CVE-2010-3696
Published: 7 October 2010
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
Notes
Author | Note |
---|---|
sbeattie | According to Vincent Danen, it may only affect 2.1.9 |
mdeslaur | Code not enabled by default, upstream has disputed CVE |
Priority
Status
Package | Release | Status |
---|---|---|
freeradius Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(pre 2.1)
|
hardy |
Not vulnerable
(pre 2.1)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Not vulnerable
(code not present)
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Not vulnerable
(2.1.10+dfsg-2ubuntu2)
|
|
oneiric |
Not vulnerable
(2.1.10+dfsg-2ubuntu2)
|
|
precise |
Not vulnerable
(2.1.10+dfsg-2ubuntu2)
|
|
upstream |
Released
(2.1.10)
|