FreeRADIUS Security Patches Fix Critical Buffer Overflow Vulnerabilities
ID: 50d41d04-4594-50cd-bd5a-917af9368356
STIX ID: report--50d41d04-4594-50cd-bd5a-917af9368356
Feed Name: securityonline.info
This advisory warns of severe unauthenticated buffer-overflow flaws in the widely deployed FreeRADIUS server—an attacker can send crafted UDP packets (e.g., a long NAS-Filter-Rule attribute) to crash the service before authentication checks, and multiple overflows affect EAP-MSCHAPv2, EAP-MD5 and TEAP. The maintainers withheld exploit details due to automated attack/tooling risks and urge immediate patching to FreeRADIUS 3.0.28 or 3.2.9 and validation of authentication environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
