Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-10979

Опубликовано: 17 июл. 2017
Источник: debian
EPSS Средний

Описание

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freeradiusfixed3.0.12+dfsg-3package
freeradiusfixed2.2.5+dfsg-0.2+deb8u1jessiepackage

Примечания

  • http://freeradius.org/security/fuzzer-2017.html#FR-GV-202

  • https://github.com/FreeRADIUS/freeradius-server/commit/ae3ba0011e7d299e92c45300e0137a56a650e8f5

  • Mark as fixed in 3.0.12+dfsg-3 the first 3.x version in unstable

  • This is not fully technically correct, the issue affects only the 2.x

  • series but not 3.x.

EPSS

Процентиль: 96%
0.25821
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 8.1
redhat
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
nvd
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
github
больше 3 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

suse-cvrf
около 8 лет назад

Security update for freeradius-server

EPSS

Процентиль: 96%
0.25821
Средний