Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Ubuntu Security Notice USN-5785-1[6]
- Authored by Ubuntu[7] | Site security.ubuntu.com[8]
-
Ubuntu Security Notice 5785-1 - It was discovered that FreeRADIUS incorrectly handled multiple EAP-pwd handshakes. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. Shane Guan discovered that FreeRADIUS incorrectly handled memory when checking unknown SIM option sent by EAP-SIM supplicant. An attacker could possibly use this issue to cause a denial of service on the server. This issue only affected Ubuntu 16.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
- systems | linux[9], ubuntu[10]
- advisories | CVE-2019-17185[11], CVE-2022-41860[12], CVE-2022-41861[13]
- SHA-256 |
a7bd71afc6329ccb72ca453d36d94ee8283b47169870a31f511a50416559d346 - Download[14] | Favorite[15] | View[16]
Change Mirror[17] Download[18]
=========================================================================
Ubuntu Security Notice USN-5785-1
January 04, 2023
freeradius vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 ESM
Summary:
Several security issues were fixed in FreeRADIUS.
Software Description:
- freeradius: high-performance and highly configurable RADIUS server
Details:
It was discovered that FreeRADIUS incorrectly handled multiple EAP-pwd
handshakes. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-17185)
Shane Guan discovered that FreeRADIUS incorrectly handled memory when
checking unknown SIM option sent by EAP-SIM supplicant. An attacker could
possibly use this issue to cause a denial of service on the server. This
issue only affected Ubuntu 16.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04
LTS. (CVE-2022-41860)
It was discovered that FreeRADIUS incorrectly handled memory when
processing certain abinary attributes. An attacker could possibly use this
issue to cause a denial of service on the server. (CVE-2022-41861)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS:
freeradius 3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.1
Ubuntu 20.04 LTS:
freeradius 3.0.20+dfsg-3ubuntu0.2
Ubuntu 18.04 LTS:
freeradius 3.0.16+dfsg-1ubuntu3.2
Ubuntu 16.04 ESM:
freeradius 2.2.8+dfsg-0.1ubuntu0.1+esm1
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-5785-1
CVE-2019-17185, CVE-2022-41860, CVE-2022-41861
Package Information:
https://launchpad.net/ubuntu/+source/freeradius/3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.1
https://launchpad.net/ubuntu/+source/freeradius/3.0.20+dfsg-3ubuntu0.2
https://launchpad.net/ubuntu/+source/freeradius/3.0.16+dfsg-1ubuntu3.2
File Tags
- ActiveX[23] (932)
- Advisory[24] (79,787)
- Arbitrary[25] (15,706)
- BBS[26] (2,859)
- Bypass[27] (1,623)
- CGI[28] (1,018)
- Code Execution[29] (6,944)
- Conference[30] (674)
- Cracker[31] (840)
- CSRF[32] (3,290)
- DoS[33] (22,609)
- Encryption[34] (2,352)
- Exploit[35] (50,392)
- File Inclusion[36] (4,166)
- File Upload[37] (946)
- Firewall[38] (821)
- Info Disclosure[39] (2,663)
- Intrusion Detection[40] (867)
- Java[41] (2,902)
- JavaScript[42] (821)
- Kernel[43] (6,293)
- Local[44] (14,202)
- Magazine[45] (586)
- Overflow[46] (12,427)
- Perl[47] (1,418)
- PHP[48] (5,093)
- Proof of Concept[49] (2,293)
- Protocol[50] (3,436)
- Python[51] (1,468)
- Remote[52] (30,061)
- Root[53] (3,505)
- Ruby[54] (595)
- Scanner[55] (1,632)
- Security Tool[56] (7,785)
- Shell[57] (3,106)
- Shellcode[58] (1,206)
- Sniffer[59] (886)
- Spoof[60] (2,171)
- SQL Injection[61] (16,110)
- TCP[62] (2,380)
- Trojan[63] (686)
- UDP[64] (877)
- Virus[65] (662)
- Vulnerability[66] (31,157)
- Web[67] (9,370)
- Whitepaper[68] (3,730)
- x86[69] (946)
- XSS[70] (17,498)
- Other[71]
File Archives
- January 2023[72]
- December 2022[73]
- November 2022[74]
- October 2022[75]
- September 2022[76]
- August 2022[77]
- July 2022[78]
- June 2022[79]
- May 2022[80]
- April 2022[81]
- March 2022[82]
- February 2022[83]
- Older[84]
Systems
- AIX[85] (426)
- Apple[86] (1,935)
- BSD[87] (370)
- CentOS[88] (55)
- Cisco[89] (1,917)
- Debian[90] (6,643)
- Fedora[91] (1,690)
- FreeBSD[92] (1,242)
- Gentoo[93] (4,279)
- HPUX[94] (878)
- iOS[95] (333)
- iPhone[96] (108)
- IRIX[97] (220)
- Juniper[98] (67)
- Linux[99] (44,341)
- Mac OS X[100] (684)
- Mandriva[101] (3,105)
- NetBSD[102] (255)
- OpenBSD[103] (479)
- RedHat[104] (12,474)
- Slackware[105] (941)
- Solaris[106] (1,607)
- SUSE[107] (1,444)
- Ubuntu[108] (8,202)
- UNIX[109] (9,165)
- UnixWare[110] (185)
- Windows[111] (6,511)
- Other[112]
Read more https://packetstormsecurity.com/files/170370/USN-5785-1.txt


