CVE-2004-0961
published 2005-02-09CVE-2004-0961: Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1)…
PriorityP419medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.26%
87.0th percentile
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 1.0.1 (bookworm) | freeradius 1.0.1 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 1.0.1 | 1.0.1 |
| freeradius | freeradius | >= 0 < 1.0.1 | 1.0.1 |
| freeradius | freeradius | >= 0 < 1.0.1 | 1.0.1 |
| freeradius | freeradius | >= 0 < 1.0.1 | 1.0.1 |
| redhat | enterprise_linux | — | — |
| redhat | fedora_core | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x6x8-7c65-c9gg: Memory leak in FreeRADIUS before 1
ghsa_unreviewed·2022-04-29
CVE-2004-0961 [MEDIUM] GHSA-x6x8-7c65-c9gg: Memory leak in FreeRADIUS before 1
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
OSV
CVE-2004-0961: Memory leak in FreeRADIUS before 1
osv·2005-02-09·CVSS 5.0
CVE-2004-0961 [MEDIUM] CVE-2004-0961: Memory leak in FreeRADIUS before 1
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
Red Hat
security flaw
vendor_redhat·2004-09-20·CVSS 5.0
CVE-2004-0961 [MEDIUM] security flaw
security flaw
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
Debian
CVE-2004-0961: freeradius - Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial...
vendor_debian·2004·CVSS 5.0
CVE-2004-0961 [MEDIUM] CVE-2004-0961: freeradius - Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial...
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
Scope: local
bookworm: resolved (fixed in 1.0.1)
bullseye: resolved (fixed in 1.0.1)
forky: resolved (fixed in 1.0.1)
sid: resolved (fixed in 1.0.1)
trixie: resolved (fixed in 1.0.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-0961 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2004-0961 [MEDIUM] CVE-2004-0961 security flaw
CVE-2004-0961 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
Bugzilla
CAN-2004-0938 Freeradius < 1.0.1 DoS and remote crash (CAN-2004-0960, CAN-2004-0961)
bugzilla·2004-10-15
[HIGH] CAN-2004-0938 Freeradius < 1.0.1 DoS and remote crash (CAN-2004-0960, CAN-2004-0961)
CAN-2004-0938 Freeradius < 1.0.1 DoS and remote crash (CAN-2004-0960, CAN-2004-0961)
Description of problem:
Remote Denial Of Service, and remote crash by sending malformed packets.
Version-Release number of selected component (if applicable):
All version of Freeradius prior to version 1.0.1 (to check)
From the freeradius ChangeLog:
FreeRADIUS 1.0.1 ; $Date: 2004/09/02 10:52:03 $, urgency=high
Denial-of-Service Security Fix
* Fix two remote crashes and a memory leak in RADIUS packet
decoding.
No CAN numbers have been associated with this issue:
http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=freeradius
Discussion:
http://www.kb.cert.org/vuls/id/541574
http://secunia.com/advisories/12570/
Removing security-sensitive tag as this issue is public.
---
RHSA-2004:609 in progress which w
http://security.gentoo.org/glsa/glsa-200409-29.xmlhttp://www.kb.cert.org/vuls/id/541574http://www.securityfocus.com/bid/11222https://exchange.xforce.ibmcloud.com/vulnerabilities/17440https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10024http://security.gentoo.org/glsa/glsa-200409-29.xmlhttp://www.kb.cert.org/vuls/id/541574http://www.securityfocus.com/bid/11222https://exchange.xforce.ibmcloud.com/vulnerabilities/17440https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10024
2005-02-09
Published