CVE-2003-0967: Medium severity freeradius freeradius vulnerability
Published Dec 2, 2003
·Updated
raddecode in FreeRADIUS 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a short RADIUS string attribute with a tag, which causes memcpy to be called with a -1 length argument, as demonstrated using the Tunnel-Password attribute.
Affected Software
1 affected component
FreeRADIUS freeradius<=0.9.2
Event History
Dec 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 15, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0967?
The severity of CVE-2003-0967 is classified as high due to its potential to cause denial of service.
2
How do I fix CVE-2003-0967?
To fix CVE-2003-0967, upgrade FreeRADIUS to version 0.9.3 or later to eliminate the vulnerability.
3
What type of attack does CVE-2003-0967 represent?
CVE-2003-0967 represents a remote denial of service attack via crafted RADIUS string attributes.
4
Which versions of FreeRADIUS are affected by CVE-2003-0967?
FreeRADIUS versions 0.9.2 and earlier are affected by CVE-2003-0967.
5
What specific RADIUS attribute can trigger CVE-2003-0967?
The Tunnel-Password attribute can trigger CVE-2003-0967 when it is exploited with a short RADIUS string.