Group administrators:
Critical Vulnerability in FreeRADIUS
Monday, September 10, 2012 - 16:04
A critical vulnerability had been found in FreeRADIUS versions 2.1.10 - 2.1.12 with configurations using TLS-based EAP
methods (including EAP-TLS, EAP-TTLS, and PEAP) this allows an attacker to execute code on affected systems prior to authenticated.
In order to mitigate the vulnerability it is advisable to upgrade all affected systems to FreeRADIUS 2.2.0 as soon as possible.
Further details of this issue are available at http://www.pre-cert.de/advisories/PRE-SA-2012-06.txt