CVE-2017-10980

Description

An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows DHCP - Memory leak in decode_tlv() and a denial of service.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.594

Associated Vulnerability

VulnerabilityOS Platform
high-performance and highly configurable RADIUS server (USN-3316-1) freeradius_3.0.12+dfsg-4ubuntu1.2_i386.debLinux
high-performance and highly configurable RADIUS server (USN-3316-1) freeradius_3.0.12+dfsg-4ubuntu1.2_amd64.debLinux
high-performance and highly configurable RADIUS server (USN-3369-1) freeradius_3.0.12+dfsg-4ubuntu1.2_i386.debLinux
Freeradius security update (CESA-2017:1759) freeradius-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-krb5-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-krb5-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-ldap-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-ldap-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-perl-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-perl-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-mysql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-mysql-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-utils-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-utils-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-python-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-python-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-unixODBC-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-unixODBC-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-postgresql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius security update (CESA-2017:1759) freeradius-postgresql-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-krb5-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-krb5-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-ldap-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-ldap-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-mysql-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-mysql-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-perl-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-perl-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-postgresql-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-postgresql-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-python-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-python-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-unixODBC-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-unixODBC-2.2.6-7.el6_9.x86_64.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-utils-2.2.6-7.el6_9.i686.rpmLinux
(RHSA-2017:1759) Important: freeradius security update freeradius-utils-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius update (ELSA-2017-1759) freeradius-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-krb5 update (ELSA-2017-1759) freeradius-krb5-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-ldap update (ELSA-2017-1759) freeradius-ldap-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-mysql update (ELSA-2017-1759) freeradius-mysql-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-perl update (ELSA-2017-1759) freeradius-perl-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-postgresql update (ELSA-2017-1759) freeradius-postgresql-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-python update (ELSA-2017-1759) freeradius-python-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-unixODBC update (ELSA-2017-1759) freeradius-unixODBC-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius-utils update (ELSA-2017-1759) freeradius-utils-2.2.6-7.el6_9.x86_64.rpmLinux
Freeradius update (ELSA-2017-1759) freeradius-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-krb5 update (ELSA-2017-1759) freeradius-krb5-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-ldap update (ELSA-2017-1759) freeradius-ldap-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-mysql update (ELSA-2017-1759) freeradius-mysql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-perl update (ELSA-2017-1759) freeradius-perl-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-postgresql update (ELSA-2017-1759) freeradius-postgresql-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-python update (ELSA-2017-1759) freeradius-python-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-unixODBC update (ELSA-2017-1759) freeradius-unixODBC-2.2.6-7.el6_9.i686.rpmLinux
Freeradius-utils update (ELSA-2017-1759) freeradius-utils-2.2.6-7.el6_9.i686.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234