Debian Freeradius vulnerabilities
41 known vulnerabilities affecting debian/freeradius.
Total CVEs
41
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH17MEDIUM9LOW9
Vulnerabilities
Page 1 of 3
CVE-2017-10986P2HIGHCVSS 7.5Exploitedfixed in freeradius 3.0.15+dfsg-1 (bookworm)2017
CVE-2017-10986 [HIGH] CVE-2017-10986: freeradius - An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read ...
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
Scope: local
bookworm: resolved (fixed in 3.0.15+dfsg-1)
bullseye: resolved (fixed in 3.0.15+dfsg-1)
forky: resolved (fixed in 3.0.15+dfsg-1)
sid: resolved (fixed in 3.0.15+dfsg-1)
trixie: resolved (fixed in 3.0.15+dfsg-1)
debian
CVE-2024-3596P2CRITICALCVSS 9.0fixed in freeradius 3.2.5+dfsg-1 (forky)2024
CVE-2024-3596 [CRITICAL] CVE-2024-3596: freeradius - RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local atta...
RADIUS Protocol under RFC 2865 is susceptible to forgery attacks by a local attacker who can modify any valid Response (Access-Accept, Access-Reject, or Access-Challenge) to any other response using a chosen-prefix collision attack against MD5 Response Authenticator signature.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 3.2.5+dfsg-1)
si
debian
CVE-2017-9148P3CRITICALCVSS 9.8fixed in freeradius 3.0.12+dfsg-5 (bookworm)2017
CVE-2017-9148 [CRITICAL] CVE-2017-9148: freeradius - The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3....
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.
Scope: local
bookworm: resolved (fixed in 3.0.12+dfs
debian
CVE-2019-11234P3CRITICALCVSS 9.8fixed in freeradius 3.0.17+dfsg-1.1 (bookworm)2019
CVE-2019-11234 [CRITICAL] CVE-2019-11234: freeradius - FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication s...
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
Scope: local
bookworm: resolved (fixed in 3.0.17+dfsg-1.1)
bullseye: resolved (fixed in 3.0.17+dfsg-1.1)
forky: resolved (fixed in 3.0.17+dfsg-1.1)
sid: resolved (fixed in 3.0.17+dfsg-1.1)
trixie: resolved (fixe
debian
CVE-2017-10979P3CRITICALCVSS 9.8fixed in freeradius 3.0.12+dfsg-3 (bookworm)2017
CVE-2017-10979 [CRITICAL] CVE-2017-10979: freeradius - An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad...
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 3.0.12+dfsg-3)
bullseye: resolved (fixed in 3.0.12+dfsg-3)
forky: resolved (fixed in 3.0.12+dfsg-3)
sid: resolved (
debian
CVE-2017-10984P3CRITICALCVSS 9.8fixed in freeradius 3.0.15+dfsg-1 (bookworm)2017
CVE-2017-10984 [CRITICAL] CVE-2017-10984: freeradius - An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in dat...
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 3.0.15+dfsg-1)
bullseye: resolved (fixed in 3.0.15+dfsg-1)
forky: resolved (fixed in 3.0.15+dfsg-1)
sid: resolved
debian
CVE-2009-3111P4LOWCVSS 5.0PoCfixed in freeradius 2.0.0-1 (bookworm)2009
CVE-2009-3111 [MEDIUM] CVE-2009-3111: freeradius - The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to ca...
The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.
Scope: local
bookworm: resolved (fixed in 2.0.0-1)
bullse
debian
CVE-2019-11235P3CRITICALCVSS 9.8fixed in freeradius 3.0.17+dfsg-1.1 (bookworm)2019
CVE-2019-11235 [CRITICAL] CVE-2019-11235: freeradius - FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the rece...
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
Scope: local
bookworm: resolved (fixed in 3.0.17+dfsg-1.1)
bullseye: re
debian
CVE-2003-0968P3LOWCVSS 10.0fixed in freeradius 1.0.1 (bookworm)2003
CVE-2003-0968 [CRITICAL] CVE-2003-0968: freeradius - Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental modu...
Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.
Scope: local
bookworm: resolved (fixed in 1.0.1)
bullseye: resolved (fixed in 1.0.1)
forky: resolved (fixed in 1.0.1)
sid: resolved (fixed in 1.0.1)
trixie: reso
debian
CVE-2022-41859P3HIGHCVSS 7.5fixed in freeradius 3.2.0+dfsg-1 (bookworm)2022
CVE-2022-41859 [HIGH] CVE-2022-41859: freeradius - In freeradius, the EAP-PWD function compute_password_element() leaks information...
In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-1)
bullseye: resolved (fixed in 3.0.21+dfsg-2.2+deb11u2)
forky: resolved (fixed in 3.2.0+dfsg-1)
sid: resolved (fixed in
debian
CVE-2014-2015P3LOWCVSS 7.5fixed in freeradius 2.2.5+dfsg-0.1 (bookworm)2014
CVE-2014-2015 [HIGH] CVE-2014-2015: freeradius - Stack-based buffer overflow in the normify function in the rlm_pap module (modul...
Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, and 3.x, possibly 3.0.1 and earlier, might allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password hash, as demonstrated by an SSHA hash.
Scope: local
bookworm: reso
debian
CVE-2003-0967P4MEDIUMCVSS 5.0PoCfixed in freeradius 0.9.2-4 (bookworm)2003
CVE-2003-0967 [MEDIUM] CVE-2003-0967: freeradius - rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a de...
rad_decode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.
Scope: local
bookworm: resolved (fixed in 0.9.2-4)
bullseye: resolved (fixed in 0.9.2-4)
forky: reso
debian
CVE-2012-3547P3MEDIUMCVSS 6.8fixed in freeradius 2.1.12+dfsg-1.1 (bookworm)2012
CVE-2012-3547 [MEDIUM] CVE-2012-3547: freeradius - Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 th...
Stack-based buffer overflow in the cbtls_verify function in FreeRADIUS 2.1.10 through 2.1.12, when using TLS-based EAP methods, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via a long "not after" timestamp in a client certificate.
Scope: local
bookworm: resolved (fixed in 2.1.12+dfsg-1.1)
bullseye: resolv
debian
CVE-2017-10978P3HIGHCVSS 7.5fixed in freeradius 3.0.15+dfsg-1 (bookworm)2017
CVE-2017-10978 [HIGH] CVE-2017-10978: freeradius - An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows ...
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.
Scope: local
bookworm: resolved (fixed in 3.0.15+dfsg-1)
bullseye: resolved (fixed in 3.0.15+dfsg-1)
forky: resolved (fixed in 3.0.15+dfsg-1)
sid: resolved (fixed in 3.0.15+dfsg-1)
trixie: resolved (fixed in 3.0.15+dfsg
debian
CVE-2019-17185P3HIGHCVSS 7.5fixed in freeradius 3.0.20+dfsg-1 (bookworm)2019
CVE-2019-17185 [HIGH] CVE-2019-17185: freeradius - In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_C...
In FreeRADIUS 3.0.x before 3.0.20, the EAP-pwd module used a global OpenSSL BN_CTX instance to handle all handshakes. This mean multiple threads use the same BN_CTX instance concurrently, resulting in crashes when concurrent EAP-pwd handshakes are initiated. This can be abused by an adversary as a Denial-of-Service (DoS) attack.
Scope: local
bookworm: resolved (f
debian
CVE-2022-41860P3HIGHCVSS 7.5fixed in freeradius 3.2.0+dfsg-1 (bookworm)2022
CVE-2022-41860 [HIGH] CVE-2022-41860: freeradius - In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the serve...
In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.
Scope: local
bookworm: resolved (fixed in 3.2.0+dfsg-1)
bullseye: resolv
debian
CVE-2015-4680P3HIGHCVSS 7.5fixed in freeradius 2.2.8+dfsg-0.1 (bookworm)2015
CVE-2015-4680 [HIGH] CVE-2015-4680: freeradius - FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check rev...
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
Scope: local
bookworm: resolved (fixed in 2.2.8+dfsg-0.1)
bullseye: resolved (fixed in 2.2.8+dfsg-0.1)
forky: resolved (fixed in 2.2.8+dfsg-0.1)
sid: resolved (fixed in 2.2.8+dfsg-0.1)
trixie: resolved (fixed in 2.2.8+dfsg-0.1)
debian
CVE-2011-4966P3LOWCVSS 6.0fixed in freeradius 2.1.12+dfsg-1.2 (bookworm)2011
CVE-2011-4966 [MEDIUM] CVE-2011-4966: freeradius - modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enable...
modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.
Scope: local
bookworm: resolved (fixed in 2.1.12+dfsg-1.2)
bullseye: resolved (fixed in 2.1.12+dfsg-1.2)
forky:
debian
CVE-2017-10982P4HIGHCVSS 7.5fixed in freeradius 3.0.12+dfsg-3 (bookworm)2017
CVE-2017-10982 [HIGH] CVE-2017-10982: freeradius - An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-re...
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.
Scope: local
bookworm: resolved (fixed in 3.0.12+dfsg-3)
bullseye: resolved (fixed in 3.0.12+dfsg-3)
forky: resolved (fixed in 3.0.12+dfsg-3)
sid: resolved (fixed in 3.0.12+dfsg-3)
trixie: resolved (fixed in 3.0.12+dfsg-3)
debian
CVE-2017-10983P4HIGHCVSS 7.5fixed in freeradius 3.0.15+dfsg-1 (bookworm)2017
CVE-2017-10983 [HIGH] CVE-2017-10983: freeradius - An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows ...
An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial of service.
Scope: local
bookworm: resolved (fixed in 3.0.15+dfsg-1)
bullseye: resolved (fixed in 3.0.15+dfsg-1)
forky: resolved (fixed in 3.0.15+dfsg-1)
sid: resolved (fixed in 3.0.15+dfsg-1)
trixie: resolved (fixed in 3.0.1
debian
1 / 3Next →