=====================================================================
                                   CERT-Renater

                        Note d'Information No. 2009/VULN366
_____________________________________________________________________

DATE                      : 11/09/2009

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Systems running FreeRADIUS
                             versions 1.1.x prior to 1.1.8.

======================================================================
http://lists.freeradius.org/pipermail/freeradius-users/2009-September/msg00242.html
______________________________________________________________________

  We have released version 1.1.8 to fix an issue with the handling of
Tunnel-Password.  This is the same issue that was found in version
0.9.2, and which managed to return.

  Version 2.X is *not* affected by this issue.

  The difference between 1.1.7 and this release is the patch to fix that
bug.  The only other changes are that the version number has changed
from 1.1.7 to 1.1.8 in a number of files.

  Alan DeKok.

======================================================================

          =========================================================
          Les serveurs de référence du CERT-Renater
          http://www.urec.fr/securite
          http://www.cru.fr/securite
          http://www.renater.fr
          =========================================================
          + CERT-RENATER          | tel : 01-53-94-20-44          +
          + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
          + 75013 Paris           | email: certsvp@renater.fr     +
          =========================================================


