Bug 237182 - net/freeradius3: Update to 3.0.19 (Fixes several security vulnerabilities)
Summary: net/freeradius3: Update to 3.0.19 (Fixes several security vulnerabilities)
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Many People
Assignee: Ryan Steinmetz
URL:
Keywords: security
Depends on:
Blocks:
 
Reported: 2019-04-10 17:19 UTC by Hans-Christian Esperer
Modified: 2019-04-29 18:25 UTC (History)
1 user (show)

See Also:
bugzilla: maintainer-feedback? (zi)
koobs: merge-quarterly?


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Hans-Christian Esperer 2019-04-10 17:19:06 UTC
Freeradius 3.17 has some security issues, especially regarding the EAP-PWD authentication module. Please upgrade the port to freeradius-3.19, which addresses these issuse.
Comment 1 commit-hook freebsd_committer freebsd_triage 2019-04-10 18:10:41 UTC
A commit references this bug:

Author: zi
Date: Wed Apr 10 18:09:40 UTC 2019
New revision: 498582
URL: https://svnweb.freebsd.org/changeset/ports/498582

Log:
  - Update to 3.0.19

  PR:		237182

Changes:
  head/net/freeradius3/Makefile
  head/net/freeradius3/distinfo
  head/net/freeradius3/pkg-plist
Comment 2 Kubilay Kocak freebsd_committer freebsd_triage 2019-04-15 07:58:09 UTC
Re-open for VuXML entry MFH. This release fixes security vulneraibilities
Comment 3 Kubilay Kocak freebsd_committer freebsd_triage 2019-04-15 07:59:47 UTC
Multiple users have reported (via IRC) that package updates (to their presumably default quarterly based package configuration) have not resulted in them receiving the version update fixing these vulnerabilities.
Comment 4 commit-hook freebsd_committer freebsd_triage 2019-04-15 13:11:28 UTC
A commit references this bug:

Author: zi
Date: Mon Apr 15 13:11:14 UTC 2019
New revision: 499022
URL: https://svnweb.freebsd.org/changeset/ports/499022

Log:
  MFH: r498582

  - Update to 3.0.19

  PR:		237182

  Approved by:	ports-secteam (with hat)

Changes:
_U  branches/2019Q2/
  branches/2019Q2/net/freeradius3/Makefile
  branches/2019Q2/net/freeradius3/distinfo
  branches/2019Q2/net/freeradius3/pkg-plist