[ubuntu/jammy-security] freeradius 3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.3 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Thu Oct 3 11:56:16 UTC 2024


freeradius (3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.3) jammy-security; urgency=medium

  * SECURITY UPDATE: forgery attack via MD5 collision (Blast-RADIUS)
    - debian/patches/CVE-2024-3596-*.patch: backport changes to require
      Message-Authenticator in all Access-* packets.
    - CVE-2024-3596

freeradius (3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.2) jammy; urgency=medium

  * d/p/avoid-smbencrypt-segfault-with-openssl3-fixes.patch: load the
    OpenSSL legacy providers and use OpenSSL3 init for MD4/MD5
    (LP: #2042824).

Date: 2024-09-12 14:19:14.655696+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/freeradius/3.0.26~dfsg~git20220223.1.00ed0241fa-0ubuntu3.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the jammy-changes mailing list