freeradius: memory leak
| Package(s): | freeradius | CVE #(s): | CVE-2007-2028 | ||||||||||||||||
| Created: | April 17, 2007 | Updated: | May 15, 2007 | ||||||||||||||||
| Description: | A memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
