Vulnerability CVE-2019-11234


Published: 2019-04-22

Description:
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.

Type:

CWE-287

(Improper Authentication)

Vendor: Redhat
Product: Enterprise linux 
Version: 7.0;
Vendor: Freeradius
Product: Freeradius 
Version:
3.0.8
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.18
3.0.17
3.0.16
3.0.15
2.2.10
2.2.0
2.1.9
2.1.8
2.1.7
2.1.6
2.1.4
2.1.3
2.1.2
2.1.12
2.1.11
2.1.10
2.1.1
2.1.0
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0
1.1.8
1.1.7
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
0.9.3
0.9.2
0.9.1
0.9.0
0.8.1
0.8
0.7.1
0.7
0.6
0.5
0.4
0.3
0.2
0.1
Vendor: Canonical
Product: Ubuntu linux 
Version:
19.04
18.10
18.04
Vendor: Fedoraproject
Product: Fedora 

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00014.html
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00032.html
https://access.redhat.com/errata/RHSA-2019:1131
https://access.redhat.com/errata/RHSA-2019:1142
https://bugzilla.redhat.com/show_bug.cgi?id=1695783
https://freeradius.org/release_notes/?br=3.0.x&re=3.0.19
https://freeradius.org/security/
https://papers.mathyvanhoef.com/dragonblood.pdf
https://usn.ubuntu.com/3954-1/
https://www.kb.cert.org/vuls/id/871675/

Related CVE
CVE-2019-10132
A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configuration parameter allows any user on the host to connect using virtlockd-admin-sock or virtlogd-admin-sock...
CVE-2019-8936
NTP through 4.2.8p12 has a NULL Pointer Dereference.
CVE-2019-7443
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. I...
CVE-2019-3844
It was discovered that a systemd service that uses DynamicUser property can get new privileges through the execution of SUID binaries, which would allow to create binaries owned by the service transient group with the setgid bit set. A local attacker...
CVE-2019-3843
It was discovered that a systemd service that uses DynamicUser property can create a SUID/SGID binary that would be allowed to run as the transient service UID/GID even after the service is terminated. A local attacker may use this flaw to access res...
CVE-2019-3900
An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest ...
CVE-2019-3882
A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of th...
CVE-2019-11235
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar is...

Copyright 2019, cxsecurity.com

 

Back to Top