CVE-2006-4181

GNU Radius 1.2 and 1.3 - Remote Code Execution via Format String in SQL Accounting

Title source: llm
STIX 2.1

Description

Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors.

References (7)

Core 7
Core References
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/23087
Patch, Vendor Advisory third-party-advisory x_refsource_idefense
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=443
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200612-17.xml
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/4712
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/30508
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/21303
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1017285

Scores

EPSS 0.2264
EPSS Percentile 95.9%

Details

Status published
Products (2)
gnu/radius 1.2
gnu/radius 1.3
Published Nov 28, 2006
Tracked Since Feb 18, 2026