Memory leak in FreeRADIUS - CVE-2017-10980
Published: July 17, 2017 / Updated: July 18, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak in decode_tlv() function when processing DHCP packets. A remote attacker on local network can send specially crafted DHCP packets with option 82 and multiple sub-options to vulnerable system and trigger denial of service attack.
Affected software
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Ubuntu