Related Vulnerabilities: CVE-2017-10985  

A security issue has been found in freeradius <= 3.0.15, where the server could go into an infinite loop and exhaust memory when it receives zero-length attributes marked 'concat' in the dictionaries.

Severity Medium

Remote Yes

Type Denial of service

Description

A security issue has been found in freeradius <= 3.0.15, where the server could go into an infinite loop and exhaust memory when it receives zero-length attributes marked 'concat' in the dictionaries.

AVG-357 freeradius 3.0.14-4 3.0.15-1 Critical Fixed

18 Jul 2017 ASA-201707-23 AVG-357 freeradius Critical multiple issues

http://freeradius.org/security/fuzzer-2017.html#FR-GV-302
https://github.com/FreeRADIUS/freeradius-server/commit/6726c16549b131ed39f6f8886cdf5d9d922a9a97