UBUNTU-CVE-2017-9148
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-9148
UBUNTU-CVE-2017-9148
Summary:
Details: The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.
References: https://ubuntu.com/security/CVE-2017-9148, http://www.openwall.com/lists/oss-security/2017/05/29/1, http://freeradius.org/security.html#session-resumption-2017, http://freeradius.org/security.html, http://seclists.org/oss-sec/2017/q2/342, https://ubuntu.com/security/notices/USN-3316-1, https://www.cve.org/CVERecord?id=CVE-2017-9148
Affected packages
Package
Name: freeradius
Purl: pkg:deb/ubuntu/[email protected]+dfsg-1.2ubuntu8.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
