RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. (CVE-2024-3596) . MGASA-2024-0385 - Updated krb5 packages fix security vulnerability Publication date: 02 Dec 2024 URL: https://advisories.mageia.org/MGASA-2024-0385.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-3596 RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature. (CVE-2024-3596) References: - https://bugs.mageia.org/show_bug.cgi?id=33769 - https://lists.fedoraproject.org/archives/list/
Important: freeradius security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4935", "synopsis": "Important: freeradius security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for freeradius.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.\n\nSecurity Fix(es):\n\n* freeradius: forgery attack (CVE-2024-3596)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2263240", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2263240", "description": ""}], "cves": [{"name": "CVE-2024-3596", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3596", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-01T01:29:16.922240Z", "rpms": {"Rocky Linux 9": {"nvras": ["freeradius-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-0:3.0.21-40.el9_4.src.rpm", "freeradius-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-debugsource-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-debugsource-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-debugsource-0:3.0.21-40.el9_4.s390x.rpm","freeradius-debugsource-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-devel-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-devel-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-devel-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-devel-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-doc-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-doc-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-doc-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-doc-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-krb5-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-krb5-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-ldap-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-ldap-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-mysql-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-mysql-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-perl-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-perl-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-perl-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-perl-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-perl-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-perl-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm","freeradius-perl-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-perl-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-postgresql-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-postgresql-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-rest-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-rest-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-rest-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-rest-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-rest-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-sqlite-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-sqlite-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-unixODBC-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-unixODBC-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-utils-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-utils-0:3.0.21-40.el9_4.ppc64le.rpm","freeradius-utils-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-utils-0:3.0.21-40.el9_4.x86_64.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "freeradius-utils-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm", "python3-freeradius-0:3.0.21-40.el9_4.aarch64.rpm", "python3-freeradius-0:3.0.21-40.el9_4.ppc64le.rpm", "python3-freeradius-0:3.0.21-40.el9_4.s390x.rpm", "python3-freeradius-0:3.0.21-40.el9_4.x86_64.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.aarch64.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.ppc64le.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.s390x.rpm", "python3-freeradius-debuginfo-0:3.0.21-40.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Urgent update released for FreeRADIUS on Rocky Linux 9, fixing a vulnerability linked to a forgery exploit identified as CVE-2024-3596.. freeradius security, rocky linux update, authentication service, network security. . Severity: Important. LinuxSecurity.com Team
Important: freeradius:3.0 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4936", "synopsis": "Important: freeradius:3.0 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for freeradius, module.freeradius.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.\n\nSecurity Fix(es):\n\n* freeradius: forgery attack (CVE-2024-3596)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2263240", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2263240", "description": ""}], "cves": [{"name": "CVE-2024-3596", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-3596", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-01T01:28:22.605677Z", "rpms": {"Rocky Linux 8": {"nvras": ["freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.src.rpm", "freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-debugsource-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-debugsource-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-devel-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm","freeradius-devel-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-doc-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-doc-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-krb5-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-krb5-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-krb5-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-krb5-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-ldap-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-ldap-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-ldap-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-ldap-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-mysql-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-mysql-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-mysql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-mysql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-perl-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-perl-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-perl-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-perl-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-postgresql-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-postgresql-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-postgresql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-postgresql-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-rest-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-rest-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-rest-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm","freeradius-rest-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-sqlite-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-sqlite-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-sqlite-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-sqlite-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-unixODBC-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-unixODBC-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-unixODBC-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-utils-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-utils-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "freeradius-utils-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "freeradius-utils-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "python3-freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "python3-freeradius-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm", "python3-freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.aarch64.rpm", "python3-freeradius-debuginfo-0:3.0.20-15.module+el8.10.0+1841+f214069a.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An update for FreeRADIUS on Rocky Linux 8 has been released to patch vulnerabilities related to forgery attacks, enhancing system security and integrity. freeradius update, important security fix, Rocky Linux advisory. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.