CVE-2007-0080

Current Description

** DISPUTED ** Buffer overflow in the SMB_Connect_Server function in FreeRadius 1.1.3 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. NOTE: the impact of this issue has been disputed by a reliable third party and the vendor, who states that exploitation is limited "only to local administrators who have write access to the server configuration files." CVE concurs with the dispute.

Evaluator Description

-- Official Vendor Statement from the FreeRADIUS Server projectThis issue is not a security vulnerability. The exploit is available only to local administrators who have write access to the server configuration files. As such, this issue has no security impact on any system running FreeRADIUS.-- Official Vendor Statement from the FreeRADIUS Server project

Evaluator Solution

A buffer overflow in the SMB_Connect_Server function in FreeRADIUS 1.1.4 and earlier allows attackers to execute arbitrary code related to the server desthost field of an SMB_Handle_Type instance. This issue can not be exploited remotely, and can only be exploited by administrators who have write access to the server configuration files.

Basic Data

PublishedJanuary 05, 2007
Last ModifiedOctober 16, 2018
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeCWE-119
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:L/AC:M/Au:S/C:C/I:C/A:C
CVSS 2 - Access VectorLOCAL
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationSINGLE
CVSS 2 - Confidentiality ImpactCOMPLETE
CVSS 2 - Availability ImpactCOMPLETE
CVSS 2 - Base Score6.6
SeverityMEDIUM
Exploitability Score2.7
Impact Score10.0
Obtain All Privilegetrue
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationFreeradiusFreeradius********1.1.3

Vulnerable Software List

VendorProductVersions
Freeradius Freeradius *

References

NameSourceURLTags
32082http://osvdb.org/32082OSVDB
1017463http://securitytracker.com/id?1017463SECTRACK
20070211 FreeRADIUS dispute of CVE-2007-0080http://www.attrition.org/pipermail/vim/2007-February/001304.htmlVIM
http://www.freeradius.org/security.htmlhttp://www.freeradius.org/security.htmlMISC
20070102 FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code executionhttp://www.securityfocus.com/archive/1/455678/100/0/threadedBUGTRAQ
20070103 Re: FreeRadius 1.1.3 SMB_Handle_Type SMB_Connect_Server arbitrary code executionhttp://www.securityfocus.com/archive/1/455812/100/0/threadedBUGTRAQ
freeradius-smbconnectserver-bo(31248)https://exchange.xforce.ibmcloud.com/vulnerabilities/31248XF