Logo
componentfreeradius3
Name
freeradius3
Version
3.2.8-r1
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:freeradius:freeradius:3.2.8:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
3.2.8-r1

Patches#


#
Title
Author
Resolve
1
Patch #1
Unknown
2
Patch #2
Unknown
CVE-2017-9148
3
Patch #3
Unknown
4
Patch #4
Unknown
5
Patch #5
Unknown
6
Patch #6
Unknown

Vulnerabilities#


Name
Analysis
Description
Patched
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.
Exploitable
modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.
Exploitable
FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.