Buffer overflow in FreeRADIUS - CVE-2017-10978
Published: July 17, 2017 / Updated: July 18, 2017
FreeRADIUS
FreeRADIUS Server Project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to boundary error in make_secret() function when processing RADIUS packets. A remote unauthenticated attacker can send a specially crafted RADIUS packet and crash the affected server.
Successful exploitation of this vulnerability may result in denial of service attack.