Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Ubuntu 12.04 LTS USN-1585-1 Critical: FreeRADIUS Denial Of Service

Ubuntu Large Esm H500
FreeRADIUS could be made to crash or run programs if it received specially crafted network traffic.
=========================================================================Ubuntu Security Notice USN-1585-1
September 26, 2012

freeradius vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04

Summary:

FreeRADIUS could be made to crash or run programs if it received
specially crafted network traffic.

Software Description:
- freeradius: a high-performance and highly configurable RADIUS server

Details:

Timo Warns discovered that FreeRADIUS incorrectly handled certain long
timestamps in client certificates. A remote attacker could exploit this
flaw and cause the FreeRADIUS server to crash, resulting in a denial of
service, or possibly execute arbitrary code.

The default compiler options for affected releases should reduce the
vulnerability to a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  freeradius                      2.1.10+dfsg-3ubuntu0.12.04.1

Ubuntu 11.10:
  freeradius                      2.1.10+dfsg-3ubuntu0.11.10.1

Ubuntu 11.04:
  freeradius                      2.1.10+dfsg-2ubuntu2.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-1585-1
  CVE-2012-3547

Package Information:

https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-3ubuntu0.12.04.1

https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-3ubuntu0.11.10.1
  https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-2ubuntu2.1

Ubuntu 12.04 LTS USN-1585-1 Critical: FreeRADIUS Denial Of Service

ubuntu
Calendar Grey September 26, 2012
Dist Ubuntu Esm H88
A vulnerability in FreeRADIUS may result in system crashes or allow unauthorized commands to be executed via specially crafted packets. An update is essential.
FreeRADIUS could be made to crash or run programs if it received specially crafted network traffic.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: freeradius 2.1.10+dfsg-3ubuntu0.12.04.1 Ubuntu 11.10: freeradius 2.1.10+dfsg-3ubuntu0.11.10.1 Ubuntu 11.04: freeradius 2.1.10+dfsg-2ubuntu2.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1585-1

CVE-2012-3547

Severity
critical
Lowest
Low
Medium
High
Critical

September 26, 2012

Package Information

https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-3ubuntu0.12.04.1 https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-3ubuntu0.11.10.1 https://launchpad.net/ubuntu/+source/freeradius/2.1.10+dfsg-2ubuntu2.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here