Comment 0 for bug 164000

Revision history for this message
William Grant (wgrant) wrote :

Binary package hint: freeradius

A validation issue exists with the EAP-MSCHAPv2 module in all versions from 1.0.0 (where the module first appeared) to 1.1.0. Insufficient input validation was being done in the EAP-MSCHAPv2 state machine. A malicious attacker could manipulate their EAP-MSCHAPv2 client state machine to potentially convince the server to bypass authentication checks. This bypassing could also result in the server crashing. We recommend that administrators upgrade immediately.

Only Dapper is unfixed, and I'll roll this in with the fix for bug #106006.