Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-2015

Опубликовано: 02 нояб. 2014
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.

РелизСтатусПримечание
devel

released

2.1.12+dfsg-1.2ubuntu8
lucid

released

2.1.8+dfsg-1ubuntu1.1
precise

released

2.1.10+dfsg-3ubuntu0.12.04.2
quantal

released

2.1.12+dfsg-1.1ubuntu0.1
saucy

released

2.1.12+dfsg-1.2ubuntu5.1
upstream

needed

Показывать по

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 11 лет назад

Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.

nvd
почти 11 лет назад

Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.

debian
почти 11 лет назад

Stack-based buffer overflow in the normify function in the rlm_pap mod ...

github
больше 3 лет назад

Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.

oracle-oval
около 10 лет назад

ELSA-2015-1287: freeradius security, bug fix, and enhancement update (MODERATE)

7.5 High

CVSS2