Re: CVE-2012-3547 vulnerability in net-dialup/freeradius
Agostino Sarubbo <[email protected]> Tue, 11 Sep 2012 21:20:28 +0200
| Newsgroups | gmane.linux.gentoo.security |
|---|---|
| Message-ID | <1567763.A67pTbQOvU@devil> |
--nextPart4714007.DYC4Eh0grk Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" On Tuesday 11 September 2012 16:56:09 =C5=A0tefan Sakal=C3=ADk wrote: > Hi, > we are affected by this vulnerability so I have created a patch for > freeradius-2.1.11-r1 (in attachment) inspired by upstream patch in gi= t > at git://git.freeradius.org/freeradius-server.git , commit 684dce7da5= fd078. > Please review this patch and include it in gentoo since it's a rather= > severe vulnerability. Please use our bugzilla for this stuff. File a new bug and proceed with= your=20 request. Anyway, I see, from this advisory[1], that is enough bump the latest ve= rsion. [1]: https://secunia.com/advisories/50484/ --=20 Agostino Sarubbo / ago -at- gentoo.org Gentoo/AMD64 Arch Security Liaison GPG: 0x7CD2DC5D --nextPart4714007.DYC4Eh0grk Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part. -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.19 (GNU/Linux) iQEcBAABCAAGBQJQT478AAoJEOTDgjZ80txdeFcIAK0mRn4Op3sMG0q9pu1O9u/U dliG21w5tq/U700ziN4EhjYc2NvLg9ekF39y3juMw+wuORB1EPsUl17P5L2WO5mf RQtDK0ttLcg4r5hzdcfheXuV3huIWfRHPxgRqht43qsSpvhbisrveh7dT/v6r5EZ GjmhvudXdOA/SK+GMKPqxH65aC7S1FNjAfAt+USkCP7pS391zAdl3uh4ebsw5m9D qcfvqumorth8h3FCRQSzJLJhToFFL06mYQ+0awA0FLGm9JkaXU8Vwp2d4jnPlpyx ieEhauCmI0etIoEM6tWjTTp4PxGFbVNQ2tDgGfKdizSkqCoJjCvROaDMExvt0Mk= =VGm+ -----END PGP SIGNATURE----- --nextPart4714007.DYC4Eh0grk--