cbcvebase.

Debian Freeradius vulnerabilities

41 known vulnerabilities affecting debian/freeradius.

Total CVEs
41
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH17MEDIUM9LOW9

Vulnerabilities

Page 2 of 3
CVE-2017-10981P4HIGHCVSS 7.5fixed in freeradius 3.0.12+dfsg-3 (bookworm)2017
CVE-2017-10981 [HIGH] CVE-2017-10981: freeradius - An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in... An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service. Scope: local bookworm: resolved (fixed in 3.0.12+dfsg-3) bullseye: resolved (fixed in 3.0.12+dfsg-3) forky: resolved (fixed in 3.0.12+dfsg-3) sid: resolved (fixed in 3.0.12+dfsg-3) trixie: resolved (fixed in 3.0.12+dfsg-3)
debian
CVE-2017-10980P4HIGHCVSS 7.5fixed in freeradius 3.0.12+dfsg-3 (bookworm)2017
CVE-2017-10980 [HIGH] CVE-2017-10980: freeradius - An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in... An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service. Scope: local bookworm: resolved (fixed in 3.0.12+dfsg-3) bullseye: resolved (fixed in 3.0.12+dfsg-3) forky: resolved (fixed in 3.0.12+dfsg-3) sid: resolved (fixed in 3.0.12+dfsg-3) trixie: resolved (fixed in 3.0.12+dfsg-3)
debian
CVE-2017-10985P4HIGHCVSS 7.5fixed in freeradius 3.0.15+dfsg-1 (bookworm)2017
CVE-2017-10985 [HIGH] CVE-2017-10985: freeradius - An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and mem... An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service. Scope: local bookworm: resolved (fixed in 3.0.15+dfsg-1) bullseye: resolved (fixed in 3.0.15+dfsg-1) forky: resolved (fixed in 3.0.15+dfsg-1) sid: resolved (fixed in 3.0.15+dfsg-1) trixie: resolved (fixed in 3.0.15+dfsg
debian
CVE-2005-4745P3HIGHCVSS 7.5fixed in freeradius 1.0.5-1 (bookworm)2005
CVE-2005-4745 [HIGH] CVE-2005-4745: freeradius - SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and... SQL injection vulnerability in the rlm_sqlcounter module in FreeRADIUS 1.0.3 and 1.0.4 allows remote attackers to execute arbitrary SQL commands via unknown attack vectors. Scope: local bookworm: resolved (fixed in 1.0.5-1) bullseye: resolved (fixed in 1.0.5-1) forky: resolved (fixed in 1.0.5-1) sid: resolved (fixed in 1.0.5-1) trixie: resolved (fixed in 1.0.5-1)
debian
CVE-2017-10987P4HIGHCVSS 7.5fixed in freeradius 3.0.15+dfsg-1 (bookworm)2017
CVE-2017-10987 [HIGH] CVE-2017-10987: freeradius - An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-re... An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service. Scope: local bookworm: resolved (fixed in 3.0.15+dfsg-1) bullseye: resolved (fixed in 3.0.15+dfsg-1) forky: resolved (fixed in 3.0.15+dfsg-1) sid: resolved (fixed in 3.0.15+dfsg-1) trixie: resolved (fixed in 3.0.15+dfsg-1)
debian
CVE-2006-1354P4HIGHCVSS 7.5fixed in freeradius 1.1.0-1.2 (bookworm)2006
CVE-2006-1354 [HIGH] CVE-2006-1354: freeradius - Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attacker... Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module. Scope: local bookworm: resolved (fixed in 1.1.0-1.2) bullseye: resolved (fixed in 1.1.0-1.2) forky: resolved (fixed in 1.1.0-1.2) sid: res
debian
CVE-2005-1454P4HIGHCVSS 7.5fixed in freeradius 1.0.2-4 (bookworm)2005
CVE-2005-1454 [HIGH] CVE-2005-1454: freeradius - SQL injection vulnerability in the radius_xlat function in the SQL module for Fr... SQL injection vulnerability in the radius_xlat function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via (1) group_membership_query, (2) simul_count_query, or (3) simul_verify_query configuration entries. Scope: local bookworm: resolved (fixed in 1.0.2-4) bullseye: resolved (fixed in 1.0.2-4)
debian
CVE-2019-10143P4LOWCVSS 7.0fixed in freeradius 3.2.6+dfsg-3 (forky)2019
CVE-2019-10143 [HIGH] CVE-2019-10143: freeradius - It was discovered freeradius up to and including version 3.0.19 does not correct... It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer
debian
CVE-2019-13456P4MEDIUMCVSS 6.5fixed in freeradius 3.0.20+dfsg-1 (bookworm)2019
CVE-2019-13456 [MEDIUM] CVE-2019-13456: freeradius - In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes ... In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494. Scope: loc
debian
