Executive Summary

Title New freeradius packages fix arbitrary code execution
Name DSA-1089 First vendor Publication 2006-06-03
Vendor Debian Last vendor Modification 2006-06-03
Severity (Vendor) N/A Revision 1

Several problems have been discovered in freeradius, a high-performance and highly configurable RADIUS server. The Common Vulnerabilities and Exposures project identifies the following problems:


SuSE researchers have discovered several off-by-one errors may allow remote attackers to cause a denial of service and possibly execute arbitrary code.


Due to insufficient input validation it is possible for a remote attacker to bypass authentication or cause a denial of service.

The old stable distribution (woody) does not contain this package.

For the stable distribution (sarge) this problem has been fixed in version 1.0.2-4sarge1.

For the unstable distribution (sid) this problem has been fixed in version 1.1.0-1.2.

We recommend that you upgrade your freeradius package.

Original Source

Url : http://www.debian.org/security/2006/dsa-1089

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:10156
Oval ID: oval:org.mitre.oval:def:10156
Title: Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
Description: Unspecified vulnerability in FreeRADIUS 1.0.0 up to 1.1.0 allows remote attackers to bypass authentication or cause a denial of service (server crash) via "Insufficient input validation" in the EAP-MSCHAPv2 state machine module.
Family: unix Class: vulnerability
Reference(s): CVE-2006-1354
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:10449
Oval ID: oval:org.mitre.oval:def:10449
Title: Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
Description: Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.
Family: unix Class: vulnerability
Reference(s): CVE-2005-4744
Version: 5
Platform(s): Red Hat Enterprise Linux 3
CentOS Linux 3
Red Hat Enterprise Linux 4
CentOS Linux 4
Oracle Linux 4
Definition Synopsis:

