LWN.net Logo

radsecproxy: SSL certificate verification weakness

Package(s):radsecproxy CVE #(s):CVE-2012-4523 CVE-2012-4566
Created:November 12, 2012 Updated:November 14, 2012
Description: From the Debian advisory:

Ralf Paffrath reported that Radsecproxy, a RADIUS protocol proxy, mixed up pre- and post-handshake verification of clients. This vulnerability may wrongly accept clients without checking their certificate chain under certain configurations.

Raphael Geissert spotted that the fix for CVE-2012-4523 was incomplete, giving origin to CVE-2012-4566.

Alerts:
Debian DSA-2573-1 2012-11-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds