Description
In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3342-1 | freeradius security update |
Debian DLA |
DLA-4232-1 | freeradius security update |
EUVD |
EUVD-2022-45023 | In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack. |
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-03T19:27:37.502Z
Reserved: 2022-09-30T00:00:00.000Z
Link: CVE-2022-41859
Updated: 2025-11-03T19:27:37.502Z
Status : Modified
Published: 2023-01-17T18:15:11.287
Modified: 2025-11-03T20:15:57.410
Link: CVE-2022-41859
OpenCVE Enrichment
No data.
Debian DLA
EUVD