freeradius-2.1.12-4.AXS4

エラータID: AXSA:2012-959:02

Release date: 
Monday, December 10, 2012 - 15:19
Subject: 
freeradius-2.1.12-4.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

The FreeRADIUS Server Project is a high performance and highly configurable GPL'd free RADIUS server. The server is similar in some respects to Livingston's 2.0 server. While FreeRADIUS started as a variant of the Cistron RADIUS server, they don't share a lot in common any more. It now has many more features than Cistron or Livingston, and is much more configurable.

FreeRADIUS is an Internet authentication daemon, which implements the RADIUS protocol, as defined in RFC 2865 (and others). It allows Network Access Servers (NAS boxes) to perform authentication for dial-up users. There are also RADIUS clients available for Web servers, firewalls, Unix logins, and more. Using RADIUS allows authentication and authorization for a network to be centralized, and minimizes the amount of re-configuration which has to be done when adding or deleting new users.

Security issues fixed with this release:

• CVE-2012-3547
Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. freeradius-2.1.12-4.AXS4.src.rpm
    MD5: 448e0c69bd33f549c2e9ae31d10c28e0
    SHA-256: 8aa943ec5771fe2b31d5b02ac82496527fc25a95d8b2c2f49306cfdfdcd4e55c
    Size: 2.62 MB

Asianux Server 4 for x86
  1. freeradius-2.1.12-4.AXS4.i686.rpm
    MD5: 8b7c65eee66047001be6faf1e22ca659
    SHA-256: fcfc0af1837a2b6640d7afcfd893cd54507e57d35bb736037b44a2959db3d04d
    Size: 1.39 MB

Asianux Server 4 for x86_64
  1. freeradius-2.1.12-4.AXS4.x86_64.rpm
    MD5: f79fa1235756b835051ae10b738c395d
    SHA-256: a407a73da20005ad7c6a89e081109504fd2f38331e14c81adf2aac04a0d0f2ec
    Size: 1.39 MB