CVE Vulnerabilities

CVE-2004-0961

Published: Feb 09, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.

Affected Software

NameVendorStart VersionEnd Version
FreeradiusFreeradius0.2 (including)0.2 (including)
FreeradiusFreeradius0.3 (including)0.3 (including)
FreeradiusFreeradius0.4 (including)0.4 (including)
FreeradiusFreeradius0.5 (including)0.5 (including)
FreeradiusFreeradius0.8 (including)0.8 (including)
FreeradiusFreeradius0.8.1 (including)0.8.1 (including)
FreeradiusFreeradius0.9 (including)0.9 (including)
FreeradiusFreeradius0.9.1 (including)0.9.1 (including)
FreeradiusFreeradius0.9.2 (including)0.9.2 (including)
FreeradiusFreeradius0.9.3 (including)0.9.3 (including)
FreeradiusFreeradius1.0.0 (including)1.0.0 (including)
Red Hat Enterprise Linux 3RedHatfreeradius-0:1.0.1-1.RHEL3*

References