|
|
| |
|
| |
radsecproxy: SSL certificate verification weakness
| Package(s): | radsecproxy |
CVE #(s): | CVE-2012-4523
CVE-2012-4566
|
| Created: | November 12, 2012 |
Updated: | November 14, 2012 |
| Description: |
From the Debian advisory:
Ralf Paffrath reported that Radsecproxy, a RADIUS protocol proxy, mixed up
pre- and post-handshake verification of clients. This vulnerability may
wrongly accept clients without checking their certificate chain under
certain configurations.
Raphael Geissert spotted that the fix for CVE-2012-4523 was incomplete,
giving origin to CVE-2012-4566. |
| Alerts: |
|
( Log in to post comments)
|
|
|