Skip to navigation

Security Advisory Updated radiusd-cistron packages are available

Advisory: RHSA-2002:030-08
Type: Security Advisory
Severity: N/A
Issued on: 2002-02-20
Last updated on: 2002-03-04
Affected Products: Powertools 7.0
Powertools 7.1
CVEs (cve.mitre.org): CVE-2001-1376
CVE-2001-1377

Details

Updated radiusd-cistron packages, which fix various security issues, are now
available.

The radiusd-cistron package contains a server daemon for the Remote
Authentication Dial-In User Server (RADIUS) client/server security
protocol. Various vulnerabilities have been found in Cistron
RADIUS as well as other RADIUS servers and clients.

In versions of Cistron RADIUS 1.6.5 and earlier, malformed packets could be
used to gain additional privileges.

All users of Cistron RADIUS are advised to upgrade to version 1.6.6, which
is not vulnerable to these issues.

Pay special attention to the installation instructions in the Solution
section as they vary significantly from the usual update method.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is currently not available through Red Hat Network.
Due to a bug in previously released versions, the original package must be
removed, and the new package must be installed to apply this update (as root):

# /sbin/service radiusd stop
# /sbin/chkconfig --del radiusd
# rpm -e --noscripts radiusd-cistron
# rpm -ivh radiusd-cistron-1.6.6-2.[arch].rpm

where [arch] is the architecture.

Updated packages

Powertools 7.0

SRPMS:
ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/SRPMS/radiusd-cistron-1.6.6-2.src.rpm
Missing file
    MD5: 398e46f80c48654b26a2c484e264b485
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/alpha/radiusd-cistron-1.6.6-2.alpha.rpm
Missing file
    MD5: 080c782aeb81f4a0e4dda4e31efbe660
 
IA-32:
ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/i386/radiusd-cistron-1.6.6-2.i386.rpm
Missing file
    MD5: b5c937f5e48d4d3484b64e20f8785b4a
 
Powertools 7.1

SRPMS:
ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/SRPMS/radiusd-cistron-1.6.6-2.src.rpm
Missing file
    MD5: 398e46f80c48654b26a2c484e264b485
 
Alpha:
ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/alpha/radiusd-cistron-1.6.6-2.alpha.rpm
Missing file
    MD5: 080c782aeb81f4a0e4dda4e31efbe660
 
IA-32:
ftp://updates.redhat.com/rhn/repository/NULL/radiusd-cistron/1.6.6-2/i386/radiusd-cistron-1.6.6-2.i386.rpm
Missing file
    MD5: b5c937f5e48d4d3484b64e20f8785b4a
 

References


Keywords

malformed, packet, radius, radiusd


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/