Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-3596

Опубликовано: 09 июл. 2024
Источник: debian

Описание

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freeradiusfixed3.2.5+dfsg-1package
freeradiusno-dsabookwormpackage
freeradiuspostponedbullseyepackage

Примечания

  • https://www.blastradius.fail/

  • https://kb.cert.org/vuls/id/456537

  • https://www.openwall.com/lists/oss-security/2024/07/09/4

  • https://blog.cloudflare.com/radius-udp-vulnerable-md5-attack/

  • CVE is for the RADIUS Protocol issue under RFC 2865, but track for time beeing

  • sources which add mitigations for the "BlastRADIUS protocol vulnerability".

  • Breaks unrelated software like proftpd: https://github.com/proftpd/proftpd/issues/1840 (fixed)

Связанные уязвимости

CVSS3: 9
ubuntu
11 месяцев назад

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

CVSS3: 9
redhat
12 месяцев назад

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

CVSS3: 9
nvd
11 месяцев назад

RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.

CVSS3: 7.5
msrc
12 месяцев назад

CERT/CC: CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability

suse-cvrf
11 месяцев назад

Security update for freeradius-server