Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 4 Aug 2015 10:41:52 +0530
From: Huzaifa Sidhpurwala <huzaifas@...hat.com>
To: oss-security@...ts.openwall.com,
        Mitre CVE assign department <cve-assign@...re.org>
Subject: Re: CVE Request: freeradius: the EAP-PWD module
 performs insufficient validation on packets received from an EAP peer

On 07/31/2015 12:04 PM, Huzaifa Sidhpurwala wrote:
> The FreeRADIUS project has reported a flaw that affects the EAP-PWD
> module of the freeradius package versions 3.0 up to 3.0.8. This module
> is not enabled by default, so administrators must have manually enabled
> it for their servers to be vulnerable.
> 
> Reference:
> http://freeradius.org/security.html#eap-pwd-2015
> 
> Can a CVE id be please assigned to this flaw?
> 
> 
Copying cve-assign this time to see if this gets picked up :)


-- 
Huzaifa Sidhpurwala / Red Hat Product Security Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.