|
|
| |
|
| |
freeradius2: authentication bypass
| Package(s): | freeradius2 |
CVE #(s): | CVE-2011-4966
|
| Created: | January 17, 2013 |
Updated: | February 7, 2013 |
| Description: |
From the Red Hat advisory:
It was found that the "unix" module ignored the password expiration
setting in "/etc/shadow". If FreeRADIUS was configured to use this module
for user authentication, this flaw could allow users with an expired
password to successfully authenticate, even though their access should have
been denied. (CVE-2011-4966)
|
| Alerts: |
|
( Log in to post comments)
|
|
|