Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 13.10: USN-2122-1 Critical: FreeRADIUS DoS Threat

ubuntu
Calendar Grey February 26, 2014
Scroller Ubuntu
Ubuntu Security Bulletin USN-2122-1 highlights critical vulnerabilities in FreeRADIUS to prevent service disruptions and authentication failures.
Several security issues were fixed in FreeRADIUS.

Summary

Several security issues were fixed in FreeRADIUS.

Software Description:

- freeradius: high-performance and highly configurable RADIUS server

Details:

It was discovered that FreeRADIUS incorrectly handled unix authentication.

A remote user could successfully authenticate with an expired password.

(CVE-2011-4966)

Pierre Carrier discovered that FreeRADIUS incorrectly handled rlm_pap

hash processing. An authenticated user could use this issue to cause

FreeRADIUS to crash, resulting in a denial of service, or possibly execute

arbitrary code. The default compiler options for affected releases should

reduce the vulnerability to a denial of service. (CVE-2014-2015)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  freeradius                      2.1.12+dfsg-1.2ubuntu5.1

Ubuntu 12.10:
  freeradius                      2.1.12+dfsg-1.1ubuntu0.1

Ubuntu 12.04 LTS:
  freeradius                      2.1.10+dfsg-3ubuntu0.12.04.2

Ubuntu 10.04 LTS:
  freeradius                      2.1.8+dfsg-1ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

CVE-2011-4966, CVE-2014-2015

Severity
critical
Lowest
Low
Medium
High
Critical

February 26, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.