PT-2005-5586 · Freeradius+1 · Freeradius+1

Published

1970-01-01

·

Updated

2010-04-02

·

CVE-2005-4745

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRADIUS versions 1.0.3 through 1.0.4
Description The issue allows remote attackers to execute arbitrary SQL commands, potentially leading to disruption of protected information. This can be exploited remotely. Multiple vulnerabilities in various FreeRADIUS packages for Debian GNU/Linux may also lead to disruption of protected information, with exploitation possible remotely.
Recommendations For FreeRADIUS versions 1.0.3 and 1.0.4, consider updating to a version that fixes the SQL injection vulnerability in the rlm sqlcounter module. At the moment, there is no information about a newer version that contains a fix for this vulnerability in other affected packages.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03123
BDU:2015-03124
BDU:2015-03125
BDU:2015-03126
BDU:2015-03127
CVE-2005-4745
DSA-1145-1

Affected Products

Debian
Freeradius