CVE-2012-4566
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to…
Does this matter?
Lower severity and a low EPSS score (1.50%). Track it; it rarely justifies an emergency change on its own.
Description
The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block being used for verifying the certificate chain, which might allow remote attackers to bypass intended access restrictions and spoof clients, a different vulnerability than CVE-2012-4523.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- uninett/radsecproxy
- Source
- secalert@redhat.com
References
- http://git.nordu.net/?p=radsecproxy.git%3Ba=commit%3Bh=3682c935facf5ccd7fa600644bbb76957155c680
- http://secunia.com/advisories/51251Vendor Advisory
- http://www.debian.org/security/2012/dsa-2573
- http://www.openwall.com/lists/oss-security/2012/10/17/7
- http://www.openwall.com/lists/oss-security/2012/10/31/6
- https://postlister.uninett.no/sympa/arc/radsecproxy/2012-09/msg00001.html
- https://postlister.uninett.no/sympa/arc/radsecproxy/2012-10/msg00001.html
- http://git.nordu.net/?p=radsecproxy.git%3Ba=commit%3Bh=3682c935facf5ccd7fa600644bbb76957155c680
- http://secunia.com/advisories/51251Vendor Advisory
- http://www.debian.org/security/2012/dsa-2573
- http://www.openwall.com/lists/oss-security/2012/10/17/7
- http://www.openwall.com/lists/oss-security/2012/10/31/6
- https://postlister.uninett.no/sympa/arc/radsecproxy/2012-09/msg00001.html
- https://postlister.uninett.no/sympa/arc/radsecproxy/2012-10/msg00001.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.