Vulnerability Name: | CVE-2003-0967 (CCN-13806) | ||||||||||||||||||||
Assigned: | 2003-11-20 | ||||||||||||||||||||
Published: | 2003-11-20 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute. | ||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Nov 20 2003 - 14:03:30 CST Remote DoS in FreeRADIUS, all versions. Source: CCN Type: BugTraq Mailing List, Fri Nov 21 2003 - 07:07:49 CST FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability Source: CCN Type: S-Quadra Advisory #2003-11-21 FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability Source: MITRE Type: CNA CVE-2003-0967 Source: BUGTRAQ Type: UNKNOWN 20031120 Remote DoS in FreeRADIUS, all versions. Source: BUGTRAQ Type: UNKNOWN 20031121 FreeRADIUS 0.9.2 "Tunnel-Password" attribute Handling Vulnerability Source: CONFIRM Type: UNKNOWN http://marc.info/?l=freeradius-users&m=106947389449613&w=2 Source: CCN Type: RHSA-2003-386 freeradius security update Source: CCN Type: FreeRADIUS Web site FreeRADIUS - building the perfect RADIUS server Source: CCN Type: GLSA-200311-04 FreeRADIUS: heap exploit and NULL pointer dereference vulnerability Source: REDHAT Type: UNKNOWN RHSA-2003:386 Source: XF Type: UNKNOWN freeradius-accesspacket-dos(13806) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10917 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |