• [SECURITY] [DSA 2573-1] radsecproxy security update

    From Luciano Bello@1:229/2 to All on Sat Nov 10 23:00:02 2012
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-2573-1 [email protected] http://www.debian.org/security/ Luciano Bello November 10, 2012 http://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : radsecproxy
    Vulnerability : SSL certificate verification weakness
    Problem type : remote
    Debian-specific: no
    CVE ID : CVE-2012-4523 CVE-2012-4566

    Ralf Paffrath reported that Radsecproxy, a RADIUS protocol proxy, mixed up
    pre- and post-handshake verification of clients. This vulnerability may
    wrongly accept clients without checking their certificate chain under
    certain configurations.

    Raphael Geissert spotted that the fix for CVE-2012-4523 was incomplete,
    giving origin to CVE-2012-4566. Both vulnerabilities are fixed with this update.

    Notice that this fix may make Radsecproxy reject some clients that are currently (erroneously) being accepted.

    For the stable distribution (squeeze), these problems have been fixed in version 1.4-1+squeeze1.

    For the testing distribution (wheezy), these problems have been fixed in version 1.6.2-1.

    For the unstable distribution (sid), these problems have been fixed in
    version 1.6.2-1.

    We recommend that you upgrade your radsecproxy packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: http://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.4.11 (GNU/Linux)

    iEYEARECAAYFAlCeylIACgkQQWTRs4lLtHkHaACcDHUTL37Y/8wTylt4xFSkwJVJ BI0AoIVkG7fkhBYWb7VEAIDSK5kjRHqJ
    =N4xn
    -----END PGP SIGNATURE-----


    --
    To UNSUBSCRIBE, email to [email protected]
    with a subject of "unsubscribe". Trouble? Contact [email protected] Archive: http://lists.debian.org/[email protected]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)