PT-2017-6783 · Freeradius+2 · Freeradius+2

Vasyl Kaigorodov

·

Published

2015-07-28

·

Updated

2024-06-15

·

CVE-2015-4680

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeRADIUS versions 2.2.x through 2.2.7 FreeRADIUS versions 3.0.x through 3.0.8
Description The issue arises from improper checking of revocation of intermediate CA certificates.
Recommendations For FreeRADIUS versions 2.2.x through 2.2.7, update to version 2.2.8 or later. For FreeRADIUS versions 3.0.x through 3.0.8, update to version 3.0.9 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1003
CVE-2015-4680
DLA-977-1
MGASA-2015-0291
OPENSUSE-SU-2024:10767-1
SUSE-SU-2017:0102-1
SUSE-SU-2017:1777-1
SUSE-SU-2017_0102-1
SUSE-SU-2017_1777-1

Affected Products

Alt Linux
Freeradius
Suse