Lucene search

K
oraclelinuxOracleLinuxELSA-2017-2389
HistoryAug 09, 2017 - 12:00 a.m.

freeradius security update

2017-08-0900:00:00
linux.oracle.com
23

EPSS

0.771

Percentile

98.2%

[3.0.13-8]

  • Avoid misinterpreting zero-size malloc in data2vp_extended() fix.
  • Related: Bug#1469414 CVE-2017-10984 freeradius: Out-of-bounds write in
    data2vp_wimax()
    [3.0.13-7]
  • Resolves: Bug#1469409 CVE-2017-10978 freeradius: Out-of-bounds read/write due
    to improper output buffer size check in make_secret()
  • Resolves: Bug#1469413 CVE-2017-10983 freeradius: Out-of-bounds read in
    fr_dhcp_decode() when decoding option 63
  • Resolves: Bug#1469414 CVE-2017-10984 freeradius: Out-of-bounds write in
    data2vp_wimax()
  • Resolves: Bug#1469417 CVE-2017-10985 freeradius: Infinite loop and memory
    exhaustion with ‘concat’ attributes
  • Resolves: Bug#1469418 CVE-2017-10986 freeradius: Infinite read in
    dhcp_attr2vp()
  • Resolves: Bug#1469421 CVE-2017-10987 freeradius: Buffer over-read in
    fr_dhcp_decode_suboptions()