Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.56477
Category:SuSE Local Security Checks
Title:SuSE Security Advisory SUSE-SA:2006:019 (freeradius)
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory SUSE-SA:2006:019.

Insufficient input validation was being done in the EAP-MSCHAPv2
state machine of the FreeRADIUS authentication server.

A malicious attacker could manipulate their EAP-MSCHAPv2 client state
machine to potentially convince the server to bypass authentication
checks. This bypassing could also result in the server crashing.

This is tracked by the Mitre CVE ID CVE-2006-1354.

Solution:
Update your system with the packages as indicated in
the referenced security advisory.

http://www.securityspace.com/smysecure/catid.html?in=SUSE-SA:2006:019

Risk factor : High

CVSS Score:
7.5

Cross-Ref: BugTraq ID: 17171
Common Vulnerability Exposure (CVE) ID: CVE-2006-1354
http://www.securityfocus.com/bid/17171
Debian Security Information: DSA-1089 (Google Search)
http://www.debian.org/security/2006/dsa-1089
http://www.gentoo.org/security/en/glsa/glsa-200604-03.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:060
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10156
RedHat Security Advisories: RHSA-2006:0271
http://rhn.redhat.com/errata/RHSA-2006-0271.html
http://securitytracker.com/id?1015795
http://secunia.com/advisories/19300
http://secunia.com/advisories/19405
http://secunia.com/advisories/19518
http://secunia.com/advisories/19527
http://secunia.com/advisories/19811
http://secunia.com/advisories/20461
SGI Security Advisory: 20060404-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.asc
SuSE Security Announcement: SUSE-SA:2006:019 (Google Search)
http://lists.suse.de/archive/suse-security-announce/2006-Mar/0009.html
http://www.trustix.org/errata/2006/0020
http://www.vupen.com/english/advisories/2006/1016
XForce ISS Database: freeradius-eap-mschapv2-auth-bypass(25352)
https://exchange.xforce.ibmcloud.com/vulnerabilities/25352
CopyrightCopyright (c) 2006 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.