CVE-2006-1354: EAP-MSCHAPv2 vulnerability

Bug #164000 reported by William Grant
256
Affects Status Importance Assigned to Milestone
freeradius (Debian)
Fix Released
Unknown
freeradius (Fedora)
Fix Released
High
freeradius (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Undecided
William Grant

Bug Description

Binary package hint: freeradius

A validation issue exists with the EAP-MSCHAPv2 module in all versions from 1.0.0 (where the module first appeared) to 1.1.0. Insufficient input validation was being done in the EAP-MSCHAPv2 state machine. A malicious attacker could manipulate their EAP-MSCHAPv2 client state machine to potentially convince the server to bypass authentication checks. This bypassing could also result in the server crashing. We recommend that administrators upgrade immediately.

Only Dapper is unfixed, and I'll roll this in with the fix for bug #106006.

CVE References

Revision history for this message
In , Josh (josh-redhat-bugs) wrote :

FreeRADIUS authentication bypass

A bug in the EAP-MSCHAPv2 module could allow an attacker to
improperly authenticate as an aribitrary user.

http://www.freeradius.org/security.html

This issue also affects RHEL3

Revision history for this message
In , Josh (josh-redhat-bugs) wrote :

Created attachment 126403
Patch from upstream CVS

Revision history for this message
In , Red (red-redhat-bugs) wrote :

An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2006-0271.html

William Grant (wgrant)
Changed in freeradius:
status: New → Fix Released
assignee: nobody → fujitsu
status: New → Triaged
William Grant (wgrant)
Changed in freeradius:
status: Triaged → In Progress
Changed in freeradius:
status: Unknown → Fix Released
Kees Cook (kees)
Changed in freeradius:
status: In Progress → Fix Committed
William Grant (wgrant)
Changed in freeradius:
status: Fix Committed → Fix Released
Changed in freeradius:
status: Unknown → Fix Released
Changed in freeradius (Fedora):
importance: Unknown → High
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.