UBUNTU-CVE-2019-13456

Source
https://ubuntu.com/security/CVE-2019-13456
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2019/UBUNTU-CVE-2019-13456.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2019-13456
Related
Published
2019-12-03T20:15:00Z
Modified
2019-12-03T20:15:00Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.

References

Affected packages

Ubuntu:18.04:LTS / freeradius

Package

Name
freeradius
Purl
pkg:deb/ubuntu/freeradius?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.16+dfsg-1ubuntu3.1

Affected versions

3.*

3.0.15+dfsg-1ubuntu2
3.0.16+dfsg-1ubuntu2
3.0.16+dfsg-1ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-common"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-config"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-dhcp"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-dhcp-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-iodbc"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-iodbc-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-krb5"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-krb5-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-ldap"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-ldap-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-memcached"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-memcached-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-mysql"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-mysql-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-postgresql"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-postgresql-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-redis"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-redis-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-rest"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-rest-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-utils"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-utils-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-yubikey"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "freeradius-yubikey-dbgsym"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "libfreeradius-dev"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "libfreeradius3"
        },
        {
            "binary_version": "3.0.16+dfsg-1ubuntu3.1",
            "binary_name": "libfreeradius3-dbgsym"
        }
    ]
}