CVE Vulnerabilities

CVE-2010-3697

Published: Oct 07, 2010 | Modified: Oct 08, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4 N/A
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.

Affected Software

Name Vendor Start Version End Version
Freeradius Freeradius 2.1.0 (including) 2.1.0 (including)
Freeradius Freeradius 2.1.1 (including) 2.1.1 (including)
Freeradius Freeradius 2.1.2 (including) 2.1.2 (including)
Freeradius Freeradius 2.1.3 (including) 2.1.3 (including)
Freeradius Freeradius 2.1.4 (including) 2.1.4 (including)
Freeradius Freeradius 2.1.6 (including) 2.1.6 (including)
Freeradius Freeradius 2.1.7 (including) 2.1.7 (including)
Freeradius Freeradius 2.1.8 (including) 2.1.8 (including)
Freeradius Freeradius 2.1.9 (including) 2.1.9 (including)
Freeradius Ubuntu jaunty *
Freeradius Ubuntu karmic *
Freeradius Ubuntu maverick *
Freeradius Ubuntu upstream *

References