Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10979

Опубликовано: 17 июл. 2017
Источник: redhat
CVSS3: 8.1

Описание

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

An out-of-bounds write flaw was found in the way FreeRADIUS server handled certain attributes in request packets. A remote attacker could use this flaw to crash the FreeRADIUS server or to execute arbitrary code in the context of the FreeRADIUS server process by sending a specially crafted request packet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freeradiusWill not fix
Red Hat Enterprise Linux 5freeradius2Will not fix
Red Hat Enterprise Linux 7freeradiusNot affected
Red Hat Enterprise Linux 6freeradiusFixedRHSA-2017:175918.07.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1468490freeradius: Out-of-bounds write in rad_coalesce()

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
nvd
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
debian
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overf ...

CVSS3: 9.8
github
больше 3 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

suse-cvrf
больше 8 лет назад

Security update for freeradius-server

8.1 High

CVSS3