CVE-2017-10978

Description

An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows Read / write overflow in make_secret() and a denial of service.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
3.305

Associated Vulnerability

VulnerabilityOS Platform
high-performance and highly configurable RADIUS server (USN-3316-1) freeradius_3.0.12+dfsg-4ubuntu1.2_i386.debLinux
high-performance and highly configurable RADIUS server (USN-3316-1) freeradius_3.0.12+dfsg-4ubuntu1.2_amd64.debLinux
high-performance and highly configurable RADIUS server (USN-3369-1) freeradius_3.0.12+dfsg-4ubuntu1.2_i386.debLinux
Freeradius security update (CESA-2017:1759) freeradius-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-krb5-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-krb5-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-ldap-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-ldap-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-perl-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-perl-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-mysql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-mysql-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-utils-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-utils-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-python-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-python-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-unixODBC-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-unixODBC-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-postgresql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-postgresql-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-krb5-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-krb5-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-ldap-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-ldap-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-mysql-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-mysql-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-perl-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-perl-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-postgresql-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-postgresql-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-python-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-python-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-unixODBC-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-unixODBC-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-utils-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-utils-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-devel-3.0.13-8.el7_4.i686.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-devel-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-doc-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-krb5-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-ldap-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-mysql-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-perl-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-postgresql-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-python-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-sqlite-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-unixODBC-3.0.13-8.el7_4.x86_64.rpmLinux
(RHSA-2017:2389) Important: freeradius security update freeradius-utils-3.0.13-8.el7_4.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-debugsource-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-doc-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-krb5-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-krb5-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-ldap-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-ldap-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-libs-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-libs-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-mysql-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-mysql-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-perl-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-perl-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-postgresql-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-postgresql-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-python-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-python-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-sqlite-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-sqlite-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-utils-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2202-1(SUSE Linux Enterprise Server 12-SP3 ) freeradius-server-utils-debuginfo-3.0.15-2.3.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-debugsource-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-doc-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-krb5-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-krb5-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-ldap-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-ldap-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-libs-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-libs-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-mysql-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-mysql-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-perl-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-perl-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-postgresql-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-postgresql-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-python-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-python-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-sqlite-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-sqlite-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-utils-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2243-1(SUSE Linux Enterprise Server 12-SP2 ) freeradius-server-utils-debuginfo-3.0.3-17.9.1.x86_64.rpmLinux
SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-2.1.1-7.25.3.1.x86_64.rpmLinux
SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-dialupadmin-2.1.1-7.25.3.1.x86_64.rpmLinux
SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-doc-2.1.1-7.25.3.1.x86_64.rpmLinux
SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-libs-2.1.1-7.25.3.1.x86_64.rpmLinux
SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-utils-2.1.1-7.25.3.1.x86_64.rpmLinux
Freeradius update (ELSA-2017-1759) freeradius-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-krb5 update (ELSA-2017-1759) freeradius-krb5-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-ldap update (ELSA-2017-1759) freeradius-ldap-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-mysql update (ELSA-2017-1759) freeradius-mysql-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-perl update (ELSA-2017-1759) freeradius-perl-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-postgresql update (ELSA-2017-1759) freeradius-postgresql-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-python update (ELSA-2017-1759) freeradius-python-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-unixODBC update (ELSA-2017-1759) freeradius-unixODBC-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-utils update (ELSA-2017-1759) freeradius-utils-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius update (ELSA-2017-1759) freeradius-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-krb5 update (ELSA-2017-1759) freeradius-krb5-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-ldap update (ELSA-2017-1759) freeradius-ldap-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-mysql update (ELSA-2017-1759) freeradius-mysql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-perl update (ELSA-2017-1759) freeradius-perl-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-postgresql update (ELSA-2017-1759) freeradius-postgresql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-python update (ELSA-2017-1759) freeradius-python-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-unixODBC update (ELSA-2017-1759) freeradius-unixODBC-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-utils update (ELSA-2017-1759) freeradius-utils-2.2.6-7.el6_9.i686.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234