Re: CVE-2012-3547 vulnerability in net-dialup/freeradius

Agostino Sarubbo <[email protected]> Tue, 11 Sep 2012 21:20:28 +0200
Newsgroups gmane.linux.gentoo.security
Message-ID <1567763.A67pTbQOvU@devil>
--nextPart4714007.DYC4Eh0grk
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

On Tuesday 11 September 2012 16:56:09 =C5=A0tefan Sakal=C3=ADk wrote:
> Hi,
> we are affected by this vulnerability so I have created a patch for
> freeradius-2.1.11-r1 (in attachment) inspired by upstream patch in gi=
t
> at git://git.freeradius.org/freeradius-server.git , commit 684dce7da5=
fd078.
> Please review this patch and include it in gentoo since it's a rather=

> severe vulnerability.
Please use our bugzilla for this stuff. File a new bug and proceed with=
 your=20
request.

Anyway, I see, from this advisory[1], that is enough bump the latest ve=
rsion.

[1]: https://secunia.com/advisories/50484/
--=20
Agostino Sarubbo / ago -at- gentoo.org
Gentoo/AMD64 Arch Security Liaison
GPG: 0x7CD2DC5D
--nextPart4714007.DYC4Eh0grk
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)

iQEcBAABCAAGBQJQT478AAoJEOTDgjZ80txdeFcIAK0mRn4Op3sMG0q9pu1O9u/U
dliG21w5tq/U700ziN4EhjYc2NvLg9ekF39y3juMw+wuORB1EPsUl17P5L2WO5mf
RQtDK0ttLcg4r5hzdcfheXuV3huIWfRHPxgRqht43qsSpvhbisrveh7dT/v6r5EZ
GjmhvudXdOA/SK+GMKPqxH65aC7S1FNjAfAt+USkCP7pS391zAdl3uh4ebsw5m9D
qcfvqumorth8h3FCRQSzJLJhToFFL06mYQ+0awA0FLGm9JkaXU8Vwp2d4jnPlpyx
ieEhauCmI0etIoEM6tWjTTp4PxGFbVNQ2tDgGfKdizSkqCoJjCvROaDMExvt0Mk=
=VGm+
-----END PGP SIGNATURE-----

--nextPart4714007.DYC4Eh0grk--