Related Vulnerabilities: CVE-2017-10987  

A security issue has been found in freeradius <= 3.0.15, where the fr_dhcp_decode_suboptions() function does not properly check if sub-options overflow the packet.

Severity Medium

Remote Yes

Type Denial of service

Description

A security issue has been found in freeradius <= 3.0.15, where the fr_dhcp_decode_suboptions() function does not properly check if sub-options overflow the packet.

AVG-357 freeradius 3.0.14-4 3.0.15-1 Critical Fixed

18 Jul 2017 ASA-201707-23 AVG-357 freeradius Critical multiple issues

http://freeradius.org/security/fuzzer-2017.html#FR-GV-304
https://github.com/FreeRADIUS/freeradius-server/commit/19a18bf7c8af649c9e9742fb6a046f6aff639866