Upstream information
Description
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 160249 SUSE Security Advisories:- SUSE-SA:2006:019, published Tue, 28 Mar 2006 11:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| Open Enterprise Server |
| core9.s390 core9.ppc sles9-nlpos.x86 core9.ia64 YOU Patch Nr: 10924 |
| SUSE LINUX 10.0 |
| |
| SUSE LINUX 9.1 for IA32 SUSE LINUX 9.1 for x86-64 |
| |
| SUSE LINUX 9.2 |
| |
| SUSE LINUX 9.3 |
|
