Total vulnerabilities in the database
The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.
Software | From | Fixed in |
---|---|---|
freeradius / freeradius | - | 1.1.7.x |
freeradius / freeradius | 1.0.0 | 1.0.0.x |
freeradius / freeradius | 0.9 | 0.9.x |
freeradius / freeradius | 1.1.5 | 1.1.5.x |
freeradius / freeradius | 0.9.2 | 0.9.2.x |
freeradius / freeradius | 1.1.0 | 1.1.0.x |
freeradius / freeradius | 1.1.3 | 1.1.3.x |
freeradius / freeradius | 0.3 | 0.3.x |
freeradius / freeradius | 0.9.1 | 0.9.1.x |
freeradius / freeradius | 0.4 | 0.4.x |
freeradius / freeradius | 1.0.1 | 1.0.1.x |
freeradius / freeradius | 0.8.1 | 0.8.1.x |
freeradius / freeradius | 1.0.4 | 1.0.4.x |
freeradius / freeradius | 1.0.2 | 1.0.2.x |
freeradius / freeradius | 0.5 | 0.5.x |
freeradius / freeradius | 1.0.5 | 1.0.5.x |
freeradius / freeradius | 1.0.3 | 1.0.3.x |
freeradius / freeradius | 0.2 | 0.2.x |
freeradius / freeradius | 1.1.6 | 1.1.6.x |
freeradius / freeradius | 0.8 | 0.8.x |
freeradius / freeradius | 0.9.3 | 0.9.3.x |