CVE-2022-41861P4MEDIUMCVSS 6.5fixed in freeradius 3.2.0+dfsg-1 (bookworm)2022
CVE-2022-41861 [MEDIUM] CVE-2022-41861: freeradius - A flaw was found in freeradius. A malicious RADIUS client or home server can sen... A flaw was found in freeradius. A malicious RADIUS client or home server can send a malformed abinary attribute which can cause the server to crash. Scope: local bookworm: resolved (fixed in 3.2.0+dfsg-1) bullseye: resolved (fixed in 3.0.21+dfsg-2.2+deb11u2) forky: resolved (fixed in 3.2.0+dfsg-1) sid: resolved (fixed in 3.2.0+dfsg-1) trixie: resolved (fixed in
debian
CVE-2005-1455P4HIGHCVSS 7.5fixed in freeradius 1.0.2-4 (bookworm)2005
CVE-2005-1455 [HIGH] CVE-2005-1455: freeradius - Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS... Buffer overflow in the sql_escape_func function in the SQL module for FreeRADIUS 1.0.2 and earlier allows remote attackers to cause a denial of service (crash). Scope: local bookworm: resolved (fixed in 1.0.2-4) bullseye: resolved (fixed in 1.0.2-4) forky: resolved (fixed in 1.0.2-4) sid: resolved (fixed in 1.0.2-4) trixie: resolved (fixed in 1.0.2-4)
debian
CVE-2005-4746P4HIGHCVSS 7.8fixed in freeradius 1.0.5-1 (bookworm)2005
CVE-2005-4746 [HIGH] CVE-2005-4746: freeradius - Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers t... Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter module or (2) unknown vectors "while expanding %t". Scope: local bookworm: resolved (fixed in 1.0.5-1) bullseye: resolved (fixed in 1.0.5-1) forky: resolved (fixed in 1.0.5-1) sid: resolved (fixed in 1.0.5-1) trixie: resolved
debian
CVE-2005-4744P4MEDIUMCVSS 6.4fixed in freeradius 1.0.5-1 (bookworm)2005
CVE-2005-4744 [MEDIUM] CVE-2005-4744: freeradius - Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2... Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, wh
debian
CVE-2008-4474P4LOWCVSS 7.2fixed in freeradius 2.0.4+dfsg-6 (bookworm)2008
CVE-2008-4474 [HIGH] CVE-2008-4474: freeradius - freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbit... freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) truncate_radacct. Scope: local bookworm: resolved (fixed in 2.0.4+dfsg-6) bullseye: resolved (fixed in 2.0.4+dfsg-6) forky: resolved (fixed in 2.0.4
debian
CVE-2007-0080P4LOWCVSS 6.6fixed in freeradius 3.0.12+dfsg-3 (bookworm)2007
CVE-2007-0080 [MEDIUM] CVE-2007-0080: freeradius - Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earli... Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have
debian
CVE-2007-2028P4LOWCVSS 5.0fixed in freeradius 1.1.6-1 (bookworm)2007
CVE-2007-2028 [MEDIUM] CVE-2007-2028: freeradius - Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a d... Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures. Scope: local bookworm: resolved (fixed in 1.1.6-1
debian
CVE-2010-3697P4LOWCVSS 4.3fixed in freeradius 2.1.10+dfsg-1 (bookworm)2010
CVE-2010-3697 [MEDIUM] CVE-2010-3697: freeradius - The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.... The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests. Scope: local bookworm: resolved (fixed in 2.1.10+dfsg-1) bul
debian
CVE-2004-0961P4MEDIUMCVSS 5.0fixed in freeradius 1.0.1 (bookworm)2004
CVE-2004-0961 [MEDIUM] CVE-2004-0961: freeradius - Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial... Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes. Scope: local bookworm: resolved (fixed in 1.0.1) bullseye: resolved (fixed in 1.0.1) forky: resolved (fixed in 1.0.1) sid: res
debian
CVE-2004-0938P4MEDIUMCVSS 5.0fixed in freeradius 1.0.1 (bookworm)2004
CVE-2004-0938 [MEDIUM] CVE-2004-0938: freeradius - FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (se... FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet. Scope: local bookworm: resolved (fixed in 1.0.1) bullseye: resolved (fixed in 1.0.1) forky: resolved (fixed in 1.0.1) sid: resolved (fixed in 1.0.1) trixie: resolved (fixed in 1.0.1)
debian
CVE-2010-3696P4MEDIUMCVSS 4.3fixed in freeradius 2.1.10+dfsg-1 (bookworm)2010
CVE-2010-3696 [MEDIUM] CVE-2010-3696: freeradius - The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-de... The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party inform
debian