FreeRadius RLM_SQLCounter SQL Injection Vulnerability
BID:17294
Info
FreeRadius RLM_SQLCounter SQL Injection Vulnerability
| Bugtraq ID: | 17294 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-4745 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2006 12:00AM |
| Updated: | Apr 26 2007 10:40PM |
| Credit: | Primoz Bratanic is credited with the discovery of this vulnerability. |
| Vulnerable: |
MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 FreeRADIUS FreeRADIUS 1.0.4 FreeRADIUS FreeRADIUS 1.0.3 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
FreeRADIUS FreeRADIUS 1.1.1 FreeRADIUS FreeRADIUS 1.1 FreeRADIUS FreeRADIUS 1.0.5 |
Discussion
FreeRadius RLM_SQLCounter SQL Injection Vulnerability
FreeRADIUS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
FreeRADIUS is prone to an SQL-injection vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input before using it in an SQL query.
Successful exploitation could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
Exploit / POC
FreeRadius RLM_SQLCounter SQL Injection Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
FreeRadius RLM_SQLCounter SQL Injection Vulnerability
Solution:
The vendor released version 1.1.1 to address this issue.
Please see the referenced advisories for more information.
FreeRADIUS FreeRADIUS 1.0.3
FreeRADIUS FreeRADIUS 1.0.4
Solution:
The vendor released version 1.1.1 to address this issue.
Please see the referenced advisories for more information.
FreeRADIUS FreeRADIUS 1.0.3
-
FreeRADIUS freeradius-1.1.1.tar.gz
ftp://ftp.freeradius.org/pub/radius/freeradius-1.1.1.tar.gz
FreeRADIUS FreeRADIUS 1.0.4
-
FreeRADIUS freeradius-1.1.1.tar.gz
ftp://ftp.freeradius.org/pub/radius/freeradius-1.1.1.tar.gz -
Mandriva freeradius-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva freeradius-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64freeradius1-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64freeradius1-devel-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64freeradius1-krb5-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64freeradius1-ldap-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64freeradius1-mysql-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64freeradius1-postgresql-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva lib64freeradius1-unixODBC-1.0.4-2.4.20060mlcs4.x86_64.rpm
Corporate 4.0/X86_64:
http://www.mandriva.com/en/download -
Mandriva libfreeradius1-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libfreeradius1-devel-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libfreeradius1-krb5-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libfreeradius1-ldap-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libfreeradius1-mysql-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libfreeradius1-postgresql-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download -
Mandriva libfreeradius1-unixODBC-1.0.4-2.4.20060mlcs4.i586.rpm
Corporate 4.0:
http://www.mandriva.com/en/download