Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10979

Опубликовано: 17 июл. 2017
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

An out-of-bounds write flaw was found in the way FreeRADIUS server handled certain attributes in request packets. A remote attacker could use this flaw to crash the FreeRADIUS server or to execute arbitrary code in the context of the FreeRADIUS server process by sending a specially crafted request packet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freeradiusWill not fix
Red Hat Enterprise Linux 5freeradius2Will not fix
Red Hat Enterprise Linux 7freeradiusNot affected
Red Hat Enterprise Linux 6freeradiusFixedRHSA-2017:175918.07.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=1468490freeradius: Out-of-bounds write in rad_coalesce()

EPSS

Процентиль: 94%
0.07043
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
nvd
около 9 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

CVSS3: 9.8
debian
около 9 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overf ...

CVSS3: 9.8
github
около 4 лет назад

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

suse-cvrf
почти 9 лет назад

Security update for freeradius-server

EPSS

Процентиль: 94%
0.07043
Низкий

8.1 High

CVSS3