CVE-2022-41859
Summary
| CVE | CVE-2022-41859 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-01-17 18:15:00 UTC |
| Updated | 2023-01-24 20:02:00 UTC |
| Description | In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Releases |
MISC |
freeradius.org |
|
| port fixes from master · FreeRADIUS/freeradius-server@9e5e8f2 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160598 Oracle Enterprise Linux Security Update for freeradius (ELSA-2023-2166)
- 160659 Oracle Enterprise Linux Security Update for freeradius:3.0 (ELSA-2023-2870)
- 181610 Debian Security Update for freeradius (DLA 3342-1)
- 183094 Debian Security Update for freeradius (CVE-2022-41859)
- 241426 Red Hat Update for freeradius (RHSA-2023:2166)
- 241539 Red Hat Update for freeradius:3.0 (RHSA-2023:2870)
- 283513 Fedora Security Update for freeradius (FEDORA-2022-98832b2cc2)
- 354797 Amazon Linux Security Advisory for freeradius : ALAS2-2023-1970
- 378746 Alibaba Cloud Linux Security Update for freeradius:3.0 (ALINUX3-SA-2023:0087)
- 503092 Alpine Linux Security Update for freeradius
- 753064 SUSE Enterprise Linux Security Update for freeradius-server (SUSE-SU-2022:4622-1)
- 753065 SUSE Enterprise Linux Security Update for freeradius-server (SUSE-SU-2022:4620-1)
- 753067 SUSE Enterprise Linux Security Update for freeradius-server (SUSE-SU-2022:4621-1)
- 753070 SUSE Enterprise Linux Security Update for freeradius-server (SUSE-SU-2022:4626-1)
- 753554 SUSE Enterprise Linux Security Update for freeradius-server (SUSE-SU-2023:0124-1)
- 941045 AlmaLinux Security Update for freeradius (ALSA-2023:2166)
- 941105 AlmaLinux Security Update for freeradius:3.0 (ALSA-2023:2870)