Record summary

CVE-2009-3111 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBFreeRadius < 1.1.8 - Zero-Length Tunnel-Password Denial of ServiceExploitDB exploitby Matthew GillespieNot analyzed1 file
ExploitDB

PoC details

References

Showing 12 of 14