Lucene search

K
redhatRedHatRHSA-2020:4799
HistoryNov 03, 2020 - 12:37 p.m.

(RHSA-2020:4799) Moderate: freeradius:3.0 security and bug fix update

2020-11-0312:37:04
access.redhat.com
20
freeradius
authentication
authorization
security fix
network
cve-2019-17185
red hat enterprise linux 8.3

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.5%

FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.

Security Fix(es):

  • freeradius: eap-pwd: DoS issues due to multithreaded BN_CTX access (CVE-2019-17185)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.3 Release Notes linked from the References section.

OSVersionArchitecturePackageVersionFilename
RedHatanys390xfreeradius-rest-debuginfo< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-rest-debuginfo-3.0.20-3.module+el8.3.0+7597+67902674.s390x.rpm
RedHatanyx86_64freeradius-perl< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-perl-3.0.20-3.module+el8.3.0+7597+67902674.x86_64.rpm
RedHatanys390xfreeradius-perl-debuginfo< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-perl-debuginfo-3.0.20-3.module+el8.3.0+7597+67902674.s390x.rpm
RedHatanyaarch64python3-freeradius< 3.0.20-3.module+el8.3.0+7597+67902674python3-freeradius-3.0.20-3.module+el8.3.0+7597+67902674.aarch64.rpm
RedHatanys390xfreeradius-utils-debuginfo< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-utils-debuginfo-3.0.20-3.module+el8.3.0+7597+67902674.s390x.rpm
RedHatanyaarch64freeradius-mysql-debuginfo< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-mysql-debuginfo-3.0.20-3.module+el8.3.0+7597+67902674.aarch64.rpm
RedHatanyaarch64freeradius-unixodbc-debuginfo< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-unixODBC-debuginfo-3.0.20-3.module+el8.3.0+7597+67902674.aarch64.rpm
RedHatanyx86_64freeradius-utils-debuginfo< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-utils-debuginfo-3.0.20-3.module+el8.3.0+7597+67902674.x86_64.rpm
RedHatanyx86_64freeradius-krb5< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-krb5-3.0.20-3.module+el8.3.0+7597+67902674.x86_64.rpm
RedHatanyx86_64freeradius-devel< 3.0.20-3.module+el8.3.0+7597+67902674freeradius-devel-3.0.20-3.module+el8.3.0+7597+67902674.x86_64.rpm
Rows per page:
1-10 of 1001

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.5%