CVE-2004-0938: Medium severity FreeRADIUS freeradius vulnerability
Published Oct 16, 2004
·Updated
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.
Affected Software
1 affected component
FreeRADIUS freeradius<=1.0.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Oct 16, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0938?
CVE-2004-0938 is classified as a denial of service vulnerability that can lead to server crashes.
2
How do I fix CVE-2004-0938?
To fix CVE-2004-0938, upgrade to FreeRADIUS version 1.0.1 or later.
3
What systems are affected by CVE-2004-0938?
CVE-2004-0938 affects FreeRADIUS versions prior to 1.0.1.
4
What does CVE-2004-0938 exploit?
CVE-2004-0938 exploits the FreeRADIUS server's handling of the Ascend-Send-Secret attribute.
5
Can CVE-2004-0938 be prevented?
Preventing CVE-2004-0938 involves ensuring that FreeRADIUS is updated to a patched version.