|
|
Log in / Subscribe / Register

freeradius: authentication bypass

Package(s):freeradius CVE #(s):CVE-2011-2701
Created:April 2, 2012 Updated:April 4, 2012
Description: From the Mandriva advisory:

The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate.

Alerts:
Gentoo 201311-09 freeradius 2013-11-13
Mandriva MDVSA-2012:047 freeradius 2012-04-02

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds