PT-2012-1047 · Freeradius+3 · Freeradius+3
Timo Warns
·
Publicado
2012-09-18
·
Atualizado
2024-06-15
·
CVE-2012-3547
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
FreeRADIUS versions 2.1.10 through 2.1.12
Description
The issue is related to a stack-based buffer overflow in the
cbtls verify function when using TLS-based EAP methods. This can be triggered by a remote attacker sending a client certificate with a long "not after" timestamp, potentially causing a denial of service (server crash) and possibly allowing the execution of arbitrary code. Multiple vulnerabilities in the FreeRADIUS package may lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.Recommendations
For FreeRADIUS versions 2.1.10 through 2.1.12, consider updating to a version that fixes the
cbtls verify function issue to prevent potential code execution and denial of service attacks.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Centos
Freeradius
Red Hat
Suse