CVE Vulnerabilities

CVE-2015-8762

NULL Pointer Dereference

Published: Mar 27, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
2.9 MODERATE
AV:A/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FreeradiusFreeradius3.0.0 (including)3.0.0 (including)
FreeradiusFreeradius3.0.1 (including)3.0.1 (including)
FreeradiusFreeradius3.0.2 (including)3.0.2 (including)
FreeradiusFreeradius3.0.3 (including)3.0.3 (including)
FreeradiusFreeradius3.0.4 (including)3.0.4 (including)
FreeradiusFreeradius3.0.5 (including)3.0.5 (including)
FreeradiusFreeradius3.0.6 (including)3.0.6 (including)
FreeradiusFreeradius3.0.7 (including)3.0.7 (including)
FreeradiusFreeradius3.0.8 (including)3.0.8 (including)

Potential Mitigations

References