CVE-2011-4966: Medium severity freeradius vulnerability
modules/rlmunix/rlmunix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4966?
The severity of CVE-2011-4966 is typically classified as medium, due to the potential for remote authenticated users to authenticate with an expired password.
How do I fix CVE-2011-4966?
To fix CVE-2011-4966, upgrade to FreeRADIUS version 2.2.0 or later where the vulnerability has been addressed.
Which versions of FreeRADIUS are affected by CVE-2011-4966?
CVE-2011-4966 affects FreeRADIUS versions prior to 2.2.0, including all earlier versions.
Can CVE-2011-4966 be exploited by local users?
Yes, CVE-2011-4966 can be exploited by local users who are able to authenticate despite having an expired password.
What are the potential impacts of CVE-2011-4966?
The potential impacts of CVE-2011-4966 include unauthorized access to systems through the use of expired credentials, leading to sensitive data exposure.