CVE-2010-3696
published 2010-10-07CVE-2010-3696: The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.62%
73.4th percentile
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 2.1.10+dfsg-1 (bookworm) | freeradius 2.1.10+dfsg-1 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63v7-hqpp-9687: The fr_dhcp_decode function in lib/dhcp
ghsa_unreviewed·2022-05-17
CVE-2010-3696 [MEDIUM] GHSA-63v7-hqpp-9687: The fr_dhcp_decode function in lib/dhcp
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
OSV
CVE-2010-3696: The fr_dhcp_decode function in lib/dhcp
osv·2010-10-07·CVSS 4.3
CVE-2010-3696 [MEDIUM] CVE-2010-3696: The fr_dhcp_decode function in lib/dhcp
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
Red Hat
freeradius: DoS via certain DHCP requests
vendor_redhat·2010-05-30·CVSS 4.3
CVE-2010-3696 [MEDIUM] freeradius: DoS via certain DHCP requests
freeradius: DoS via certain DHCP requests
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
Statement: Not vulnerable. This issue did not affect the versions of freeradius as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Package: freeradius (Red Hat Enterprise Linux 4) - Not affected
Package: freeradius (Red Hat Enterprise Linux 5) - Not affected
Package: freeradius (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-3696: freeradius - The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-de...
vendor_debian·2010·CVSS 4.3
CVE-2010-3696 [MEDIUM] CVE-2010-3696: freeradius - The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-de...
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 2.1.10+dfsg-1)
bullseye: resolved (fixed in 2.1.10+dfsg-1)
forky: resolved (fixed in 2.1.10+dfsg-1)
sid: resolved (fixed in 2.1.10+dfsg-1)
trixie: resolved (fixed in 2.1.10+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3696 freeradius: DoS via certain DHCP requests
bugzilla·2010-10-01·CVSS 4.3
CVE-2010-3696 [MEDIUM] CVE-2010-3696 freeradius: DoS via certain DHCP requests
CVE-2010-3696 freeradius: DoS via certain DHCP requests
It was reported [1],[2] that an error when processing DHCP requests with the 'Relay Agent Information' option (82) in src/lib/dhcp.c could be exploited to cause an infinite loop, in the process denying further requests via a packet with multiple sub-options.
According to the upstream report, this flaw seems to only affect 2.1.9 and was fixed [3] in 2.1.10.
[1] https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=77
[2] http://secunia.com/advisories/41621
[3] http://github.com/alandekok/freeradius-server/commit/4dc7800b866f889a1247685bbaa6dd4238a56279
The offending file (dhcp.c) is not present in the version of freeradius as provided with Red Hat Enterprise Linux 5 (1.1.3).
Discussion:
This issue has been assigned the name CVE-20
Bugzilla
CVE-2010-3696 CVE-2010-3697 freeradius various flaws [fedora-all]
bugzilla·2010-10-01·CVSS 4.3
CVE-2010-3696 [MEDIUM] CVE-2010-3696 CVE-2010-3697 freeradius various flaws [fedora-all]
CVE-2010-3696 CVE-2010-3697 freeradius various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=639390
Please note: this issue affects multiple supporte
http://freeradius.org/press/index.html#2.1.10http://github.com/alandekok/freeradius-server/commit/4dc7800b866f889a1247685bbaa6dd4238a56279http://secunia.com/advisories/41621http://www.openwall.com/lists/oss-security/2010/10/01/3http://www.openwall.com/lists/oss-security/2010/10/01/8https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=77https://bugzilla.redhat.com/show_bug.cgi?id=639390http://freeradius.org/press/index.html#2.1.10http://github.com/alandekok/freeradius-server/commit/4dc7800b866f889a1247685bbaa6dd4238a56279http://secunia.com/advisories/41621http://www.openwall.com/lists/oss-security/2010/10/01/3http://www.openwall.com/lists/oss-security/2010/10/01/8https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=77https://bugzilla.redhat.com/show_bug.cgi?id=639390
2010-10-07
Published