VDB
CVE-2011-4966
CVE-2011-4966
PUBLISHED
CVSS 6 MEDIUM
modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.
EPSS 1.38% · 70.1th percentile
Risk Scores
CVSS 2.0
6
EPSS Score
1.38%
70.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| freeradius | freeradius | 1.1.8, 0, 0.1 |
| n/a | n/a | n/a |
Timeline
- Mar 12, 2013 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- RHSA-2013:0134 vendor-advisory
- openSUSE-SU-2013:0137 vendor-advisory
- openSUSE-SU-2013:0191 vendor-advisory
- http://rhn.redhat.com/errata/RHBA-2012-0881.html url
- https://nvd.nist.gov/vuln/detail/CVE-2011-4966 advisory
- https://github.com/alandekok/freeradius-server/commit/1b1ec5ce75e224bd1755650c18ccdaa6dc53e605 technical