CVE-2003-0968: Buffer Overflow
Published Dec 2, 2003
·Updated
Stack-based buffer overflow in SMBLogonServer of the rlmsmb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.
Affected Software
2 affected components
FreeRADIUS freeradius<=0.9.3
FreeRADIUS freeradius<=0.9.3
Event History
Dec 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Dec 15, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0968?
The severity of CVE-2003-0968 is generally categorized as critical due to the potential for remote code execution.
2
How do I fix CVE-2003-0968?
To fix CVE-2003-0968, upgrade FreeRADIUS to a version later than 0.9.3.
3
What causes CVE-2003-0968?
CVE-2003-0968 is caused by a stack-based buffer overflow in the SMB_Logon_Server of the rlm_smb module.
4
Who is affected by CVE-2003-0968?
Any system running FreeRADIUS version 0.9.3 or earlier that utilizes the rlm_smb module is affected by CVE-2003-0968.
5
What type of attacks can exploit CVE-2003-0968?
CVE-2003-0968 can be exploited by remote attackers to execute arbitrary code on the affected system.