freeradius-2.2.6-7.AXS4

エラータID: AXSA:2017-1744:01

Release date: 
Tuesday, July 18, 2017 - 13:07
Subject: 
freeradius-2.2.6-7.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

The FreeRADIUS Server Project is a high performance and highly configurable
GPL'd free RADIUS server. The server is similar in some respects to
Livingston's 2.0 server. While FreeRADIUS started as a variant of the
Cistron RADIUS server, they don't share a lot in common any more. It now has
many more features than Cistron or Livingston, and is much more configurable.

FreeRADIUS is an Internet authentication daemon, which implements the RADIUS
protocol, as defined in RFC 2865 (and others). It allows Network Access
Servers (NAS boxes) to perform authentication for dial-up users. There are
also RADIUS clients available for Web servers, firewalls, Unix logins, and
more. Using RADIUS allows authentication and authorization for a network to
be centralized, and minimizes the amount of re-configuration which has to be
done when adding or deleting new users.

Security issues fixed with this release:

CVE-2017-10978
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before
3.0.15 allows "Read / write overflow in make_secret()" and a denial of
service.
CVE-2017-10979
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write
overflow in rad_coalesce()" - this allows remote attackers to cause a
denial of service (daemon crash) or possibly execute arbitrary code.
CVE-2017-10980
An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP -
Memory leak in decode_tlv()" and a denial of service.
CVE-2017-10981
An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP -
Memory leak in fr_dhcp_decode()" and a denial of service.
CVE-2017-10982
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP -
Buffer over-read in fr_dhcp_decode_options()" and a denial of service.
CVE-2017-10983
An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before
3.0.15 allows "DHCP - Read overflow when decoding option 63" and a
denial of service.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. freeradius-2.2.6-7.AXS4.src.rpm
    MD5: b8733df1a1cd61b74fd6b78982d1efcb
    SHA-256: ec04c3ce4e31b9d161d11b77bd6c9349df2f67cc066ef5cd87117c701294d64b
    Size: 2.76 MB

Asianux Server 4 for x86
  1. freeradius-2.2.6-7.AXS4.i686.rpm
    MD5: 726f3ccd14fc6a3958d3afd226bced41
    SHA-256: 319d0f03607c2eec9028536850061620a5ed091df8a0324c3c1daeda3316655e
    Size: 1.52 MB

Asianux Server 4 for x86_64
  1. freeradius-2.2.6-7.AXS4.x86_64.rpm
    MD5: a329d7eaf540acf3d78eb8de2af7392a
    SHA-256: e249cadc60b5b4dc5ddf2cce0c94e395ab633e6f9a6444c9a23189b76f3e133d
    Size: 1.52 MB