1 ## >+native >\ No newline at end of property >Added: svn:mime-type >## -0,0 +1 ## >+text/plain >\ No newline at end of property >Index: net/hostapd/files/patch-src_eap__peer_eap__pwd.c >=================================================================== >--- net/hostapd/files/patch-src_eap__peer_eap__pwd.c (revision 0) >+++ net/hostapd/files/patch-src_eap__peer_eap__pwd.c (working copy) >@@ -0,0 +1,77 @@ >+--- src/eap_peer/eap_pwd.c.orig 2015-03-15 17:30:39 UTC >++++ src/eap_peer/eap_pwd.c >+@@ -301,6 +301,23 @@ eap_pwd_perform_commit_exchange(struct e >+ BIGNUM *mask = NULL, *x = NULL, *y = NULL, *cofactor = NULL; >+ u16 offset; >+ u8 *ptr, *scalar = NULL, *element = NULL; >++ size_t prime_len, order_len; >++ >++ if (data->state != PWD_Commit_Req) { >++ ret->ignore = TRUE; >++ goto fin; >++ } >++ >++ prime_len = BN_num_bytes(data->grp->prime); >++ order_len = BN_num_bytes(data->grp->order); >++ >++ if (payload_len != 2 * prime_len + order_len) { >++ wpa_printf(MSG_INFO, >++ "EAP-pwd: Unexpected Commit payload length %u (expected %u)", >++ (unsigned int) payload_len, >++ (unsigned int) (2 * prime_len + order_len)); >++ goto fin; >++ } >+ >+ if (((data->private_value = BN_new()) == NULL) || >+ ((data->my_element = EC_POINT_new(data->grp->group)) == NULL) || >+@@ -500,6 +517,18 @@ eap_pwd_perform_confirm_exchange(struct >+ u8 conf[SHA256_MAC_LEN], *cruft = NULL, *ptr; >+ int offset; >+ >++ if (data->state != PWD_Confirm_Req) { >++ ret->ignore = TRUE; >++ goto fin; >++ } >++ >++ if (payload_len != SHA256_MAC_LEN) { >++ wpa_printf(MSG_INFO, >++ "EAP-pwd: Unexpected Confirm payload length %u (expected %u)", >++ (unsigned int) payload_len, SHA256_MAC_LEN); >++ goto fin; >++ } >++ >+ /* >+ * first build up the ciphersuite which is group | random_function | >+ * prf >+@@ -783,11 +812,23 @@ eap_pwd_process(struct eap_sm *sm, void >+ * if it's the first fragment there'll be a length field >+ */ >+ if (EAP_PWD_GET_LENGTH_BIT(lm_exch)) { >++ if (len < 2) { >++ wpa_printf(MSG_DEBUG, >++ "EAP-pwd: Frame too short to contain Total-Length field"); >++ ret->ignore = TRUE; >++ return NULL; >++ } >+ tot_len = WPA_GET_BE16(pos); >+ wpa_printf(MSG_DEBUG, "EAP-pwd: Incoming fragments whose " >+ "total length = %d", tot_len); >+ if (tot_len > 15000) >+ return NULL; >++ if (data->inbuf) { >++ wpa_printf(MSG_DEBUG, >++ "EAP-pwd: Unexpected new fragment start when previous fragment is still in use"); >++ ret->ignore = TRUE; >++ return NULL; >++ } >+ data->inbuf = wpabuf_alloc(tot_len); >+ if (data->inbuf == NULL) { >+ wpa_printf(MSG_INFO, "Out of memory to buffer " >+@@ -873,6 +914,7 @@ eap_pwd_process(struct eap_sm *sm, void >+ /* >+ * we have output! Do we need to fragment it? >+ */ >++ lm_exch = EAP_PWD_GET_EXCHANGE(lm_exch); >+ len = wpabuf_len(data->outbuf); >+ if ((len + EAP_PWD_HDR_SIZE) > data->mtu) { >+ resp = eap_msg_alloc(EAP_VENDOR_IETF, EAP_TYPE_PWD, data->mtu, > >Property changes on: net/hostapd/files/patch-src_eap__peer_eap__pwd.c >___________________________________________________________________ >Added: svn:mime-type >## -0,0 +1 ## >+text/plain >\ No newline at end of property >Added: fbsd:nokeywords >## -0,0 +1 ## >+yes >\ No newline at end of property >Added: svn:eol-style >## -0,0 +1 ## >+native >\ No newline at end of property >Index: net/hostapd/files/patch-src_eap__server_eap__server__pwd.c >=================================================================== >--- net/hostapd/files/patch-src_eap__server_eap__server__pwd.c (revision 0) >+++ net/hostapd/files/patch-src_eap__server_eap__server__pwd.c (working copy) >@@ -0,0 +1,60 @@ >+--- src/eap_server/eap_server_pwd.c.orig 2015-03-15 17:30:39 UTC >++++ src/eap_server/eap_server_pwd.c >+@@ -634,9 +634,21 @@ eap_pwd_process_commit_resp(struct eap_s >+ BIGNUM *x = NULL, *y = NULL, *cofactor = NULL; >+ EC_POINT *K = NULL, *point = NULL; >+ int res = 0; >++ size_t prime_len, order_len; >+ >+ wpa_printf(MSG_DEBUG, "EAP-pwd: Received commit response"); >+ >++ prime_len = BN_num_bytes(data->grp->prime); >++ order_len = BN_num_bytes(data->grp->order); >++ >++ if (payload_len != 2 * prime_len + order_len) { >++ wpa_printf(MSG_INFO, >++ "EAP-pwd: Unexpected Commit payload length %u (expected %u)", >++ (unsigned int) payload_len, >++ (unsigned int) (2 * prime_len + order_len)); >++ goto fin; >++ } >++ >+ if (((data->peer_scalar = BN_new()) == NULL) || >+ ((data->k = BN_new()) == NULL) || >+ ((cofactor = BN_new()) == NULL) || >+@@ -752,6 +764,13 @@ eap_pwd_process_confirm_resp(struct eap_ >+ u8 conf[SHA256_MAC_LEN], *cruft = NULL, *ptr; >+ int offset; >+ >++ if (payload_len != SHA256_MAC_LEN) { >++ wpa_printf(MSG_INFO, >++ "EAP-pwd: Unexpected Confirm payload length %u (expected %u)", >++ (unsigned int) payload_len, SHA256_MAC_LEN); >++ goto fin; >++ } >++ >+ /* build up the ciphersuite: group | random_function | prf */ >+ grp = htons(data->group_num); >+ ptr = (u8 *) &cs; >+@@ -901,11 +920,21 @@ static void eap_pwd_process(struct eap_s >+ * the first fragment has a total length >+ */ >+ if (EAP_PWD_GET_LENGTH_BIT(lm_exch)) { >++ if (len < 2) { >++ wpa_printf(MSG_DEBUG, >++ "EAP-pwd: Frame too short to contain Total-Length field"); >++ return; >++ } >+ tot_len = WPA_GET_BE16(pos); >+ wpa_printf(MSG_DEBUG, "EAP-pwd: Incoming fragments, total " >+ "length = %d", tot_len); >+ if (tot_len > 15000) >+ return; >++ if (data->inbuf) { >++ wpa_printf(MSG_DEBUG, >++ "EAP-pwd: Unexpected new fragment start when previous fragment is still in use"); >++ return; >++ } >+ data->inbuf = wpabuf_alloc(tot_len); >+ if (data->inbuf == NULL) { >+ wpa_printf(MSG_INFO, "EAP-pwd: Out of memory to " > >Property changes on: net/hostapd/files/patch-src_eap__server_eap__server__pwd.c >___________________________________________________________________ >Added: svn:mime-type >## -0,0 +1 ## >+text/plain >\ No newline at end of property >Added: fbsd:nokeywords >## -0,0 +1 ## >+yes >\ No newline at end of property >Added: svn:eol-style >## -0,0 +1 ## >+native >\ No newline at end of property >Index: net/hostapd/files/patch-src_wps_httpread.c >=================================================================== >--- net/hostapd/files/patch-src_wps_httpread.c (revision 0) >+++ net/hostapd/files/patch-src_wps_httpread.c (working copy) >@@ -0,0 +1,16 @@ >+--- src/wps/httpread.c.orig 2015-03-15 17:30:39 UTC >++++ src/wps/httpread.c >+@@ -533,6 +533,13 @@ static void httpread_read_handler(int sd >+ if (!isxdigit(*cbp)) >+ goto bad; >+ h->chunk_size = strtoul(cbp, NULL, 16); >++ if (h->chunk_size < 0 || >++ h->chunk_size > h->max_bytes) { >++ wpa_printf(MSG_DEBUG, >++ "httpread: Invalid chunk size %d", >++ h->chunk_size); >++ goto bad; >++ } >+ /* throw away chunk header >+ * so we have only real data >+ */ > >Property changes on: net/hostapd/files/patch-src_wps_httpread.c >___________________________________________________________________ >Added: svn:mime-type >## -0,0 +1 ## >+text/plain >\ No newline at end of property >Added: fbsd:nokeywords >## -0,0 +1 ## >+yes >\ No newline at end of property >Added: svn:eol-style >## -0,0 +1 ## >+native >\ No newline at end of property
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 200567
: 157334 |
157336