CVE-2006-1354
published 2006-03-22CVE-2006-1354: Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via…
PriorityP432high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.76%
84.6th percentile
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 1.1.0-1.2 (bookworm) | freeradius 1.1.0-1.2 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 1.1.0-1.2 | 1.1.0-1.2 |
| freeradius | freeradius | >= 0 < 1.1.0-1.2 | 1.1.0-1.2 |
| freeradius | freeradius | >= 0 < 1.1.0-1.2 | 1.1.0-1.2 |
| freeradius | freeradius | >= 0 < 1.1.0-1.2 | 1.1.0-1.2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2006-03-20·CVSS 7.5
CVE-2006-1354 [HIGH] security flaw
security flaw
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
Debian
CVE-2006-1354: freeradius - Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attacker...
vendor_debian·2006·CVSS 7.5
CVE-2006-1354 [HIGH] CVE-2006-1354: freeradius - Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attacker...
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
Scope: local
bookworm: resolved (fixed in 1.1.0-1.2)
bullseye: resolved (fixed in 1.1.0-1.2)
forky: resolved (fixed in 1.1.0-1.2)
sid: resolved (fixed in 1.1.0-1.2)
trixie: resolved (fixed in 1.1.0-1.2)
GHSA
GHSA-778m-hp9h-2cxq: Unspecified vulnerability in FreeRADIUS 1
ghsa_unreviewed·2022-05-03
CVE-2006-1354 [HIGH] GHSA-778m-hp9h-2cxq: Unspecified vulnerability in FreeRADIUS 1
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
OSV
CVE-2006-1354: Unspecified vulnerability in FreeRADIUS 1
osv·2006-03-22·CVSS 7.5
CVE-2006-1354 [HIGH] CVE-2006-1354: Unspecified vulnerability in FreeRADIUS 1
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2006-1354 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2006-1354 [HIGH] CVE-2006-1354 security flaw
CVE-2006-1354 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
Bugzilla
CVE-2006-1354 FreeRADIUS authentication bypass
bugzilla·2006-10-20·CVSS 7.5
CVE-2006-1354 [HIGH] CVE-2006-1354 FreeRADIUS authentication bypass
CVE-2006-1354 FreeRADIUS authentication bypass
This appears to also affect FC4.
+++ This bug was initially created as a clone of Bug #211653 +++
+++ This bug was initially created as a clone of Bug #186083 +++
FreeRADIUS authentication bypass
A bug in the EAP-MSCHAPv2 module could allow an attacker to
improperly authenticate as an aribitrary user.
http://www.freeradius.org/security.html
This issue also affects RHEL3
-- Additional comment from [email protected] on 2006-03-21 10:28 EST --
Created an attachment (id=126403)
Patch from upstream CVS
-- Additional comment from [email protected] on 2006-04-04 04:45 EST --
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more
Bugzilla
CVE-2006-1354 FreeRADIUS authentication bypass
bugzilla·2006-10-20·CVSS 7.5
CVE-2006-1354 [HIGH] CVE-2006-1354 FreeRADIUS authentication bypass
CVE-2006-1354 FreeRADIUS authentication bypass
This appears to also affect FC3.
+++ This bug was initially created as a clone of Bug #186083 +++
FreeRADIUS authentication bypass
A bug in the EAP-MSCHAPv2 module could allow an attacker to
improperly authenticate as an aribitrary user.
http://www.freeradius.org/security.html
This issue also affects RHEL3
-- Additional comment from [email protected] on 2006-03-21 10:28 EST --
Created an attachment (id=126403)
Patch from upstream CVS
-- Additional comment from [email protected] on 2006-04-04 04:45 EST --
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated fil
Bugzilla
CVE-2006-1354 FreeRADIUS authentication bypass
bugzilla·2006-03-21·CVSS 7.5
CVE-2006-1354 [HIGH] CVE-2006-1354 FreeRADIUS authentication bypass
CVE-2006-1354 FreeRADIUS authentication bypass
FreeRADIUS authentication bypass
A bug in the EAP-MSCHAPv2 module could allow an attacker to
improperly authenticate as an aribitrary user.
http://www.freeradius.org/security.html
This issue also affects FC4
Discussion:
Attachment 126403 is the upstream fix from CVS.
---
FC-5 is EOL - closing
Bugzilla
CVE-2006-1354 FreeRADIUS authentication bypass
bugzilla·2006-03-21·CVSS 7.5
CVE-2006-1354 [HIGH] CVE-2006-1354 FreeRADIUS authentication bypass
CVE-2006-1354 FreeRADIUS authentication bypass
FreeRADIUS authentication bypass
A bug in the EAP-MSCHAPv2 module could allow an attacker to
improperly authenticate as an aribitrary user.
http://www.freeradius.org/security.html
This issue also affects RHEL3
Discussion:
Created attachment 126403
Patch from upstream CVS
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0271.html
ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.aschttp://lists.suse.de/archive/suse-security-announce/2006-Mar/0009.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0271.htmlhttp://secunia.com/advisories/19300http://secunia.com/advisories/19405http://secunia.com/advisories/19518http://secunia.com/advisories/19527http://secunia.com/advisories/19811http://secunia.com/advisories/20461http://securitytracker.com/id?1015795http://www.debian.org/security/2006/dsa-1089http://www.freeradius.org/security.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200604-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:060http://www.securityfocus.com/bid/17171http://www.trustix.org/errata/2006/0020http://www.vupen.com/english/advisories/2006/1016https://exchange.xforce.ibmcloud.com/vulnerabilities/25352https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10156ftp://patches.sgi.com/support/free/security/advisories/20060404-01-U.aschttp://lists.suse.de/archive/suse-security-announce/2006-Mar/0009.htmlhttp://rhn.redhat.com/errata/RHSA-2006-0271.htmlhttp://secunia.com/advisories/19300http://secunia.com/advisories/19405http://secunia.com/advisories/19518http://secunia.com/advisories/19527http://secunia.com/advisories/19811http://secunia.com/advisories/20461http://securitytracker.com/id?1015795http://www.debian.org/security/2006/dsa-1089http://www.freeradius.org/security.htmlhttp://www.gentoo.org/security/en/glsa/glsa-200604-03.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2006:060http://www.securityfocus.com/bid/17171http://www.trustix.org/errata/2006/0020http://www.vupen.com/english/advisories/2006/1016https://exchange.xforce.ibmcloud.com/vulnerabilities/25352https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10156
2006-03-22
Published