cbcvebase.
CVE-2017-10978
published 2017-07-17

CVE-2017-10978: An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.

Affected

25 ranges
VendorProductVersion rangeFixed in
applemacos_server
debiandebian_linux
debiandebian_linux
debianfreeradius< freeradius 3.0.15+dfsg-1 (bookworm)freeradius 3.0.15+dfsg-1 (bookworm)
freeradiusfreeradius>= 0 < 3.0.15+dfsg-13.0.15+dfsg-1
freeradiusfreeradius>= 0 < 3.0.15+dfsg-13.0.15+dfsg-1
freeradiusfreeradius>= 0 < 3.0.15+dfsg-13.0.15+dfsg-1
freeradiusfreeradius>= 0 < 3.0.15+dfsg-13.0.15+dfsg-1
freeradiusfreeradius>= 2.0 < 2.2.102.2.10
freeradiusfreeradius>= 3.0.0 < 3.0.153.0.15
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
redhatenterprise_linux_workstation

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH