Logo
componentfreeradius3
Name
freeradius3
Version
3.2.10-r
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:freeradius:freeradius:3.2.10:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
openwrt-25.12
3.2.8-r1

Patches#


#
Title
Author
Resolve
1
configure: assume __thread TLS works when cross-compiling
Alexandru Ardelean <alex@shruggie.ro>
2
Patch #2
Unknown
3
radtest: use $HOSTNAME for the NAS name when it is set
Alexandru Ardelean <alex@shruggie.ro>
4
rlm_krb5: assume thread-safety when cross-compiling
Alexandru Ardelean <alex@shruggie.ro>
5
fix compilation without deprecated OpenSSL APIs
Rosen Penev <rosenp@gmail.com>

Vulnerabilities#


Name
Analysis
Description
Exploitable
modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenticated users to authenticate using an expired password.
Exploitable
FreeRADIUS RADIUS server allows remote attackers to cause a denial of service (CPU consumption) via a flood of Access-Request packets.