VDB
CVE-2010-3696
CVE-2010-3696
PUBLISHED
CVSS 4.300000190734863 MEDIUM
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.
EPSS 1.62% · 73.9th percentile
Risk Scores
CVSS 2.0
4.300000190734863
EPSS Score
1.62%
73.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| freeradius | freeradius | 2.1.9 |
| n/a | n/a | * |
Timeline
- Oct 7, 2010 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 18, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=77 url
- http://github.com/alandekok/freeradius-server/commit/4dc7800b866f889a1247685bbaa6dd4238a56279 url
- [oss-security] 20101001 CVE request: freeradius mailing-list
- http://freeradius.org/press/index.html#2.1.10 url
- https://bugzilla.redhat.com/show_bug.cgi?id=639390 technical
- http://www.openwall.com/lists/oss-security/2010/10/01/8 technical
- https://nvd.nist.gov/vuln/detail/CVE-2010-3696 advisory
- http://secunia.com/advisories/41621 url