REDHAT-BUG-639390: Low severity FreeRADIUS freeradius vulnerability

Published Oct 1, 2010
·
Updated

It was reported [1],[2] that an error when processing DHCP requests with the 'Relay Agent Information' option (82) in src/lib/dhcp.c could be exploited to cause an infinite loop, in the process denying further requests via a packet with multiple sub-options.

According to the upstream report, this flaw seems to only affect 2.1.9 and was fixed [3] in 2.1.10.

[1] https://bugs.freeradius.org/bugzilla/showbug.cgi?id=77 [2] http://secunia.com/advisories/41621 [3] http://github.com/alandekok/freeradius-server/commit/4dc7800b866f889a1247685bbaa6dd4238a56279

The offending file (dhcp.c) is not present in the version of freeradius as provided with Red Hat Enterprise Linux 5 (1.1.3).

Affected Software

1 affected component
FreeRADIUS freeradius

Event History

Oct 1, 2010
Data Sourced
04:00 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-639390?

REDHAT-BUG-639390 has a high severity because it can be exploited to create an infinite loop, affecting the availability of the DHCP service.

2

How do I fix REDHAT-BUG-639390?

To fix REDHAT-BUG-639390, users should update their FreeRADIUS server to the latest patched version that addresses this vulnerability.

3

What causes the vulnerability REDHAT-BUG-639390?

The vulnerability REDHAT-BUG-639390 is caused by an error in processing DHCP requests with the 'Relay Agent Information' option, leading to an infinite loop.

4

What impact does REDHAT-BUG-639390 have on network services?

The impact of REDHAT-BUG-639390 includes denial of service for further DHCP requests, potentially disrupting network connectivity.

5

Is REDHAT-BUG-639390 specific to any version of FreeRADIUS?

Yes, REDHAT-BUG-639390 specifically affects FreeRADIUS servers that do not have the appropriate updates to mitigate this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203