Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Gentoo: GLSA 200505-13 Normal: FreeRADIUS SQL Injection & DoS Advisory

gentoo
Calendar Grey May 20, 2005
Scroller Gentoo
Important notice regarding FreeRADIUS: critical vulnerabilities detected including SQL injection and risk of Denial of Service on Gentoo systems. Immediate action recommended!
This advisory incorrectly described FreeRADIUS versions as being vulnerable to a remote compromise

Summary

Gentoo Linux Security Advisory [ERRATA UPDATE] GLSA 200505-13:02 https://security.gentoo.org/ Severity: Normal Title: FreeRADIUS: SQL injection and Denial of Service vulnerability Date: May 17, 2005 Updated: May 20, 2005 Bugs: #91736 ID: 200505-13:02

Errata ===== This advisory incorrectly described FreeRADIUS versions as being vulnerable to a remote compromise. After further verifications, it appears to only result in potential Denial of Service. The SQL injection issue is not affected by this. Many thanks to Nicolas Baradakis for bringing this to our attention.
The corrected sections appear below.
Synopsis ======= The FreeRADIUS server is vulnerable to an SQL injection attack and a buffer overflow, possibly resulting in disclosure and modification of data and Denial of Service.
Affected packages ================ ------------------------------------------------------------------- Pa...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround