CVE-2007-0080
Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance.
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files." CVE concurs with the dispute
- CVSS 2.0
- 6.6 MEDIUMAV:L/AC:M/Au:S/C:C/I:C/A:C
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- freeradius/freeradius
- Source
- cve@mitre.org
References
- http://osvdb.org/32082
- http://securitytracker.com/id?1017463
- http://www.attrition.org/pipermail/vim/2007-February/001304.html
- http://www.freeradius.org/security.html
- http://www.securityfocus.com/archive/1/455678/100/0/threaded
- http://www.securityfocus.com/archive/1/455812/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31248
- http://osvdb.org/32082
- http://securitytracker.com/id?1017463
- http://www.attrition.org/pipermail/vim/2007-February/001304.html
- http://www.freeradius.org/security.html
- http://www.securityfocus.com/archive/1/455678/100/0/threaded
- http://www.securityfocus.com/archive/1/455812/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31248
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.