CVE-2012-3547
published 2012-09-18CVE-2012-3547: Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to…
PriorityP338medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.70%
92.1th percentile
Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 2.1.12+dfsg-1.1 (bookworm) | freeradius 2.1.12+dfsg-1.1 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 2.1.12+dfsg-1.1 | 2.1.12+dfsg-1.1 |
| freeradius | freeradius | >= 0 < 2.1.12+dfsg-1.1 | 2.1.12+dfsg-1.1 |
| freeradius | freeradius | >= 0 < 2.1.12+dfsg-1.1 | 2.1.12+dfsg-1.1 |
| freeradius | freeradius | >= 0 < 2.1.12+dfsg-1.1 | 2.1.12+dfsg-1.1 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRADIUS vulnerability
vendor_ubuntu·2012-09-26
CVE-2012-3547 FreeRADIUS vulnerability
Title: FreeRADIUS vulnerability
Summary: FreeRADIUS could be made to crash or run programs if it received
specially crafted network traffic.
Timo Warns discovered that FreeRADIUS incorrectly handled certain long
timestamps in client certificates. A remote attacker could exploit this
flaw and cause the FreeRADIUS server to crash, resulting in a denial of
service, or possibly execute arbitrary code.
The default compiler options for affected releases should reduce the
vulnerability to a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freeradius: stack-based buffer overflow via long expiration date fields in client X509 certificates
vendor_redhat·2012-09-10·CVSS 6.8
CVE-2012-3547 [MEDIUM] CWE-121 freeradius: stack-based buffer overflow via long expiration date fields in client X509 certificates
freeradius: stack-based buffer overflow via long expiration date fields in client X509 certificates
Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.
Package: freeradius (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2012-3547: freeradius - Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 th...
vendor_debian·2012·CVSS 6.8
CVE-2012-3547 [MEDIUM] CVE-2012-3547: freeradius - Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 th...
Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.
Scope: local
bookworm: resolved (fixed in 2.1.12+dfsg-1.1)
bullseye: resolved (fixed in 2.1.12+dfsg-1.1)
forky: resolved (fixed in 2.1.12+dfsg-1.1)
sid: resolved (fixed in 2.1.12+dfsg-1.1)
trixie: resolved (fixed in 2.1.12+dfsg-1.1)
GHSA
GHSA-rv5x-2jxm-gf9c: Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2
ghsa_unreviewed·2022-05-17
CVE-2012-3547 [MEDIUM] CWE-119 GHSA-rv5x-2jxm-gf9c: Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2
Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.
OSV
CVE-2012-3547: Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2
osv·2012-09-18·CVSS 6.8
CVE-2012-3547 [MEDIUM] CVE-2012-3547: Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2
Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3547 freeradius: Stack-based buffer overflow by processing certain expiration date fields of a certificate during x509 certificate validation [fedora-all]
bugzilla·2012-09-10·CVSS 6.8
CVE-2012-3547 [MEDIUM] CVE-2012-3547 freeradius: Stack-based buffer overflow by processing certain expiration date fields of a certificate during x509 certificate validation [fedora-all]
CVE-2012-3547 freeradius: Stack-based buffer overflow by processing certain expiration date fields of a certificate during x509 certificate validation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
B
Bugzilla
CVE-2012-3547 freeradius: stack-based buffer overflow via long expiration date fields in client X509 certificates
bugzilla·2012-08-29·CVSS 6.8
CVE-2012-3547 [MEDIUM] CVE-2012-3547 freeradius: stack-based buffer overflow via long expiration date fields in client X509 certificates
CVE-2012-3547 freeradius: stack-based buffer overflow via long expiration date fields in client X509 certificates
A stack-based buffer overflow flaw was found in the way FreeRADIUS, a high-performance and highly configurable free RADIUS server, performed x509 certificates validation when freeradius was configured to use some of TLS-based Extensible Authentication Protocols, EAP (EAP-TLS, EAP-TTLS, or PEAP). A remote RADIUS client could present a specially-crafted X509_v3 certificate that, when processed by RADIUS server in order to establish TLS session, would lead to radiusd daemon crash or, potentially, arbitrary code execution with the privileges of the user running the radiusd service.
Upstream patch that introduced this issue:
[1] https://github.com/alandekok/freeradius-server/commi
http://archives.neohapsis.com/archives/bugtraq/2012-09/0043.htmlhttp://freeradius.org/security.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090171.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00023.htmlhttp://osvdb.org/85325http://rhn.redhat.com/errata/RHSA-2012-1326.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1327.htmlhttp://secunia.com/advisories/50484http://secunia.com/advisories/50584http://secunia.com/advisories/50637http://secunia.com/advisories/50770http://www.debian.org/security/2012/dsa-2546http://www.mandriva.com/security/advisories?name=MDVSA-2012:159http://www.openwall.com/lists/oss-security/2012/09/10/2http://www.pre-cert.de/advisories/PRE-SA-2012-06.txthttp://www.securityfocus.com/bid/55483http://www.securitytracker.com/id?1027509http://www.ubuntu.com/usn/USN-1585-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78408http://archives.neohapsis.com/archives/bugtraq/2012-09/0043.htmlhttp://freeradius.org/security.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090171.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-09/msg00023.htmlhttp://osvdb.org/85325http://rhn.redhat.com/errata/RHSA-2012-1326.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1327.htmlhttp://secunia.com/advisories/50484http://secunia.com/advisories/50584http://secunia.com/advisories/50637http://secunia.com/advisories/50770http://www.debian.org/security/2012/dsa-2546http://www.mandriva.com/security/advisories?name=MDVSA-2012:159http://www.openwall.com/lists/oss-security/2012/09/10/2http://www.pre-cert.de/advisories/PRE-SA-2012-06.txthttp://www.securityfocus.com/bid/55483http://www.securitytracker.com/id?1027509http://www.ubuntu.com/usn/USN-1585-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78408
2012-09-18
Published