Synopsis
The remote host is missing a vendor-supplied security patch
Description
The remote host is missing the patch for the advisory SUSE-SA:2006:019 (freeradius).
Insufficient input validation was being done in the EAP-MSCHAPv2 state machine of the FreeRADIUS authentication server.
A malicious attacker could manipulate their EAP-MSCHAPv2 client state machine to potentially convince the server to bypass authentication checks. This bypassing could also result in the server crashing.
This is tracked by the Mitre CVE ID CVE-2006-1354.
Solution
http://www.suse.de/security/advisories/2006_19_freeradius.html
Plugin Details
File Name: suse_SA_2006_019.nasl
Agent: unix
Supported Sensors: Continuous Assessment, Nessus Agent, Nessus
Vulnerability Information
Required KB Items: Host/SuSE/rpm-list