Out-of-bounds read in FreeRADIUS - CVE-2017-10983
Published: July 18, 2017
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak in fr_dhcp_decode() function when processing DHCP packets. A remote attacker on local network can send specially crafted DHCP option 63 with non-zero contents to vulnerable system and trigger denial of service attack.
Affected software
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
SUSE Linux
Ubuntu
Fedora
freeradius
How to mitigate CVE-2017-10983
External References
Related Security Bulletins
- Multiple vulnerabilities in FreeRADIUS
- Red Hat Enterprise Linux update for FreeRADIUS
- Ubuntu update for FreeRADIUS
- Debian update for freeradius
- Amazon Linux AMI update for freeradius
- OpenSUSE Linux update for freeradius-server
- SUSE Linux update for freeradius-server
- Fedora 26 update for freeradius
- Fedora 25 update for freeradius