PT-2012-1047 · Freeradius+3 · Freeradius+3

Timo Warns

·

Publicado

2012-09-18

·

Atualizado

2024-06-15

·

CVE-2012-3547

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FreeRADIUS versions 2.1.10 through 2.1.12
Description The issue is related to a stack-based buffer overflow in the cbtls verify function when using TLS-based EAP methods. This can be triggered by a remote attacker sending a client certificate with a long "not after" timestamp, potentially causing a denial of service (server crash) and possibly allowing the execution of arbitrary code. Multiple vulnerabilities in the FreeRADIUS package may lead to breaches of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For FreeRADIUS versions 2.1.10 through 2.1.12, consider updating to a version that fixes the cbtls verify function issue to prevent potential code execution and denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03122
CESA-2012_1326
CVE-2012-3547
DSA-2546-1
OPENSUSE-SU-2012_1200-1
OPENSUSE-SU-2024:10053-1
RHSA-2012:1326
RHSA-2012:1327
RHSA-2012_1326
RHSA-2012_1327

Produtos afetados

Centos
Freeradius
Red Hat
Suse