Updated radiusd-cistron packages are available
| Advisory: | RHSA-2002:030-08 |
|---|---|
| Type: | Security Advisory |
| Severity: | N/A |
| Issued on: | 2002-02-20 |
| Last updated on: | 2002-03-04 |
| Affected Products: | Powertools 7.0 Powertools 7.1 |
| CVEs (cve.mitre.org): |
CVE-2001-1376 CVE-2001-1377 |
Details
Updated radiusd-cistron packages, which fix various security issues, are now
available.
The radiusd-cistron package contains a server daemon for the Remote
Authentication Dial-In User Server (RADIUS) client/server security
protocol. Various vulnerabilities have been found in Cistron
RADIUS as well as other RADIUS servers and clients.
In versions of Cistron RADIUS 1.6.5 and earlier, malformed packets could be
used to gain additional privileges.
All users of Cistron RADIUS are advised to upgrade to version 1.6.6, which
is not vulnerable to these issues.
Pay special attention to the installation instructions in the Solution
section as they vary significantly from the usual update method.
Solution
relevant to your system have been applied.
This update is currently not available through Red Hat Network.
Due to a bug in previously released versions, the original package must be
removed, and the new package must be installed to apply this update (as root):
# /sbin/service radiusd stop
# /sbin/chkconfig --del radiusd
# rpm -e --noscripts radiusd-cistron
# rpm -ivh radiusd-cistron-1.6.6-2.[arch].rpm
where [arch] is the architecture.
Updated packages
| Powertools 7.0 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/SRPMS/radiusd-cistron-1.6.6-2.src.rpm Missing file |
MD5: 398e46f80c48654b26a2c484e264b485 |
| Alpha: | |
| ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/alpha/radiusd-cistron-1.6.6-2.alpha.rpm Missing file |
MD5: 080c782aeb81f4a0e4dda4e31efbe660 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/i386/radiusd-cistron-1.6.6-2.i386.rpm Missing file |
MD5: b5c937f5e48d4d3484b64e20f8785b4a |
| Powertools 7.1 | |
| SRPMS: | |
| ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/SRPMS/radiusd-cistron-1.6.6-2.src.rpm Missing file |
MD5: 398e46f80c48654b26a2c484e264b485 |
| Alpha: | |
| ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/alpha/radiusd-cistron-1.6.6-2.alpha.rpm Missing file |
MD5: 080c782aeb81f4a0e4dda4e31efbe660 |
| IA-32: | |
| ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/i386/radiusd-cistron-1.6.6-2.i386.rpm Missing file |
MD5: b5c937f5e48d4d3484b64e20f8785b4a |
References
https://www.redhat.com/security/data/cve/CVE-2001-1377.html
http://www.kb.cert.org/vuls/id/589523
http://www.kb.cert.org/vuls/id/936683
Keywords
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package
The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/