漏洞信息详情
FreeRADIUS 授权问题漏洞
漏洞简介
FreeRADIUS是FreeRADIUS Server项目的一套实现了RADIUS协议的软件。该软件主要用于账户认证管理、记账管理和上网账户管理等。
FreeRADIUS 3.0.19之前版本中存在授权问题漏洞。该漏洞源于网络系统或产品中缺少身份验证措施或身份验证强度不足。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://freeradius.org/security/
参考网址
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1131
来源:REDHAT
链接:https://access.redhat.com/errata/RHSA-2019:1142
来源:www.kb.cert.org
链接:https://www.kb.cert.org/vuls/id/871675/
来源:papers.mathyvanhoef.com
链接:https://papers.mathyvanhoef.com/dragonblood.pdf
来源:freeradius.org
链接:https://freeradius.org/security/
来源:freeradius.org
链接:https://freeradius.org/release_notes/?br=3.0.x&re=3.0.19
来源:bugzilla.redhat.com
链接:https://bugzilla.redhat.com/show_bug.cgi?id=1695783
来源:UBUNTU
链接:https://usn.ubuntu.com/3954-1/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00014.html
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00032.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191086-1.html
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1131
来源:access.redhat.com
链接:https://access.redhat.com/errata/RHSA-2019:1142
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191039-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191181-1.html
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-11234
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80762
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79686
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80462
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80594
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152619/Ubuntu-Security-Notice-USN-3954-1.html
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79898
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152778/Red-Hat-Security-Advisory-2019-1131-01.html
受影响实体
暂无
补丁
- FreeRADIUS 授权问题漏洞的修复措施<!--2019-4-22-->
还没有评论,来说两句吧...