CVE Vulnerabilities

CVE-2004-0960

Published: Feb 09, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.

Affected Software

NameVendorStart VersionEnd Version
FreeradiusFreeradius0.2 (including)0.2 (including)
FreeradiusFreeradius0.3 (including)0.3 (including)
FreeradiusFreeradius0.4 (including)0.4 (including)
FreeradiusFreeradius0.5 (including)0.5 (including)
FreeradiusFreeradius0.8 (including)0.8 (including)
FreeradiusFreeradius0.8.1 (including)0.8.1 (including)
FreeradiusFreeradius0.9 (including)0.9 (including)
FreeradiusFreeradius0.9.1 (including)0.9.1 (including)
FreeradiusFreeradius0.9.2 (including)0.9.2 (including)
FreeradiusFreeradius0.9.3 (including)0.9.3 (including)
FreeradiusFreeradius1.0.0 (including)1.0.0 (including)
Red Hat Enterprise Linux 3RedHatfreeradius-0:1.0.1-1.RHEL3*

References