CVE-2015-4680
Publication date 5 April 2017
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
Status
Package | Ubuntu Release | Status |
---|---|---|
freeradius | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
tyhicks
Upstream states that the recommended configuration is not affected. Only configurations using certs from a public CA are affected and upstream says that such configurations are not recommended.
mdeslaur
we will not be fixing this issue in Ubuntu 14.04 LTS. Users are advised to follow upstream recommendations or to update to a later Ubuntu release.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 · High |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | High |
Availability impact | None |
Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |