Skip to content
Snippets Groups Projects
  1. May 23, 2018
    • Zoltan HERPAI's avatar
      freeradius2: bump to 2.2.10 · 1657a09a
      Zoltan HERPAI authored
       - Fix multiple security issues. See http://freeradius.org/security/fuzzer-2017.html
      
       Thanks to Guido Vranken for working with us to discover the issues and test the fixes.
       - FR-GV-207 Avoid zero-length malloc() in data2vp().
       - FR-GV-206 correct decoding of option 60.
       - FR-GV-205 check for "too long" WiMAX options.
       - FR-GV-204 free VP if decoding fails, so we don't leak memory.
       - FR-GV-203 fix memory leak when using decode_tlv().
       - FR-GV-202 check for "too long" attributes.
       - FR-GV-201 check input/output length in make_secret().
       - FR-AD-001 Use strncmp() instead of memcmp() for bounded data.
       - Disable in-memory TLS session caches due to OpenSSL API issues.
       - Allow issuer_cert to be empty.
       - Look for extensions using correct index.
       - Fix types.
       - Work around OpenSSL 1.0.2 problems, which cause failures in TLS-based EAP methods.
       - Revert RedHat contributed bug which removes run-time checks for OpenSSL consistency.
       - Allow OCSP responder URL to be later in the packet Fix by Ean Pasternak.
       - Catch empty subject and non-existent issuer cert in OCSP Fix by Ean Pasternak.
       - Allow non-FIPS for MD5 Fix by Ean Pasternak.
      
      Signed-off-by: default avatarZoltan HERPAI <wigyori@uid0.hu>
      1657a09a
    • Daniel Golle's avatar
      freeradius2: update to version 2.2.9 · 520ac45c
      Daniel Golle authored
      
      Signed-off-by: default avatarDaniel Golle <daniel@makrotopia.org>
      520ac45c
  2. Nov 03, 2017
  3. Oct 31, 2017
  4. Jul 15, 2017
  5. Apr 08, 2017
  6. Mar 22, 2017
  7. Mar 08, 2017
  8. Feb 26, 2017
  9. Feb 23, 2017
  10. Feb 12, 2017
  11. Feb 09, 2017
  12. Jan 20, 2017
  13. Jan 18, 2017
  14. Jan 12, 2017
  15. Jan 11, 2017
  16. Jan 06, 2017
  17. Jan 05, 2017
  18. Nov 27, 2016
  19. Nov 25, 2016
  20. Nov 24, 2016
  21. Nov 21, 2016
  22. Nov 18, 2016
  23. Nov 16, 2016
  24. Nov 12, 2016
  25. Nov 10, 2016
  26. Nov 09, 2016
  27. Nov 08, 2016
Loading