CVE-2017-10982
Description
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows DHCP - Buffer over-read in fr_dhcp_decode_options() and a denial of service.
Risk Information
Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
1.42
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| high-performance and highly configurable RADIUS server (USN-3316-1) freeradius_3.0.12+dfsg-4ubuntu1.2_i386.deb | Linux |
| high-performance and highly configurable RADIUS server (USN-3316-1) freeradius_3.0.12+dfsg-4ubuntu1.2_amd64.deb | Linux |
| high-performance and highly configurable RADIUS server (USN-3369-1) freeradius_3.0.12+dfsg-4ubuntu1.2_i386.deb | Linux |
| SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-2.1.1-7.25.3.1.x86_64.rpm | Linux |
| SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-dialupadmin-2.1.1-7.25.3.1.x86_64.rpm | Linux |
| SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-doc-2.1.1-7.25.3.1.x86_64.rpm | Linux |
| SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-libs-2.1.1-7.25.3.1.x86_64.rpm | Linux |
| SUSE-SU-2017:2244-1(SUSE Linux Enterprise Server 11-SP4 ) freeradius-server-utils-2.1.1-7.25.3.1.x86_64.rpm | Linux |
| Freeradius update (ELSA-2017-1759) freeradius-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-krb5 update (ELSA-2017-1759) freeradius-krb5-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-ldap update (ELSA-2017-1759) freeradius-ldap-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-mysql update (ELSA-2017-1759) freeradius-mysql-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-perl update (ELSA-2017-1759) freeradius-perl-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-postgresql update (ELSA-2017-1759) freeradius-postgresql-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-python update (ELSA-2017-1759) freeradius-python-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-unixODBC update (ELSA-2017-1759) freeradius-unixODBC-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius-utils update (ELSA-2017-1759) freeradius-utils-2.2.6-7.el6_9.x86_64.rpm | Linux |
| Freeradius update (ELSA-2017-1759) freeradius-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-krb5 update (ELSA-2017-1759) freeradius-krb5-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-ldap update (ELSA-2017-1759) freeradius-ldap-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-mysql update (ELSA-2017-1759) freeradius-mysql-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-perl update (ELSA-2017-1759) freeradius-perl-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-postgresql update (ELSA-2017-1759) freeradius-postgresql-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-python update (ELSA-2017-1759) freeradius-python-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-unixODBC update (ELSA-2017-1759) freeradius-unixODBC-2.2.6-7.el6_9.i686.rpm | Linux |
| Freeradius-utils update (ELSA-2017-1759) freeradius-utils-2.2.6-7.el6_9.i686.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234