CVE-2015-8762
Published: 27 March 2017
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.
Notes
Author | Note |
---|---|
sbeattie | EAP-PWD module not enabled in default configuration |
mdeslaur | 3.0+ only |
Priority
CVSS 3 base score: 5.9
Status
Package | Release | Status |
---|---|---|
freeradius Launchpad, Ubuntu, Debian |
upstream |
Needs triage
|
precise |
Not vulnerable
|
|
trusty |
Does not exist
(trusty was not-affected)
|
|
vivid |
Not vulnerable
|
|
wily |
Not vulnerable
|