CVE-2015-8762: Null Pointer Dereference
Published Mar 27, 2017
·Updated
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.
Affected Software
9 affected components
FreeRADIUS freeradius=3.0.0
FreeRADIUS freeradius=3.0.1
FreeRADIUS freeradius=3.0.2
FreeRADIUS freeradius=3.0.3
FreeRADIUS freeradius=3.0.4
FreeRADIUS freeradius=3.0.5
FreeRADIUS freeradius=3.0.6
FreeRADIUS freeradius=3.0.7
FreeRADIUS freeradius=3.0.8
Remediation
Patch Available
Event History
Mar 27, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8762?
CVE-2015-8762 is classified as a denial of service vulnerability.
2
How do I fix CVE-2015-8762?
To mitigate CVE-2015-8762, upgrade FreeRADIUS to version 3.0.9 or later.
3
What versions of FreeRADIUS are affected by CVE-2015-8762?
CVE-2015-8762 affects FreeRADIUS versions 3.0.0 through 3.0.8.
4
What kind of attack is possible with CVE-2015-8762?
CVE-2015-8762 allows remote attackers to cause a denial of service through a malformed EAP-PWD packet.
5
What is EAP-PWD in the context of CVE-2015-8762?
EAP-PWD is an authentication method used in the FreeRADIUS server that is vulnerable to exploitation in CVE-2015-8762.