{"id":"openSUSE-SU-2021:0452-1","summary":"Security update for connman","details":"This update for connman fixes the following issues:\n\nUpdate to 1.39 (boo#1181751):\n\n* Fix issue with scanning state synchronization and iwd.\n* Fix issue with invalid key with 4-way handshake offloading.\n* Fix issue with DNS proxy length checks to prevent buffer overflow. (CVE-2021-26675)\n* Fix issue with DHCP leaking stack data via uninitialized variable. (CVE-2021-26676)\n\nUpdate to 1.38:\n\n* Fix issue with online check on IP address update.\n* Fix issue with OpenVPN and encrypted private keys.\n* Fix issue with finishing of VPN connections.\n* Add support for updated stable iwd APIs.\n* Add support for WireGuard networks.\n\nUpdate to 1.37:\n\n* Fix issue with handling invalid gateway addresses.\n* Fix issue with handling updates of default gateway.\n* Fix issue with DHCP servers that require broadcast flag.\n* Add support for option to use gateways as time servers.\n* Add support for option to select default technology.\n* Add support for Address Conflict Detection (ACD).\n* Add support for IPv6 iptables management.\n\nChange in 1.36:\n\n* Fix issue with DNS short response on error handling.\n* Fix issue with handling incoming DNS requests.\n* Fix issue with handling empty timeserver list.\n* Fix issue with incorrect DHCP byte order.\n* Fix issue with AllowDomainnameUpdates handling.\n* Fix issue with IPv4 link-local IP conflict error.\n* Fix issue with handling WISPr over TLS connections.\n* Fix issue with WiFi background scanning handling.\n* Fix issue with WiFi disconnect+connect race condition.\n* Fix issue with WiFi scanning and tethering operation.\n* Fix issue with WiFi security change handling.\n* Fix issue with missing signal for WPS changes.\n* Fix issue with online check retry handling.\n* Add support for systemd-resolved backend.\n* Add support for mDNS configuration setup.\n\n\nThis update was imported from the openSUSE:Leap:15.2:Update update project.","modified":"2026-03-11T07:32:58.879048Z","published":"2021-03-20T13:05:14Z","related":["CVE-2021-26675","CVE-2021-26676"],"upstream":["CVE-2021-26675","CVE-2021-26676"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/SB6R3XK5JUBLJRIRVG3PVC2DOVU5KBVK/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181751"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-26675"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-26676"}],"affected":[{"package":{"name":"connman","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/connman&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.39-bp152.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"connman-test":"1.39-bp152.4.3.1","connman-devel":"1.39-bp152.4.3.1","connman-plugin-hh2serial-gps":"1.39-bp152.4.3.1","connman":"1.39-bp152.4.3.1","connman-plugin-wireguard":"1.39-bp152.4.3.1","connman-plugin-pptp":"1.39-bp152.4.3.1","connman-plugin-vpnc":"1.39-bp152.4.3.1","connman-client":"1.39-bp152.4.3.1","connman-plugin-openconnect":"1.39-bp152.4.3.1","connman-plugin-openvpn":"1.39-bp152.4.3.1","connman-doc":"1.39-bp152.4.3.1","connman-nmcompat":"1.39-bp152.4.3.1","connman-plugin-iospm":"1.39-bp152.4.3.1","connman-plugin-l2tp":"1.39-bp152.4.3.1","connman-plugin-polkit":"1.39-bp152.4.3.1","connman-plugin-tist":"1.39-bp152.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0452-1.json"}}],"schema_version":"1.7.5"}