{"affected":[{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:OpenStack Cloud 6","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20OpenStack%20Cloud%206"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP3","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12-LTSS","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1-LTSS","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1-LTSS"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP3","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"wpa_supplicant":"2.2-15.3.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP3","name":"wpa_supplicant","purl":"pkg:rpm/suse/wpa_supplicant&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.2-15.3.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for wpa_supplicant fixes the security issues:\n\n- Several vulnerabilities in standard conforming implementations of the WPA2\n  protocol have been discovered and published under the code name KRACK. This\n  update remedies those issues in a backwards compatible manner, i.e. the\n  updated wpa_supplicant can interface properly with both vulnerable and\n  patched implementations of WPA2, but an attacker won't be able to exploit the\n  KRACK weaknesses in those connections anymore even if the other party is\n  still vulnerable. [bsc#1056061, CVE-2017-13078, CVE-2017-13079,\n  CVE-2017-13080, CVE-2017-13081, CVE-2017-13087, CVE-2017-13088]\n","id":"SUSE-SU-2017:2745-1","modified":"2017-10-17T12:17:01Z","published":"2017-10-17T12:17:01Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20172745-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1056061"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13078"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13079"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13080"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13081"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13087"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-13088"}],"related":["CVE-2017-13078","CVE-2017-13079","CVE-2017-13080","CVE-2017-13081","CVE-2017-13087","CVE-2017-13088"],"summary":"Security update for wpa_supplicant","upstream":["CVE-2017-13078","CVE-2017-13079","CVE-2017-13080","CVE-2017-13081","CVE-2017-13087","CVE-2017-13088"]}