Security Advisory

CVE-2011-2701

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-08-04 01:00:00
Last updated 2024-08-06 23:08:23
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allows remote attackers to bypass authentication by using the EAP-TLS protocol with a revoked X.509 client certificate.