[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

[3.6] freeradius: Multiple vulnerabilities (CVE-2019-11234, CVE-2019-11235)

ID: oval:org.secpod.oval:def:1801405Date: (C)2019-06-19   (M)2021-11-09
Class: PATCHFamily: unix




CVE-2019-11234: eap-pwd: fake authentication using reflection¶ A vulnerability was found in FreeRadius. An attacker can reflect the received scalar and element from the server in it"s own commit message, and subsequently reflect the confirm value as well. This causes the adversary to successfully authenticate as the victim. Fortunately, the adversary will not posses the negotiated session key, meaning the adversary cannot actually perform any actions as this user. Affected Versions:¶ freeradius 3.0.0 through 3.0.18 Fixed In Version:¶ freeradius 3.0.19

Platform:
Alpine Linux 3.6
Product:
freeradius
Reference:
10328
CVE-2019-11234
CVE-2019-11235
CVE    2
CVE-2019-11234
CVE-2019-11235
CPE    57
cpe:/a:freeradius:freeradius
cpe:/a:freeradius:freeradius:1.0.0
cpe:/a:freeradius:freeradius:0.2
cpe:/a:freeradius:freeradius:2.0
...

© SecPod Technologies