USN-3369-1: FreeRADIUS vulnerabilities

USN-3369-1: FreeRADIUS vulnerabilities

Ubuntu Security Notice USN-3369-1

27th July, 2017

freeradius vulnerabilities

A security issue affects these releases of Ubuntu and its
derivatives:

  • Ubuntu 17.04
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS

Summary

Several security issues were fixed in FreeRADIUS.

Software description

  • freeradius
    – high-performance and highly configurable RADIUS server

Details

Guido Vranken discovered that FreeRADIUS incorrectly handled memory when
decoding packets. A remote attacker could use this issue to cause
FreeRADIUS to crash or hang, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 17.04:
freeradius

3.0.12+dfsg-4ubuntu1.2
Ubuntu 16.04 LTS:
freeradius

2.2.8+dfsg-0.1ubuntu0.1
Ubuntu 14.04 LTS:
freeradius

2.1.12+dfsg-1.2ubuntu8.2

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

CVE-2017-10978,

CVE-2017-10979,

CVE-2017-10980,

CVE-2017-10981,

CVE-2017-10982,

CVE-2017-10983,

CVE-2017-10984,

CVE-2017-10985,

CVE-2017-10986,

CVE-2017-10987

Source: USN-3369-1: FreeRADIUS vulnerabilities

About KENNETH 19694 Articles
지락문화예술공작단

Be the first to comment

Leave a Reply

Your email address will not be published.


*


이 사이트는 스팸을 줄이는 아키스밋을 사용합니다. 댓글이 어떻게 처리되는지 알아보십시오.