vulnerability
CentOS Linux: CVE-2019-11235: Important: freeradius security update (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Apr 22, 2019 | May 17, 2019 | May 25, 2023 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Apr 22, 2019
Added
May 17, 2019
Modified
May 25, 2023
Description
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
Solutions
centos-upgrade-freeradiuscentos-upgrade-freeradius-debuginfocentos-upgrade-freeradius-debugsourcecentos-upgrade-freeradius-develcentos-upgrade-freeradius-doccentos-upgrade-freeradius-krb5centos-upgrade-freeradius-krb5-debuginfocentos-upgrade-freeradius-ldapcentos-upgrade-freeradius-ldap-debuginfocentos-upgrade-freeradius-mysqlcentos-upgrade-freeradius-mysql-debuginfocentos-upgrade-freeradius-perlcentos-upgrade-freeradius-perl-debuginfocentos-upgrade-freeradius-postgresqlcentos-upgrade-freeradius-postgresql-debuginfocentos-upgrade-freeradius-pythoncentos-upgrade-freeradius-restcentos-upgrade-freeradius-rest-debuginfocentos-upgrade-freeradius-sqlitecentos-upgrade-freeradius-sqlite-debuginfocentos-upgrade-freeradius-unixodbccentos-upgrade-freeradius-unixodbc-debuginfocentos-upgrade-freeradius-utilscentos-upgrade-freeradius-utils-debuginfo
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.