CVE-2010-3697
Published: 7 October 2010
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
Notes
Author | Note |
---|---|
mdeslaur | upstream has disputed this CVE, as the server would need to be down already, so no security impact. |
Priority
Status
Package | Release | Status |
---|---|---|
freeradius Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
(pre 2.1)
|
hardy |
Not vulnerable
(pre 2.1)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Not vulnerable
|
|
maverick |
Ignored
(end of life)
|
|
natty |
Not vulnerable
(2.1.10+dfsg-2ubuntu2)
|
|
oneiric |
Not vulnerable
(2.1.10+dfsg-2ubuntu2)
|
|
precise |
Not vulnerable
(2.1.10+dfsg-2ubuntu2)
|
|
upstream |
Released
(2.1.10)
|