LWN.net Logo

freeradius2: authentication bypass

Package(s):freeradius2 CVE #(s):CVE-2011-4966
Created:January 17, 2013 Updated:February 7, 2013
Description:

From the Red Hat advisory:

It was found that the "unix" module ignored the password expiration setting in "/etc/shadow". If FreeRADIUS was configured to use this module for user authentication, this flaw could allow users with an expired password to successfully authenticate, even though their access should have been denied. (CVE-2011-4966)

Alerts:
Scientific Linux SL-free-20130116 2013-01-16
CentOS CESA-2013:0134 2013-01-09
openSUSE openSUSE-SU-2013:0137-1 2013-01-23
openSUSE openSUSE-SU-2013:0191-1 2013-01-23
Mageia MGASA-2013-0026 2013-02-06
Mandriva MDVSA-2013:038 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds