Remote Authentication Dial-In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA or Triple A) management for users who connect and use a network service.
Security Fix(es):
In freeradius, the EAP-PWD function computepasswordelement() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.(CVE-2022-41859)
{ "severity": "High" }
{ "src": [ "freeradius-3.0.25-2.oe2203.src.rpm" ], "x86_64": [ "python3-freeradius-3.0.25-2.oe2203.x86_64.rpm", "freeradius-help-3.0.25-2.oe2203.x86_64.rpm", "freeradius-krb5-3.0.25-2.oe2203.x86_64.rpm", "freeradius-debugsource-3.0.25-2.oe2203.x86_64.rpm", "freeradius-perl-3.0.25-2.oe2203.x86_64.rpm", "freeradius-3.0.25-2.oe2203.x86_64.rpm", "freeradius-debuginfo-3.0.25-2.oe2203.x86_64.rpm", "freeradius-mysql-3.0.25-2.oe2203.x86_64.rpm", "freeradius-devel-3.0.25-2.oe2203.x86_64.rpm", "freeradius-sqlite-3.0.25-2.oe2203.x86_64.rpm", "freeradius-utils-3.0.25-2.oe2203.x86_64.rpm", "freeradius-ldap-3.0.25-2.oe2203.x86_64.rpm", "freeradius-postgresql-3.0.25-2.oe2203.x86_64.rpm" ], "aarch64": [ "freeradius-sqlite-3.0.25-2.oe2203.aarch64.rpm", "freeradius-debuginfo-3.0.25-2.oe2203.aarch64.rpm", "freeradius-postgresql-3.0.25-2.oe2203.aarch64.rpm", "python3-freeradius-3.0.25-2.oe2203.aarch64.rpm", "freeradius-debugsource-3.0.25-2.oe2203.aarch64.rpm", "freeradius-mysql-3.0.25-2.oe2203.aarch64.rpm", "freeradius-utils-3.0.25-2.oe2203.aarch64.rpm", "freeradius-krb5-3.0.25-2.oe2203.aarch64.rpm", "freeradius-perl-3.0.25-2.oe2203.aarch64.rpm", "freeradius-help-3.0.25-2.oe2203.aarch64.rpm", "freeradius-devel-3.0.25-2.oe2203.aarch64.rpm", "freeradius-ldap-3.0.25-2.oe2203.aarch64.rpm", "freeradius-3.0.25-2.oe2203.aarch64.rpm" ] }