Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9148

Опубликовано: 29 мая 2017
Источник: debian
EPSS Низкий

Описание

The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freeradiusfixed3.0.12+dfsg-5package
freeradiusnot-affectedjessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2017/05/29/1

  • http://freeradius.org/security.html#session-resumption-2017

  • https://anonscm.debian.org/cgit/pkg-freeradius/freeradius.git/commit/?id=8d681449aa95ee4388b5e3c266bdb070a264f563

EPSS

Процентиль: 78%
0.01209
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.

CVSS3: 7.4
redhat
больше 8 лет назад

The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.

CVSS3: 9.8
nvd
больше 8 лет назад

The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.

suse-cvrf
больше 8 лет назад

Security update for freeradius-server

suse-cvrf
больше 8 лет назад

Security update for freeradius-server

EPSS

Процентиль: 78%
0.01209
Низкий