Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10985

Опубликовано: 17 июл. 2017
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.

A denial of service flaw was found in the way FreeRADIUS server handled certain attributes in request packets. A remote attacker could use this flaw to cause the FreeRADIUS server to enter an infinite loop, consume increasing amounts of memory resources, and ultimately crash by sending a specially crafted request packet.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freeradiusNot affected
Red Hat Enterprise Linux 5freeradius2Not affected
Red Hat Enterprise Linux 6freeradiusNot affected
Red Hat Enterprise Linux 7freeradiusFixedRHSA-2017:238901.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1468550freeradius: Infinite loop and memory exhaustion with 'concat' attributes

EPSS

Процентиль: 83%
0.01995
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.

CVSS3: 7.5
nvd
больше 8 лет назад

An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.

CVSS3: 7.5
debian
больше 8 лет назад

An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite lo ...

CVSS3: 7.5
github
больше 3 лет назад

An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.

suse-cvrf
около 8 лет назад

Security update for freeradius-server

EPSS

Процентиль: 83%
0.01995
Низкий

5.9 Medium

CVSS3