Lucene search

K
mageiaGentoo FoundationMGASA-2018-0323
HistoryJul 25, 2018 - 11:24 a.m.

Updated nonfree firmware packages fixes security vulnerabilities

2018-07-2511:24:17
Gentoo Foundation
advisories.mageia.org
51

CVSS2

5.4

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.004

Percentile

72.8%

This firmware update fixes the following security issues: * bcm4356, bcm4354, bcm43362, bcm43340, bcm43430: - dropping replayed M3 for offloaded 4-way handshake (CVE-2017-13077, CVE-2017-13078, CVE-2017-13079) - dropping replayed G1 for offloaded GTK rekey (CVE-2017-13080, CVE-2017-13081) Also in this update: * Updated bluethooth firmwares for Intel 7260, 7265, 8260 * fixed firmware for Amd Vega10 VCE causing a hang

CVSS2

5.4

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:A/AC:M/Au:N/C:P/I:P/A:P

CVSS3

6.8

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.004

Percentile

72.8%