Juniper Steel-Belted Radius Multiple OpenSSL Vulnerabilities
Medium Nessus Plugin ID 70165
SynopsisThe remote host has an application installed that is affected by multiple OpenSSL vulnerabilities.
DescriptionThe version of Juniper Steel-Belted Radius software installed on the remote RedHat or CentOS host is affected by multiple OpenSSL vulnerabilities :
- The SSL 3.0 implementation in OpenSSL does not properly initialize data structures for block cipher padding, which could allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer. (CVE-2011-4576)
- The Server Gated Cryptography (SGC) implementation in OpenSSL does not properly handle handshake restarts, which could allow remote attackers to cause a denial of service condition. (CVE-2011-4619)
SolutionUpdates are available from the vendor.