CVE-2005-4744

Source
https://cve.org/CVERecord?id=CVE-2005-4744
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2005-4744.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2005-4744
Downstream
Published
2005-12-31T05:00:00Z
Modified
2025-08-09T19:01:27Z
Summary
[none]
Details

Off-by-one error in the sqlerror function in sqlunixodbc.c in FreeRADIUS 1.0.2.5-5, and possibly other versions including 1.0.4, might allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by causing the external database query to fail. NOTE: this single issue is part of a larger-scale disclosure, originally by SUSE, which reported multiple issues that were disputed by FreeRADIUS. Disputed issues included file descriptor leaks, memory disclosure, LDAP injection, and other issues. Without additional information, the most recent FreeRADIUS report is being regarded as the authoritative source for this CVE identifier.

References

Affected packages