what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2014-058

Mandriva Linux Security Advisory 2014-058
Posted Mar 14, 2014
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2014-058 - SSHA processing in freeradius before 2.2.3 runs into a stack-based buffer overflow in the freeradius rlm_pap module if the password source uses an unusually long hashed password.

tags | advisory, overflow
systems | linux, mandriva
advisories | CVE-2014-2015
SHA-256 | 4abd4790fbbfe3df3a6955b9c9a46d812e0b17d035f4299001798f8b1b631ef1

Mandriva Linux Security Advisory 2014-058

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2014:058
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : freeradius
Date : March 13, 2014
Affected: Business Server 1.0, Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

Updated freeradius package fixes security vulnerability:

SSHA processing in freeradius before 2.2.3 runs into a stack-based
buffer overflow in the freeradius rlm_pap module if the password
source uses an unusually long hashed password (CVE-2014-2015).
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2015
http://advisories.mageia.org/MGASA-2014-0088.html
_______________________________________________________________________

Updated Packages:

Mandriva Enterprise Server 5:
ad944c9074b82a96e5bca829cb9e53a6 mes5/i586/freeradius-2.1.0-3.2mdvmes5.2.i586.rpm
a99e3e6e10a0856e4d755d17653865a0 mes5/i586/freeradius-krb5-2.1.0-3.2mdvmes5.2.i586.rpm
322a9c4b628cf1e94263c060b6978fde mes5/i586/freeradius-ldap-2.1.0-3.2mdvmes5.2.i586.rpm
e554bcf6daa40436f85ad06b4bc4a81a mes5/i586/freeradius-mysql-2.1.0-3.2mdvmes5.2.i586.rpm
95588e3bdf6cf1f1711416c1966a5683 mes5/i586/freeradius-postgresql-2.1.0-3.2mdvmes5.2.i586.rpm
e998de66a546e5f1c325a1aae720ce8d mes5/i586/freeradius-unixODBC-2.1.0-3.2mdvmes5.2.i586.rpm
92cc08607f5a1db4b8181f3fa1f882ac mes5/i586/freeradius-web-2.1.0-3.2mdvmes5.2.i586.rpm
59efbacd16cd43b769194eebd86b9aa8 mes5/i586/libfreeradius1-2.1.0-3.2mdvmes5.2.i586.rpm
c22ae710c958e08cd230f90b4a8dd02d mes5/i586/libfreeradius-devel-2.1.0-3.2mdvmes5.2.i586.rpm
cc1524d78d985dcfe1cc52e0c4167c53 mes5/SRPMS/freeradius-2.1.0-3.2mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
56840a173c160cba06a7fb7c80ddb64f mes5/x86_64/freeradius-2.1.0-3.2mdvmes5.2.x86_64.rpm
0941ddc851295f4925de5f583da68475 mes5/x86_64/freeradius-krb5-2.1.0-3.2mdvmes5.2.x86_64.rpm
e4af5670c6cab9b67add4e70aed3b684 mes5/x86_64/freeradius-ldap-2.1.0-3.2mdvmes5.2.x86_64.rpm
25df0aba6eee4288d21ecda61c30b778 mes5/x86_64/freeradius-mysql-2.1.0-3.2mdvmes5.2.x86_64.rpm
b9ccf0bc86cdc0b3cd05bfa4fabacf2a mes5/x86_64/freeradius-postgresql-2.1.0-3.2mdvmes5.2.x86_64.rpm
7826a0387961c9d212be1532f2455664 mes5/x86_64/freeradius-unixODBC-2.1.0-3.2mdvmes5.2.x86_64.rpm
d20ac56207ef50426beaea46e1196c63 mes5/x86_64/freeradius-web-2.1.0-3.2mdvmes5.2.x86_64.rpm
1dad7dd1a4b40a99c21edc8598b7aeea mes5/x86_64/lib64freeradius1-2.1.0-3.2mdvmes5.2.x86_64.rpm
047d0222be6c58c6757fb63c4489e91e mes5/x86_64/lib64freeradius-devel-2.1.0-3.2mdvmes5.2.x86_64.rpm
cc1524d78d985dcfe1cc52e0c4167c53 mes5/SRPMS/freeradius-2.1.0-3.2mdvmes5.2.src.rpm

Mandriva Business Server 1/X86_64:
0057f36548b76ab4309513af32189a7a mbs1/x86_64/freeradius-2.1.12-9.2.mbs1.x86_64.rpm
bf926a73a78b4d71ed289882174faff0 mbs1/x86_64/freeradius-krb5-2.1.12-9.2.mbs1.x86_64.rpm
2a4d779f740e148179a2fa47f6b5d11a mbs1/x86_64/freeradius-ldap-2.1.12-9.2.mbs1.x86_64.rpm
6194d14adfb3a1be7098d6a80c68666c mbs1/x86_64/freeradius-mysql-2.1.12-9.2.mbs1.x86_64.rpm
aa9d2789f6ba9ef13ddcbd8f1401053b mbs1/x86_64/freeradius-postgresql-2.1.12-9.2.mbs1.x86_64.rpm
dced45a8d3116fda640cbf87a92045d9 mbs1/x86_64/freeradius-sqlite-2.1.12-9.2.mbs1.x86_64.rpm
6334b8e46550b4386845e965de3ddd6e mbs1/x86_64/freeradius-unixODBC-2.1.12-9.2.mbs1.x86_64.rpm
7c50512bed1debd14c01ac39a23664a0 mbs1/x86_64/freeradius-web-2.1.12-9.2.mbs1.x86_64.rpm
180924551409613494f9d37e171981bd mbs1/x86_64/lib64freeradius1-2.1.12-9.2.mbs1.x86_64.rpm
aa658a202d8dfa5d34126b548206afb9 mbs1/x86_64/lib64freeradius-devel-2.1.12-9.2.mbs1.x86_64.rpm
d71925925b1416ea729b8b85c7f0919c mbs1/SRPMS/freeradius-2.1.12-9.2.mbs1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFTIaX3mqjQ0CJFipgRAmfrAJ4+2PFcRArhKtgBxVFMRghXs3mB+QCfQNcE
KMIx0VlhDi+BX+cm21ZnGgQ=
=MBcL
-----END PGP SIGNATURE-----
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    25 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close