package/hostapd: add upstream 2020-1 security patches
authorPeter Korsgaard <peter@korsgaard.com>
Mon, 24 Aug 2020 10:46:15 +0000 (12:46 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Mon, 24 Aug 2020 20:38:51 +0000 (22:38 +0200)
commit9b020359b141f5316276079cbea8001649bcec0c
treed54d03db29d91743d391188b3223f9c882551c24
parentdac45969b6b8f85bdb9a3dd76e12211fc7c131ab
package/hostapd: add upstream 2020-1 security patches

Fixes the following security vulnerabilities:

CVE-2020-12695: The Open Connectivity Foundation UPnP specification before
2020-04-17 does not forbid the acceptance of a subscription request with a
delivery URL on a different network segment than the fully qualified
event-subscription URL, aka the CallStranger issue.

For details, see the advisory:
https://w1.fi/security/2020-1/upnp-subscribe-misbehavior-wps-ap.txt

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/hostapd/hostapd.hash
package/hostapd/hostapd.mk