CVE Vulnerabilities

CVE-2010-3696

Published: Oct 07, 2010 | Modified: Nov 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4 LOW
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.

Affected Software

Name Vendor Start Version End Version
Freeradius Freeradius 2.1.9 (including) 2.1.9 (including)
Freeradius Ubuntu jaunty *
Freeradius Ubuntu karmic *
Freeradius Ubuntu maverick *
Freeradius Ubuntu upstream *

References