Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-10988

Опубликовано: 17 июл. 2017
Источник: redhat
CVSS3: 0

Описание

[REJECTED CVE] A vulnerability has been identified in Freeradius. Attributes of data type 'signed' would sometimes be created from uninitialized memory, instead of from the received packet. There is only one 'signed' attribute, which is in the WiMAX dictionaries, and it is used only in certain limited situations.

Отчет

This CVE has been rejected, because upstream report say: No overflow or exploit is possible. No remote code execution is possible. No denial of service is possible. Exploitation does not cross a privilege boundary in a correct and realistic product deployment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5freeradiusNot affected
Red Hat Enterprise Linux 5freeradius2Not affected
Red Hat Enterprise Linux 6freeradiusNot affected
Red Hat Enterprise Linux 7freeradiusNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-456
https://bugzilla.redhat.com/show_bug.cgi?id=1468555freeradius: Incorrectly created 'signed' attributes

0 Low

CVSS3

Связанные уязвимости

nvd
больше 8 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

suse-cvrf
больше 8 лет назад

Security update for freeradius-server

suse-cvrf
больше 8 лет назад

Security update for freeradius-server

suse-cvrf
больше 8 лет назад

Security update for freeradius-server

0 Low

CVSS3