Upstream information

CVE-2008-4474 at MITRE

Description

freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) truncate_radacct.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 7.2
Vector AV:L/AC:L/Au:N/C:C/I:C/A:C
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entry: 433762 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Server 11 SP1
  • freeradius-server >= 2.1.1-7.7.19.77
  • freeradius-server-dialupadmin >= 2.1.1-7.7.19.77
  • freeradius-server-doc >= 2.1.1-7.7.19.77
  • freeradius-server-libs >= 2.1.1-7.7.19.77
  • freeradius-server-utils >= 2.1.1-7.7.19.77
Patchnames:
SUSE Linux Enterprise Server 11 SP1 GA freeradius-server
SUSE Linux Enterprise Server 11 SP2
  • freeradius-server >= 2.1.1-7.10.1
  • freeradius-server-dialupadmin >= 2.1.1-7.7.19.77
  • freeradius-server-doc >= 2.1.1-7.7.19.77
  • freeradius-server-libs >= 2.1.1-7.7.19.77
  • freeradius-server-utils >= 2.1.1-7.7.19.77
Patchnames:
SUSE Linux Enterprise Server 11 SP2 GA freeradius-server
SUSE Linux Enterprise Server 11 SP3
  • freeradius-server >= 2.1.1-7.16.7
  • freeradius-server-dialupadmin >= 2.1.1-7.16.7
  • freeradius-server-doc >= 2.1.1-7.16.7
  • freeradius-server-libs >= 2.1.1-7.16.7
  • freeradius-server-utils >= 2.1.1-7.16.7
Patchnames:
SUSE Linux Enterprise Server 11 SP3 GA freeradius-server
SUSE Linux Enterprise Server 11 SP4
  • freeradius-server >= 2.1.1-7.18.1
  • freeradius-server-dialupadmin >= 2.1.1-7.18.1
  • freeradius-server-doc >= 2.1.1-7.18.1
  • freeradius-server-libs >= 2.1.1-7.18.1
  • freeradius-server-utils >= 2.1.1-7.18.1
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA freeradius-server
SUSE Linux Enterprise Software Development Kit 11 SP4
  • freeradius-server-devel >= 2.1.1-7.18.1
  • freeradius-server-libs >= 2.1.1-7.18.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA freeradius-server-devel
openSUSE 11.0
  • freeradius-server-debuginfo >= 2.0.5-8.3
  • freeradius-server-debugsource >= 2.0.5-8.3
openSUSE 11.0
  • freeradius-server >= 2.0.5-8.3
  • freeradius-server-devel >= 2.0.5-8.3
  • freeradius-server-dialupadmin >= 2.0.5-8.3
  • freeradius-server-doc >= 2.0.5-8.3
  • freeradius-server-libs >= 2.0.5-8.3
  • freeradius-server-utils >= 2.0.5-8.3