CVE-2005-4744
published 2005-12-31CVE-2005-4744: Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers…
PriorityP425medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
4.38%
90.2th percentile
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 1.0.5-1 (bookworm) | freeradius 1.0.5-1 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
| freeradius | freeradius | >= 0 < 1.0.5-1 | 1.0.5-1 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5382-qx5c-8j6g: Off-by-one error in the sql_error function in sql_unixodbc
ghsa_unreviewed·2022-05-03
CVE-2005-4744 [MEDIUM] GHSA-5382-qx5c-8j6g: Off-by-one error in the sql_error function in sql_unixodbc
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
OSV
CVE-2005-4744: Off-by-one error in the sql_error function in sql_unixodbc
osv·2005-12-31·CVSS 6.4
CVE-2005-4744 [MEDIUM] CVE-2005-4744: Off-by-one error in the sql_error function in sql_unixodbc
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
Red Hat
security flaw
vendor_redhat·2005-09-09·CVSS 6.4
CVE-2005-4744 [MEDIUM] security flaw
security flaw
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
Debian
CVE-2005-4744: freeradius - Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2...
vendor_debian·2005·CVSS 6.4
CVE-2005-4744 [MEDIUM] CVE-2005-4744: freeradius - Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2...
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
Scope: local
bookworm: resolved (fixed in 1.0.5-1)
bullseye: resolved (fixed in 1.0.5-1)
forky: resolved (fixed in 1.0.5-1)
sid: resol
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-4744 security flaw
bugzilla·2018-08-16·CVSS 6.4
CVE-2005-4744 [MEDIUM] CVE-2005-4744 security flaw
CVE-2005-4744 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regar
Bugzilla
CVE-2005-4744 Multiple freeradius security issues
bugzilla·2005-09-06·CVSS 6.4
CVE-2005-4744 [MEDIUM] CVE-2005-4744 Multiple freeradius security issues
CVE-2005-4744 Multiple freeradius security issues
+++ This bug was initially created as a clone of Bug #167676 +++
A number of issues have been found in freeradius:
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/lib/token.c.diff?r1=1.17&r2=1.18
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/modules/rlm_sql/drivers/rlm_sql_unixodbc/sql_unixodbc.c.diff?r1=1.13&r2=1.14
* moderate
Off by one error (\0 being written to end of string, probably not even a crash)
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/main/session.c.diff?r1=1.27&r2=1.28
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/modules/rlm_exec/exec.c.diff?r1=1.2&r2=1.3
* low
Use per-system max fd to close, rather than hard-coded number
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/s
Bugzilla
CVE-2005-4744 Multiple freeradius security issues
bugzilla·2005-09-06·CVSS 6.4
CVE-2005-4744 [MEDIUM] CVE-2005-4744 Multiple freeradius security issues
CVE-2005-4744 Multiple freeradius security issues
A number of issues have been found in freeradius:
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/lib/token.c.diff?r1=1.17&r2=1.18
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/modules/rlm_sql/drivers/rlm_sql_unixodbc/sql_unixodbc.c.diff?r1=1.13&r2=1.14
* moderate
Off by one error (\0 being written to end of string, probably not even a crash)
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/main/session.c.diff?r1=1.27&r2=1.28
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/modules/rlm_exec/exec.c.diff?r1=1.2&r2=1.3
* low
Use per-system max fd to close, rather than hard-coded number
http://www.freeradius.org/cgi-bin/cvsweb.cgi/radiusd/src/main/xlat.c.diff?r1=1.101&r2=1.102
* low
If strftime(3) returns
ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.aschttp://rhn.redhat.com/errata/RHSA-2006-0271.htmlhttp://secunia.com/advisories/16712http://secunia.com/advisories/19497http://secunia.com/advisories/19518http://secunia.com/advisories/19811http://secunia.com/advisories/20461http://www.debian.org/security/2006/dsa-1089http://www.freeradius.org/security/20050909-response-to-suse.txthttp://www.freeradius.org/security/20050909-vendor-sec.txthttp://www.securityfocus.com/bid/14775http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:066https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=167676https://exchange.xforce.ibmcloud.com/vulnerabilities/22211https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10449ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.aschttp://rhn.redhat.com/errata/RHSA-2006-0271.htmlhttp://secunia.com/advisories/16712http://secunia.com/advisories/19497http://secunia.com/advisories/19518http://secunia.com/advisories/19811http://secunia.com/advisories/20461http://www.debian.org/security/2006/dsa-1089http://www.freeradius.org/security/20050909-response-to-suse.txthttp://www.freeradius.org/security/20050909-vendor-sec.txthttp://www.securityfocus.com/bid/14775http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:066https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=167676https://exchange.xforce.ibmcloud.com/vulnerabilities/22211https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10449
2005-12-31
Published