Secunia Logo
 
CVE Reference: CVE-2005-4744
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-4744

Description:
Off-by-one error in the sql_error function in sql_unixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/22211

SGI

SAID
  Secunia Advisory: SA19811
  Secunia Advisory: SA20461
  Secunia Advisory: SA19518
  Secunia Advisory: SA19497
  Secunia Advisory: SA16712

REDHAT
  http://rhn.redhat.com/errata/RHSA-2006-0271.html

MISC
  http://www.freeradius.org/security/20050909-vendor-sec.txt

MANDRIVA
  http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:066

DEBIAN
  http://www.debian.org/security/2006/dsa-1089

CONFIRM
  http://www.freeradius.org/security/20050909-response-to-suse.txt

BID
  14775


Return to the previous page.