|
|
Log in / Subscribe / Register

freeradius: memory leak

Package(s):freeradius CVE #(s):CVE-2007-2028
Created:April 17, 2007 Updated:May 15, 2007
Description: A memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
Alerts:
Fedora FEDORA-2007-499 freeradius 2007-05-14
Red Hat RHSA-2007:0338-01 freeradius 2007-05-10
Gentoo 200704-14 freeradius 2007-04-17
Mandriva MDKSA-2007:085 freeradius 2007-04-16

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds