CVE-2010-3697
published 2010-10-07CVE-2010-3697: The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.21%
80.7th percentile
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freeradius | < freeradius 2.1.10+dfsg-1 (bookworm) | freeradius 2.1.10+dfsg-1 (bookworm) |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | — | — |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
| freeradius | freeradius | >= 0 < 2.1.10+dfsg-1 | 2.1.10+dfsg-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
freeradius: crash when processing requests queued for more than 30 seconds
vendor_redhat·2010-05-30·CVSS 4.3
CVE-2010-3697 [MEDIUM] freeradius: crash when processing requests queued for more than 30 seconds
freeradius: crash when processing requests queued for more than 30 seconds
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
Statement: Red Hat does not consider this to a security issue. In order for the crash condition to be observed, the RADIUS server must already be unresponsive for extended periods of time, the net result of which is that you cannot DoS an already-unresponsive server. Other specialized conditions are required as well, that make an attack using this flaw unviable.
Package: freeradius (Red Hat Enterprise Linux 4) - N
Debian
CVE-2010-3697: freeradius - The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2....
vendor_debian·2010·CVSS 4.3
CVE-2010-3697 [MEDIUM] CVE-2010-3697: freeradius - The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2....
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
Scope: local
bookworm: resolved (fixed in 2.1.10+dfsg-1)
bullseye: resolved (fixed in 2.1.10+dfsg-1)
forky: resolved (fixed in 2.1.10+dfsg-1)
sid: resolved (fixed in 2.1.10+dfsg-1)
trixie: resolved (fixed in 2.1.10+dfsg-1)
GHSA
GHSA-v8vm-3fjp-pgmg: The wait_for_child_to_die function in main/event
ghsa_unreviewed·2022-05-17
CVE-2010-3697 [MEDIUM] GHSA-v8vm-3fjp-pgmg: The wait_for_child_to_die function in main/event
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
OSV
CVE-2010-3697: The wait_for_child_to_die function in main/event
osv·2010-10-07·CVSS 4.3
CVE-2010-3697 [MEDIUM] CVE-2010-3697: The wait_for_child_to_die function in main/event
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3697 freeradius: crash when processing requests queued for more than 30 seconds
bugzilla·2010-10-01·CVSS 4.3
CVE-2010-3697 [MEDIUM] CVE-2010-3697 freeradius: crash when processing requests queued for more than 30 seconds
CVE-2010-3697 freeradius: crash when processing requests queued for more than 30 seconds
It was reported [1],[2] that an error when processing requests queued for more than 30 seconds in src/main/event.c could be exploited to cause the process to crash by sending a large number of requests for an extended period of time.
This flaw seems to only affect 2.1.x and was fixed [3] in 2.1.10.
[1] https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=35
[2] http://secunia.com/advisories/41621
[3] http://github.com/alandekok/freeradius-server/commit/ff94dd35673bba1476594299d31ce8293b8bd223
The offending file (event.c), nor the affected function (wait_for_child_to_die()) are not present in the version of freeradius as provided with Red Hat Enterprise Linux 5 (1.1.3).
Discussion:
This issue has
Bugzilla
CVE-2010-3696 CVE-2010-3697 freeradius various flaws [fedora-all]
bugzilla·2010-10-01·CVSS 4.3
CVE-2010-3696 [MEDIUM] CVE-2010-3696 CVE-2010-3697 freeradius various flaws [fedora-all]
CVE-2010-3696 CVE-2010-3697 freeradius various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=639390
Please note: this issue affects multiple supporte
http://freeradius.org/press/index.html#2.1.10http://github.com/alandekok/freeradius-server/commit/ff94dd35673bba1476594299d31ce8293b8bd223http://secunia.com/advisories/41621http://www.openwall.com/lists/oss-security/2010/10/01/3http://www.openwall.com/lists/oss-security/2010/10/01/8https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=35https://bugzilla.redhat.com/show_bug.cgi?id=639397http://freeradius.org/press/index.html#2.1.10http://github.com/alandekok/freeradius-server/commit/ff94dd35673bba1476594299d31ce8293b8bd223http://secunia.com/advisories/41621http://www.openwall.com/lists/oss-security/2010/10/01/3http://www.openwall.com/lists/oss-security/2010/10/01/8https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=35https://bugzilla.redhat.com/show_bug.cgi?id=639397
2010-10-07
Published