Red Hat Customer Portal

Skip to main content

Main Navigation

  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
Red Hat Logo Customer Portal
  • Products & Services
    • Back
    • View All Products
    • Infrastructure and Management
      • Back
      • Red Hat Enterprise Linux
      • Red Hat Virtualization
      • Red Hat Identity Management
      • Red Hat Directory Server
      • Red Hat Certificate System
      • Red Hat Satellite
      • Red Hat Subscription Management
      • Red Hat Update Infrastructure
      • Red Hat Insights
      • Red Hat Ansible Tower
      • Red Hat Ansible Engine
    • Cloud Computing
      • Back
      • Red Hat CloudForms
      • Red Hat OpenStack Platform
      • Red Hat Cloud Infrastructure
      • Red Hat Cloud Suite
      • Red Hat OpenShift Container Platform
      • Red Hat OpenShift Online
      • Red Hat OpenShift Dedicated
      • Red Hat OpenShift Application Runtimes
    • Storage
      • Back
      • Red Hat Gluster Storage
      • Red Hat Hyperconverged Infrastructure
      • Red Hat Ceph Storage
      • Red Hat Openshift Container Storage
    • JBoss Development and Management
      • Back
      • Red Hat JBoss Enterprise Application Platform
      • Red Hat JBoss Data Grid
      • Red Hat JBoss Web Server
      • Red Hat JBoss Operations Network
      • Red Hat Developer Studio
    • JBoss Integration and Automation
      • Back
      • Red Hat JBoss Data Virtualization
      • Red Hat Fuse
      • Red Hat AMQ
      • Red Hat Process Automation Manager
      • Red Hat Decision Manager
      • Red Hat 3scale API Management
    • Mobile
      • Back
      • Red Hat Mobile Application Platform
    • Support
    • Production Support
    • Development Support
    • Product Life Cycle & Update Policies
    • Documentation
    • Red Hat Enterprise Linux
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenStack Platform
    • Red Hat OpenShift Container Platform
    • Services
    • Consulting
    • Technical Account Management
    • Training & Certifications
    • Ecosystem
    • Browse Certified Solutions
    • Partner Resources
  • Tools
    • Back
    • Red Hat Insights
    • Tools
    • Solution Engine
    • Packages
    • Errata
    • Customer Portal Labs
    • Explore Labs
    • Configuration
    • Deployment
    • Security
    • Troubleshooting
  • Security
    • Back
    • Product Security Center
    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Security Labs
    • Resources
    • Overview
    • Security Blog
    • Security Measurement
    • Severity Ratings
    • Backporting Policies
    • Product Signing (GPG) Keys
  • Community
    • Back
    • Customer Portal Community
    • Discussions
    • Blogs
    • Private Groups
    • Community Activity
    • Customer Events
    • Red Hat Convergence
    • Red Hat Summit
    • Stories
    • Red Hat Subscription Value
    • You Asked. We Acted.
    • Open Source Communities
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Account
    • Back
    • Log In
    • Register
    • Red Hat Account Number:
    • Account Details
    • User Management
    • Account Maintenance
    • My Profile
    • Notifications
    • Help
    • Log Out
  • Language
    • Back
    • English
    • Español
    • Deutsch
    • Italiano
    • 한국어
    • Français
    • 日本語
    • Português
    • 中文 (中国)
    • русский
  • Subscriptions
  • Downloads
  • Containers
  • Support Cases
  • Search
  • Log In
  • Language
Troubleshooting an issue? Try Solution Engine—our new support tool.

Log in to Your Red Hat Account

Log In

Your Red Hat account gives you access to your profile, preferences, and services, depending on your status.

Register

If you are a new customer, register now for access to product evaluations and purchasing capabilities.

Need access to an account?

If your company has an existing Red Hat account, your organization administrator can grant you access.

If you have any questions, please contact customer service.

Red Hat Account Number:

Red Hat Account

  • Account Details
  • User Management
  • Account Maintenance

Customer Portal

  • My Profile
  • Notifications
  • Help

For your security, if you’re on a public computer and have finished using your Red Hat services, please be sure to log out.

Log Out

Select Your Language

  • English
  • Español
  • Deutsch
  • Italiano
  • 한국어
  • Français
  • 日本語
  • Português
  • 中文 (中国)
  • русский
Red Hat Customer Portal
  • Products & Services
  • Tools
  • Security
  • Community
  • Infrastructure and Management

  • Cloud Computing

  • Storage

  • JBoss Development and Management

  • JBoss Integration and Automation

  • Mobile

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Tower
  • Red Hat Ansible Engine
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat Cloud Infrastructure
  • Red Hat Cloud Suite
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat OpenShift Application Runtimes
  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat Openshift Container Storage
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat JBoss Data Grid
  • Red Hat JBoss Web Server
  • Red Hat JBoss Operations Network
  • Red Hat Developer Studio
  • Red Hat JBoss Data Virtualization
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager
  • Red Hat 3scale API Management
  • Red Hat Mobile Application Platform
View All Products
  • Support
  • Production Support
  • Development Support
  • Product Life Cycle & Update Policies

Services

  • Consulting
  • Technical Account Management
  • Training & Certifications
  • Documentation
  • Red Hat Enterprise Linux
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Ecosystem
  • Browse Certified Solutions
  • Partner Resources

Tools

  • Solution Engine
  • Packages
  • Errata
  • Customer Portal Labs
  • Configuration
  • Deployment
  • Security
  • Troubleshooting
  • Red Hat Insights

Increase visibility into IT operations to detect and resolve technical issues before they impact your business.

Red Hat Product Security Center

Engage with our Red Hat Product Security team, access security updates, and ensure your environments are not exposed to any known security vulnerabilities.

Product Security Center

Security Updates

  • Security Advisories
  • Red Hat CVE Database
  • Security Labs

Keep your systems secure with Red Hat's specialized responses for high-priority security vulnerabilities.

  • View Responses

Resources

  • Overview
  • Security Blog
  • Security Measurement
  • Severity Ratings
  • Backporting Policies
  • Product Signing (GPG) Keys

Customer Portal Community

  • Discussions
  • Blogs
  • Private Groups
  • Community Activity

Customer Events

  • Red Hat Convergence
  • Red Hat Summit

Stories

  • Red Hat Subscription Value
  • You Asked. We Acted.
  • Open Source Communities
Red Hat Product Errata RHSA-2006:0271 - Security Advisory
Issued:
2006-04-04
Updated:
2006-04-13

RHSA-2006:0271 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

freeradius security update

Type/Severity

Security Advisory: Important

Topic

Updated freeradius packages that fix an authentication weakness are now
available.

This update has been rated as having important security impact by the Red
Hat Security Response Team.

Description

FreeRADIUS is a high-performance and highly configurable free RADIUS server
designed to allow centralized authentication and authorization for a network.

A bug was found in the way FreeRADIUS authenticates users via the MSCHAP V2
protocol. It is possible for a remote attacker to authenticate as a victim
by sending a malformed MSCHAP V2 login request to the FreeRADIUS server.
(CVE-2006-1354)

Please note that FreeRADIUS installations not using the MSCHAP V2 protocol
for authentication are not vulnerable to this issue.

A bug was also found in the way FreeRADIUS logs SQL errors from the
sql_unixodbc module. It may be possible for an attacker to cause FreeRADIUS
to crash or execute arbitrary code if they are able to manipulate the SQL
database FreeRADIUS is connecting to. (CVE-2005-4744)

Users of FreeRADIUS should update to these erratum packages, which contain
backported patches and are not vulnerable to these issues.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

This update is available via Red Hat Network. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Affected Products

  • Red Hat Enterprise Linux Server 4 x86_64
  • Red Hat Enterprise Linux Server 4 ia64
  • Red Hat Enterprise Linux Server 4 i386
  • Red Hat Enterprise Linux Server 3 x86_64
  • Red Hat Enterprise Linux Server 3 ia64
  • Red Hat Enterprise Linux Server 3 i386
  • Red Hat Enterprise Linux for IBM z Systems 4 s390x
  • Red Hat Enterprise Linux for IBM z Systems 4 s390
  • Red Hat Enterprise Linux for IBM z Systems 3 s390x
  • Red Hat Enterprise Linux for IBM z Systems 3 s390
  • Red Hat Enterprise Linux for Power, big endian 4 ppc
  • Red Hat Enterprise Linux for Power, big endian 3 ppc

