#VU7557 Out-of-bounds read in FreeRADIUS - CVE-2017-10983
Published: July 18, 2017
FreeRADIUS
FreeRADIUS Server Project
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak in fr_dhcp_decode() function when processing DHCP packets. A remote attacker on local network can send specially crafted DHCP option 63 with non-zero contents to vulnerable system and trigger denial of service attack.