Remote Authentication Dial-In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA or Triple A) management for users who connect and use a network service.
Security Fix(es):
In freeradius, the EAP-PWD function computepasswordelement() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.(CVE-2022-41859)
{
"severity": "High"
}{
"x86_64": [
"freeradius-help-3.0.15-27.oe1.x86_64.rpm",
"freeradius-mysql-3.0.15-27.oe1.x86_64.rpm",
"freeradius-sqlite-3.0.15-27.oe1.x86_64.rpm",
"freeradius-debuginfo-3.0.15-27.oe1.x86_64.rpm",
"python2-freeradius-3.0.15-27.oe1.x86_64.rpm",
"freeradius-ldap-3.0.15-27.oe1.x86_64.rpm",
"freeradius-krb5-3.0.15-27.oe1.x86_64.rpm",
"freeradius-3.0.15-27.oe1.x86_64.rpm",
"freeradius-debugsource-3.0.15-27.oe1.x86_64.rpm",
"freeradius-devel-3.0.15-27.oe1.x86_64.rpm",
"freeradius-utils-3.0.15-27.oe1.x86_64.rpm",
"freeradius-postgresql-3.0.15-27.oe1.x86_64.rpm",
"freeradius-perl-3.0.15-27.oe1.x86_64.rpm"
],
"src": [
"freeradius-3.0.15-27.oe1.src.rpm"
],
"aarch64": [
"freeradius-help-3.0.15-27.oe1.aarch64.rpm",
"freeradius-postgresql-3.0.15-27.oe1.aarch64.rpm",
"freeradius-mysql-3.0.15-27.oe1.aarch64.rpm",
"freeradius-debuginfo-3.0.15-27.oe1.aarch64.rpm",
"freeradius-3.0.15-27.oe1.aarch64.rpm",
"freeradius-utils-3.0.15-27.oe1.aarch64.rpm",
"freeradius-devel-3.0.15-27.oe1.aarch64.rpm",
"freeradius-perl-3.0.15-27.oe1.aarch64.rpm",
"python2-freeradius-3.0.15-27.oe1.aarch64.rpm",
"freeradius-ldap-3.0.15-27.oe1.aarch64.rpm",
"freeradius-debugsource-3.0.15-27.oe1.aarch64.rpm",
"freeradius-krb5-3.0.15-27.oe1.aarch64.rpm",
"freeradius-sqlite-3.0.15-27.oe1.aarch64.rpm"
]
}