[3.6] freeradius: Multiple vulnerabilities (CVE-2019-11234, CVE-2019-11235)ID: oval:org.secpod.oval:def:1801405 | Date: (C)2019-06-19 (M)2021-11-09 |
Class: PATCH | Family: unix |
CVE-2019-11234: eap-pwd: fake authentication using reflection¶ A vulnerability was found in FreeRadius. An attacker can reflect the received scalar and element from the server in it"s own commit message, and subsequently reflect the confirm value as well. This causes the adversary to successfully authenticate as the victim. Fortunately, the adversary will not posses the negotiated session key, meaning the adversary cannot actually perform any actions as this user. Affected Versions:¶ freeradius 3.0.0 through 3.0.18 Fixed In Version:¶ freeradius 3.0.19
Platform: |
Alpine Linux 3.6 |