Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Ubuntu 12.04 LTS USN-1585-1 Critical: FreeRADIUS Denial Of Service

ubuntu
Calendar Grey September 26, 2012
Scroller Ubuntu
A vulnerability in FreeRADIUS may result in system crashes or allow unauthorized commands to be executed via specially crafted packets. An update is essential.
FreeRADIUS could be made to crash or run programs if it received specially crafted network traffic.

Summary

FreeRADIUS could be made to crash or run programs if it received

specially crafted network traffic.

Software Description:

- freeradius: a high-performance and highly configurable RADIUS server

Details:

Timo Warns discovered that FreeRADIUS incorrectly handled certain long

timestamps in client certificates. A remote attacker could exploit this

flaw and cause the FreeRADIUS server to crash, resulting in a denial of

service, or possibly execute arbitrary code.

The default compiler options for affected releases should reduce the

vulnerability to a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
  freeradius                      2.1.10+dfsg-3ubuntu0.12.04.1

Ubuntu 11.10:
  freeradius                      2.1.10+dfsg-3ubuntu0.11.10.1

Ubuntu 11.04:
  freeradius                      2.1.10+dfsg-2ubuntu2.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1585-1

CVE-2012-3547

Severity
critical
Lowest
Low
Medium
High
Critical

September 26, 2012

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.