CVE-2012-2110

2012-04-19 Thread Brian Julin
A cursory look suggests we may use some of the effected codepaths in CVE-2012-2110 (http://lists.grok.org.uk/pipermail/full-disclosure/2012-April/086585.html) and given that FreeRADIUS often deals with certificates from sources that are not under direct control of administrators (dot1x clients

Re: CVE-2012-2110

2012-04-19 Thread Alan DeKok
Brian Julin wrote: > A cursory look suggests we may use some of the effected codepaths > in CVE-2012-2110 > (http://lists.grok.org.uk/pipermail/full-disclosure/2012-April/086585.html) > and given that FreeRADIUS often deals with certificates from > sources that are not under di