Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10979

Опубликовано: 17 июл. 2017
Источник: redhat
CVSS3: 8.1
EPSS Средний

Описание

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

An out-of-bounds write flaw was found in the way FreeRADIUS server handled certain attributes in request packets. A remote attacker could use this flaw to crash the FreeRADIUS server or to execute arbitrary code in the context of the FreeRADIUS server process by sending a specially crafted request packet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freeradiusWill not fix
Red Hat Enterprise Linux 5freeradius2Will not fix
Red Hat Enterprise Linux 7freeradiusNot affected
Red Hat Enterprise Linux 6freeradiusFixedRHSA-2017:175918.07.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1468490freeradius: Out-of-bounds write in rad_coalesce()

EPSS

Процентиль: 96%
0.25821
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
nvd
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
debian
больше 8 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overf ...

CVSS3: 9.8
github
больше 3 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

suse-cvrf
около 8 лет назад

Security update for freeradius-server

EPSS

Процентиль: 96%
0.25821
Средний

8.1 High

CVSS3