[ubuntu/focal-security] freeradius 3.0.20+dfsg-3ubuntu0.4 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Oct 3 11:56:17 UTC 2024


freeradius (3.0.20+dfsg-3ubuntu0.4) focal-security; urgency=medium

  * SECURITY UPDATE: forgery attack via MD5 collision (Blast-RADIUS)
    - debian/patches/CVE-2024-3596-*.patch: backport changes to require
      Message-Authenticator in all Access-* packets.
    - debian/tests/rlm_python3-data/ubuntu_example.py.mods-config: adjust
      offsets to handle Message-Authenticator.
    - CVE-2024-3596

Date: 2024-10-02 14:18:13.811383+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/freeradius/3.0.20+dfsg-3ubuntu0.4
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list