CVE Vulnerabilities

CVE-2004-0849

Published: Dec 23, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the –enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.

Affected Software

NameVendorStart VersionEnd Version
RadiusGnu0.92.1 (including)0.92.1 (including)
RadiusGnu0.93 (including)0.93 (including)
RadiusGnu0.94 (including)0.94 (including)
RadiusGnu0.95 (including)0.95 (including)
RadiusGnu0.96 (including)0.96 (including)
RadiusGnu1.1 (including)1.1 (including)
RadiusGnu1.2 (including)1.2 (including)

References