Fixes

  • BZ - 167676 - CVE-2005-4744 Multiple freeradius security issues
  • BZ - 186083 - CVE-2006-1354 FreeRADIUS authentication bypass

CVEs

  • CVE-2006-1354
  • CVE-2005-4744

References

  • http://www.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server 4

SRPM
freeradius-1.0.1-3.RHEL4.3.src.rpm SHA-256: 2828833dd8ce414677a7f9ad72357cbca8b0964cc23fb94555be1680d53a6f2c
x86_64
freeradius-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: c922295d3819f6b36ef7d19f940703f0ae51e735db271c8380a59bb660967d62
freeradius-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: c922295d3819f6b36ef7d19f940703f0ae51e735db271c8380a59bb660967d62
freeradius-mysql-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: e4f50d4277bc1fc72e006d4ad3e9b3d00197e6e29ffca4129a65bec59d8597c6
freeradius-mysql-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: e4f50d4277bc1fc72e006d4ad3e9b3d00197e6e29ffca4129a65bec59d8597c6
freeradius-postgresql-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: 9fd979be9f3bcc82150ca6be32b1febe98808d4099f58ebdc7c3eb2dbaa70883
freeradius-postgresql-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: 9fd979be9f3bcc82150ca6be32b1febe98808d4099f58ebdc7c3eb2dbaa70883
freeradius-unixODBC-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: 56b9c5cf9848bf31e0ed3f7ba38c44c3de1d4e48e8c993701bf712bfdff022e6
freeradius-unixODBC-1.0.1-3.RHEL4.3.x86_64.rpm SHA-256: 56b9c5cf9848bf31e0ed3f7ba38c44c3de1d4e48e8c993701bf712bfdff022e6
ia64
freeradius-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: fb57c128668e4d9dbeda37a9dcc5b10987a39a34754fb9664146ccb8e5edaf34
freeradius-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: fb57c128668e4d9dbeda37a9dcc5b10987a39a34754fb9664146ccb8e5edaf34
freeradius-mysql-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: 1daaf40f5909a92b292d3e2db4ce2a7fd680744fbe43ca99f65438e7232fe9a1
freeradius-mysql-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: 1daaf40f5909a92b292d3e2db4ce2a7fd680744fbe43ca99f65438e7232fe9a1
freeradius-postgresql-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: 505ec694c842f2380e22fbf3c09cf358796db438c573b1c645e5933107093c2a
freeradius-postgresql-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: 505ec694c842f2380e22fbf3c09cf358796db438c573b1c645e5933107093c2a
freeradius-unixODBC-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: 5cc442815a4dab74cb7597b7749e14770b4f9990e144d1ee8c73ed85c97df372
freeradius-unixODBC-1.0.1-3.RHEL4.3.ia64.rpm SHA-256: 5cc442815a4dab74cb7597b7749e14770b4f9990e144d1ee8c73ed85c97df372
i386
freeradius-1.0.1-3.RHEL4.3.i386.rpm SHA-256: 3b051ee9b137d406373773b2d2b774147346d334a3bd1f19659303c674610ee9
freeradius-1.0.1-3.RHEL4.3.i386.rpm SHA-256: 3b051ee9b137d406373773b2d2b774147346d334a3bd1f19659303c674610ee9
freeradius-mysql-1.0.1-3.RHEL4.3.i386.rpm SHA-256: 1342cb02c959cb7b2ab0049d1691fd33dc4e4c92698e5d7a1e85facbd3de21a4
freeradius-mysql-1.0.1-3.RHEL4.3.i386.rpm SHA-256: 1342cb02c959cb7b2ab0049d1691fd33dc4e4c92698e5d7a1e85facbd3de21a4
freeradius-postgresql-1.0.1-3.RHEL4.3.i386.rpm SHA-256: d48f7a956c9e8a1661b87fab1a0b858bdf8ad4056d48372cf97179827df358d3
freeradius-postgresql-1.0.1-3.RHEL4.3.i386.rpm SHA-256: d48f7a956c9e8a1661b87fab1a0b858bdf8ad4056d48372cf97179827df358d3
freeradius-unixODBC-1.0.1-3.RHEL4.3.i386.rpm SHA-256: dbe0ef5fc526b6849844a7a084309bb8ad42fedb6340efdda3a4ca68b32c7b2b
freeradius-unixODBC-1.0.1-3.RHEL4.3.i386.rpm SHA-256: dbe0ef5fc526b6849844a7a084309bb8ad42fedb6340efdda3a4ca68b32c7b2b

Red Hat Enterprise Linux for IBM z Systems 4

SRPM
freeradius-1.0.1-3.RHEL4.3.src.rpm SHA-256: 2828833dd8ce414677a7f9ad72357cbca8b0964cc23fb94555be1680d53a6f2c
s390x
freeradius-1.0.1-3.RHEL4.3.s390x.rpm SHA-256: 208fa8fae0c8a91631be07300aad7919334e45a8797a45df1ac87a500ad8a9cc
freeradius-mysql-1.0.1-3.RHEL4.3.s390x.rpm SHA-256: af55c11bf06ca009f424500f717bbe8484698deddb9fa396a02a060c09207f91
freeradius-postgresql-1.0.1-3.RHEL4.3.s390x.rpm SHA-256: a876dd0fef6a4abf214323079b3da0bf7024e51a144a45ca012c9676ab4e4628
freeradius-unixODBC-1.0.1-3.RHEL4.3.s390x.rpm SHA-256: 93f82ee48b2d9f77bc93e8ea70c1c9a3cdd2b32ff85c920b77cd25af9f190367
s390
freeradius-1.0.1-3.RHEL4.3.s390.rpm SHA-256: 9b3f51d8a2d8b140f64823d5c2ccc0e7a2864709fe586f6a55a71298133ed57f
freeradius-mysql-1.0.1-3.RHEL4.3.s390.rpm SHA-256: e6110b180ce78edae8d0c3e200ea9fdc44c4452ffa993cce4950dfcc1fdae31f
freeradius-postgresql-1.0.1-3.RHEL4.3.s390.rpm SHA-256: 08c5e82775c414758b054ca65377bfbf9a3ab2fd975d3b9e819e21da9e69d05d
freeradius-unixODBC-1.0.1-3.RHEL4.3.s390.rpm SHA-256: 79eba2848aa046cb417eb9975f4c19db2c0a98cdaaed74fcf87153ffe97de024

Red Hat Enterprise Linux for Power, big endian 4

SRPM
freeradius-1.0.1-3.RHEL4.3.src.rpm SHA-256: 2828833dd8ce414677a7f9ad72357cbca8b0964cc23fb94555be1680d53a6f2c
ppc
freeradius-1.0.1-3.RHEL4.3.ppc.rpm SHA-256: 8bc5a134ac8ca7c31398d64c21312a82e007d5def4c1526af95aeeeb3498d654
freeradius-mysql-1.0.1-3.RHEL4.3.ppc.rpm SHA-256: a2170771b2bf922325aa8f0fcba4a3f7a54ca70fd0e4bbca56819cf32a18fafc
freeradius-postgresql-1.0.1-3.RHEL4.3.ppc.rpm SHA-256: f62acab2d9a63a323fa0bd2024c363e6ef2580e133ef973a5b7480f4d7e17cc5
freeradius-unixODBC-1.0.1-3.RHEL4.3.ppc.rpm SHA-256: 462cf10140eaa541e59abb8a5344a3622cac30994fe8891cea24e56be21e3f39

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • openshift.com
  • developers.redhat.com
  • connect.redhat.com

About

  • Red Hat Subscription Value
  • About Red Hat
  • Red Hat Jobs
Copyright © 2018 Red Hat, Inc.
  • Privacy Statement
  • Customer Portal Terms of Use
  • All Policies and Guidelines
Red Hat Summit
Twitter Facebook Google+