Lucene search

K
redhatRedHatRHSA-2020:1672
HistoryApr 28, 2020 - 9:03 a.m.

(RHSA-2020:1672) Moderate: freeradius:3.0 security update

2020-04-2809:03:31
access.redhat.com
16

2.9 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

54.2%

FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.

Security Fix(es):

  • freeradius: eap-pwd: Information leak due to aborting when needing more than 10 iterations (CVE-2019-13456)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.2 Release Notes linked from the References section.

OSVersionArchitecturePackageVersionFilename
RedHatanyppc64lefreeradius-unixodbc-debuginfo< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-unixODBC-debuginfo-3.0.17-7.module+el8.2.0+4847+336970e8.ppc64le.rpm
RedHatanyppc64lefreeradius-ldap< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-ldap-3.0.17-7.module+el8.2.0+4847+336970e8.ppc64le.rpm
RedHatanyaarch64freeradius-debuginfo< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-debuginfo-3.0.17-7.module+el8.2.0+4847+336970e8.aarch64.rpm
RedHatanyx86_64freeradius-utils-debuginfo< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-utils-debuginfo-3.0.17-7.module+el8.2.0+4847+336970e8.x86_64.rpm
RedHatanyppc64lefreeradius-utils-debuginfo< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-utils-debuginfo-3.0.17-7.module+el8.2.0+4847+336970e8.ppc64le.rpm
RedHatanyppc64lefreeradius-debugsource< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-debugsource-3.0.17-7.module+el8.2.0+4847+336970e8.ppc64le.rpm
RedHatanyppc64lefreeradius-perl-debuginfo< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-perl-debuginfo-3.0.17-7.module+el8.2.0+4847+336970e8.ppc64le.rpm
RedHatanyx86_64freeradius-ldap< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-ldap-3.0.17-7.module+el8.2.0+4847+336970e8.x86_64.rpm
RedHatanyx86_64freeradius-mysql< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-mysql-3.0.17-7.module+el8.2.0+4847+336970e8.x86_64.rpm
RedHatanyaarch64freeradius-krb5-debuginfo< 3.0.17-7.module+el8.2.0+4847+336970e8freeradius-krb5-debuginfo-3.0.17-7.module+el8.2.0+4847+336970e8.aarch64.rpm
Rows per page:
1-10 of 921

2.9 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

54.2%