Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FreeRADIUS EAP-PWD模块安全漏洞
Vulnerability Description
FreeRADIUS是FreeRADIUS Server项目的一套实现了RADIUS协议的软件。该软件主要用于账户认证管理、记账管理和上网账户管理等,并包含有一个Radius服务器、一个BSD协议授权的客户端库、一个PAM库和一个Apache模块。EAP-PWD是用于其中的一个可扩展的身份验证协议模块。 FreeRADIUS 3.0版本至3.0.8版本中的EAP-PWD模块中存在安全漏洞。远程攻击者可借助特制的commit或confirm消息利用该漏洞造成越边界读取。
CVSS Information
N/A
Vulnerability Type
N/A