[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3930-1 freeradius -- freeradius

ID: oval:org.secpod.oval:def:53113Date: (C)2019-04-04   (M)2023-12-20
Class: PATCHFamily: unix




Guido Vranken discovered that FreeRADIUS, an open source implementation of RADIUS, the IETF protocol for AAA , did not properly handle memory when processing packets. This would allow a remote attacker to cause a denial-of-service by application crash, or potentially execute arbitrary code. All those issues are covered by this single DSA, but it"s worth noting that not all issues affect all releases: - CVE-2017-10978 and CVE-2017-10983 affect both jessie and stretch - CVE-2017-10979, CVE-2017-10980, CVE-2017-10981 and CVE-2017-10982 affect only jessie - CVE-2017-10984, CVE-2017-10985, CVE-2017-10986 and CVE-2017-10987 affect only stretch.

Platform:
Linux Mint 3
Product:
freeradius
Reference:
DSA-3930-1
CVE-2017-10978
CVE-2017-10979
CVE-2017-10980
CVE-2017-10981
CVE-2017-10982
CVE-2017-10983
CVE-2017-10984
CVE-2017-10985
CVE-2017-10986
CVE-2017-10987
CVE    10
CVE-2017-10981
CVE-2017-10980
CVE-2017-10983
CVE-2017-10982
...
CPE    30
cpe:/a:freeradius:freeradius
cpe:/a:freeradius:freeradius:2.0.4
cpe:/a:freeradius:freeradius:2.0.5
cpe:/a:freeradius:freeradius:2.0.1
...

© SecPod Technologies