GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Tue Jan 26, 2021 5:26 am Post subject: [ GLSA 202101-27 ] FreeRADIUS |
|
|
Gentoo Linux Security Advisory
Title: FreeRADIUS: Root privilege escalation (GLSA 202101-27)
Severity: normal
Exploitable: local
Date: 2021-01-26
Bug(s): #630910
ID: 202101-27
Synopsis
Multiple vulnerabilities were discovered in Gentoo's systemd unit
for FreeRADIUS which could lead to root privilege escalation.
Background
FreeRADIUS is a modular, high performance free RADIUS suite.
Affected Packages
Package: net-dialup/freeradius
Vulnerable: < 3.0.20-r1
Unaffected: >= 3.0.20-r1
Architectures: All supported architectures
Description
It was discovered that Gentoo’s FreeRADIUS systemd unit set
permissions on an unsafe directory on start.
Impact
A local attacker could escalate privileges.
Workaround
There is no known workaround at this time.
Resolution
All FreeRADIUS users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-dialup/freeradius-3.0.20-r1"
|
|
|