Oval Definition:oval:com.redhat.rhsa:def:20050524
Revision Date:2005-06-23Version:502
Title:RHSA-2005:524: freeradius security update (Moderate)
Description:FreeRADIUS is a high-performance and highly configurable free RADIUS server designed to allow centralized authentication and authorization for a network.

A buffer overflow bug was found in the way FreeRADIUS escapes data in an SQL query. An attacker may be able to crash FreeRADIUS if they cause FreeRADIUS to escape a string containing three or less characters. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1454 to this issue.

Additionally a bug was found in the way FreeRADIUS escapes SQL data. It is possible that an authenticated user could execute arbitrary SQL queries by sending a specially crafted request to FreeRADIUS. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1455 to this issue.

Users of FreeRADIUS should update to these erratum packages, which contain backported patches and are not vulnerable to these issues.
Family:unixClass:patch
Status:Reference(s):CVE-2005-1454
CVE-2005-1455
RHSA-2005:524-01
Platform(s):Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 3 is installed
  • AND
  • freeradius-mysql is earlier than 0:1.0.1-1.1.RHEL3
  • AND freeradius-mysql is signed with Red Hat master key
  • freeradius-postgresql is earlier than 0:1.0.1-1.1.RHEL3
  • AND freeradius-postgresql is signed with Red Hat master key
  • freeradius-unixODBC is earlier than 0:1.0.1-1.1.RHEL3
  • AND freeradius-unixODBC is signed with Red Hat master key
  • freeradius is earlier than 0:1.0.1-1.1.RHEL3
  • AND freeradius is signed with Red Hat master key
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND
  • freeradius-mysql is earlier than 0:1.0.1-3.RHEL4
  • AND freeradius-mysql is signed with Red Hat master key
  • freeradius-postgresql is earlier than 0:1.0.1-3.RHEL4
  • AND freeradius-postgresql is signed with Red Hat master key
  • freeradius-unixODBC is earlier than 0:1.0.1-3.RHEL4
  • AND freeradius-unixODBC is signed with Red Hat master key
  • freeradius is earlier than 0:1.0.1-3.RHEL4
  • AND freeradius is signed with Red Hat master key
  • BACK