CVE Vulnerabilities

CVE-2015-8762

NULL Pointer Dereference

Published: Mar 27, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
2.9 MODERATE
AV:A/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Freeradius Freeradius 3.0.0 (including) 3.0.0 (including)
Freeradius Freeradius 3.0.1 (including) 3.0.1 (including)
Freeradius Freeradius 3.0.2 (including) 3.0.2 (including)
Freeradius Freeradius 3.0.3 (including) 3.0.3 (including)
Freeradius Freeradius 3.0.4 (including) 3.0.4 (including)
Freeradius Freeradius 3.0.5 (including) 3.0.5 (including)
Freeradius Freeradius 3.0.6 (including) 3.0.6 (including)
Freeradius Freeradius 3.0.7 (including) 3.0.7 (including)
Freeradius Freeradius 3.0.8 (including) 3.0.8 (including)

Potential Mitigations

References