CVE-2010-3697

The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
freeradiusfreeradius
2.1.0
freeradiusfreeradius
2.1.1
freeradiusfreeradius
2.1.2
freeradiusfreeradius
2.1.3
freeradiusfreeradius
2.1.4
freeradiusfreeradius
2.1.6
freeradiusfreeradius
2.1.7
freeradiusfreeradius
2.1.8
freeradiusfreeradius
2.1.9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
freeradius
bullseye
3.0.21+dfsg-2.2+deb11u1
fixed
bookworm
3.2.1+dfsg-4+deb12u1
fixed
sid
3.2.5+dfsg-3
fixed
trixie
3.2.5+dfsg-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freeradius
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
ignored
lucid
not-affected
karmic
ignored
jaunty
ignored
hardy
not-affected
dapper
not-affected
Common Weakness Enumeration