Vulnerability   
Search   
    Search 219043 CVE descriptions
and 99761 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-3547
Description:Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.
Test IDs: 1.3.6.1.4.1.25623.1.0.72175   1.3.6.1.4.1.25623.1.0.72199   1.3.6.1.4.1.25623.1.0.72447   1.3.6.1.4.1.25623.1.0.72448   1.3.6.1.4.1.25623.1.0.72433   1.3.6.1.4.1.25623.1.0.72434   1.3.6.1.4.1.25623.1.0.72467   1.3.6.1.4.1.25623.1.0.123806   1.3.6.1.4.1.25623.1.0.123750   1.3.6.1.4.1.25623.1.0.123809   1.3.6.1.4.1.25623.1.0.881509   1.3.6.1.4.1.25623.1.0.850337   1.3.6.1.4.1.25623.1.0.881510   1.3.6.1.4.1.25623.1.0.831738   1.3.6.1.4.1.25623.1.0.870841   1.3.6.1.4.1.25623.1.0.120330   1.3.6.1.4.1.25623.1.0.870840   1.3.6.1.4.1.25623.1.0.864800   1.3.6.1.4.1.25623.1.0.841161   1.3.6.1.4.1.25623.1.0.864788  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-3547
http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html
BugTraq ID: 55483
http://www.securityfocus.com/bid/55483
Bugtraq: 20120910 [PRE-SA-2012-06] FreeRADIUS: Stack Overflow in TLS-based EAP Methods (Google Search)
http://archives.neohapsis.com/archives/bugtraq/2012-09/0043.html
Debian Security Information: DSA-2546 (Google Search)
http://www.debian.org/security/2012/dsa-2546
http://lists.fedoraproject.org/pipermail/package-announce/2012-October/090171.html
http://www.mandriva.com/security/advisories?name=MDVSA-2012:159
http://www.pre-cert.de/advisories/PRE-SA-2012-06.txt
http://www.openwall.com/lists/oss-security/2012/09/10/2
http://osvdb.org/85325
RedHat Security Advisories: RHSA-2012:1326
http://rhn.redhat.com/errata/RHSA-2012-1326.html
RedHat Security Advisories: RHSA-2012:1327
http://rhn.redhat.com/errata/RHSA-2012-1327.html
http://www.securitytracker.com/id?1027509
http://secunia.com/advisories/50484
http://secunia.com/advisories/50584
http://secunia.com/advisories/50637
http://secunia.com/advisories/50770
SuSE Security Announcement: openSUSE-SU-2012:1200 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00023.html
http://www.ubuntu.com/usn/USN-1585-1
XForce ISS Database: freeradius-cbtlsverify-bo(78408)
https://exchange.xforce.ibmcloud.com/vulnerabilities/78408




© 1998-2021 E-Soft Inc. All rights reserved.