CVE-2007-2028
published 2007-04-13CVE-2007-2028: Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.48%
82.9th percentile
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 1.1.6-1 (bookworm) | freeradius 1.1.6-1 (bookworm) |
| freeradius | freeradius | <= 1.1.5 | — |
| freeradius | freeradius | >= 0 < 1.1.6-1 | 1.1.6-1 |
| freeradius | freeradius | >= 0 < 1.1.6-1 | 1.1.6-1 |
| freeradius | freeradius | >= 0 < 1.1.6-1 | 1.1.6-1 |
| freeradius | freeradius | >= 0 < 1.1.6-1 | 1.1.6-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pmm2-rpqr-7h29: Memory leak in freeRADIUS 1
ghsa_unreviewed·2022-05-01
CVE-2007-2028 [MEDIUM] GHSA-pmm2-rpqr-7h29: Memory leak in freeRADIUS 1
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
OSV
CVE-2007-2028: Memory leak in freeRADIUS 1
osv·2007-04-13·CVSS 5.0
CVE-2007-2028 [MEDIUM] CVE-2007-2028: Memory leak in freeRADIUS 1
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
Red Hat
security flaw
vendor_redhat·2007-04-12·CVSS 5.0
CVE-2007-2028 [MEDIUM] security flaw
security flaw
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
Debian
CVE-2007-2028: freeradius - Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a d...
vendor_debian·2007·CVSS 5.0
CVE-2007-2028 [MEDIUM] CVE-2007-2028: freeradius - Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a d...
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
Scope: local
bookworm: resolved (fixed in 1.1.6-1)
bullseye: resolved (fixed in 1.1.6-1)
forky: resolved (fixed in 1.1.6-1)
sid: resolved (fixed in 1.1.6-1)
trixie: resolved (fixed in 1.1.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-2028 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2007-2028 [MEDIUM] CVE-2007-2028 security flaw
CVE-2007-2028 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
Bugzilla
CVE-2007-2028 Freeradius EAP-TTLS denial of service
bugzilla·2007-04-12·CVSS 5.0
CVE-2007-2028 [MEDIUM] CVE-2007-2028 Freeradius EAP-TTLS denial of service
CVE-2007-2028 Freeradius EAP-TTLS denial of service
A flaw was found in the way FreeRADIUS parses certain authentication requests.
The upstream description explain it as such:
http://www.freeradius.org/security.html
2007.04.10 v1.1.5, and earlier - A malicous 802.1x supplicant could send
malformed Diameter format attributes inside of an EAP-TTLS tunnel. The
server would reject the authentication request, but would leak one
VALUE_PAIR data structure, of approximately 300 bytes. If an attacker
performed the attack many times (e.g. thousands or more over a period of
minutes to hours), the server could leak megabytes of memory, potentially
leading to an "out of memory" condition, and early process exit.
We recommend that administrators using EAP-TTLS upgrade immediately.
This bug was found
Bugzilla
CVE-2007-2028 Freeradius EAP-TTLS denial of service
bugzilla·2007-04-12·CVSS 5.0
CVE-2007-2028 [MEDIUM] CVE-2007-2028 Freeradius EAP-TTLS denial of service
CVE-2007-2028 Freeradius EAP-TTLS denial of service
+++ This bug was initially created as a clone of Bug #236247 +++
A flaw was found in the way FreeRADIUS parses certain authentication requests.
The upstream description explain it as such:
http://www.freeradius.org/security.html
2007.04.10 v1.1.5, and earlier - A malicous 802.1x supplicant could send
malformed Diameter format attributes inside of an EAP-TTLS tunnel. The
server would reject the authentication request, but would leak one
VALUE_PAIR data structure, of approximately 300 bytes. If an attacker
performed the attack many times (e.g. thousands or more over a period of
minutes to hours), the server could leak megabytes of memory, potentially
leading to an "out of memory" condition, and early process exit.
We recommend that admi
http://rhn.redhat.com/errata/RHSA-2007-0338.htmlhttp://secunia.com/advisories/24849http://secunia.com/advisories/24907http://secunia.com/advisories/24917http://secunia.com/advisories/24996http://secunia.com/advisories/25201http://secunia.com/advisories/25220http://security.gentoo.org/glsa/glsa-200704-14.xmlhttp://www.freeradius.org/security.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:085http://www.novell.com/linux/security/advisories/2007_10_sr.htmlhttp://www.securityfocus.com/bid/23466http://www.securitytracker.com/id?1018042http://www.trustix.org/errata/2007/0013/http://www.vupen.com/english/advisories/2007/1369https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11156http://rhn.redhat.com/errata/RHSA-2007-0338.htmlhttp://secunia.com/advisories/24849http://secunia.com/advisories/24907http://secunia.com/advisories/24917http://secunia.com/advisories/24996http://secunia.com/advisories/25201http://secunia.com/advisories/25220http://security.gentoo.org/glsa/glsa-200704-14.xmlhttp://www.freeradius.org/security.htmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2007:085http://www.novell.com/linux/security/advisories/2007_10_sr.htmlhttp://www.securityfocus.com/bid/23466http://www.securitytracker.com/id?1018042http://www.trustix.org/errata/2007/0013/http://www.vupen.com/english/advisories/2007/1369https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11156
2007-04-13
Published