CVE Vulnerabilities

CVE-2006-1354

Published: Mar 22, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via Insufficient input validation in the EAP-MSCHAPv2 state machine module.

Affected Software

NameVendorStart VersionEnd Version
FreeradiusFreeradius1.0.0 (including)1.0.0 (including)
FreeradiusFreeradius1.0.1 (including)1.0.1 (including)
FreeradiusFreeradius1.0.2 (including)1.0.2 (including)
FreeradiusFreeradius1.0.3 (including)1.0.3 (including)
FreeradiusFreeradius1.0.4 (including)1.0.4 (including)
FreeradiusFreeradius1.0.5 (including)1.0.5 (including)
FreeradiusFreeradius1.1.0 (including)1.1.0 (including)
Red Hat Enterprise Linux 3RedHatfreeradius-0:1.0.1-2.RHEL3.2*
Red Hat Enterprise Linux 4RedHatfreeradius-0:1.0.1-3.RHEL4.3*
FreeradiusUbuntudapper*
FreeradiusUbuntuupstream*

References