CVE-2006-4181
published 2006-11-28CVE-2006-4181: Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute…
PriorityP345critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.00%
91.2th percentile
Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | radius | — | — |
| gnu | radius | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wpp6-rjff-897j: Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1
ghsa_unreviewed·2022-05-01
CVE-2006-4181 [HIGH] GHSA-wpp6-rjff-897j: Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1
Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.
Red Hat
CVE-2006-4181: Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1
vendor_redhat·CVSS 10.0
CVE-2006-4181 [CRITICAL] CVE-2006-4181: Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1
Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.
Statement: Not Vulnerable. Red Hat does not ship GNU Radius in Red Hat Enterprise Linux 2.1, 3, or 4.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=443http://secunia.com/advisories/23087http://security.gentoo.org/glsa/glsa-200612-17.xmlhttp://securitytracker.com/id?1017285http://www.securityfocus.com/bid/21303http://www.vupen.com/english/advisories/2006/4712https://exchange.xforce.ibmcloud.com/vulnerabilities/30508http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=443http://secunia.com/advisories/23087http://security.gentoo.org/glsa/glsa-200612-17.xmlhttp://securitytracker.com/id?1017285http://www.securityfocus.com/bid/21303http://www.vupen.com/english/advisories/2006/4712https://exchange.xforce.ibmcloud.com/vulnerabilities/30508
2006-11-28
Published