« Volver al listado

CVE-2010-3697

Estado: ModificadaMedia (4.3)—

The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-3697",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-10-07T21:00:03.500",
  "references": [
    {
      "url": "http://freeradius.org/press/index.html#2.1.10",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://github.com/alandekok/freeradius-server/commit/ff94dd35673bba1476594299d31ce8293b8bd223",
      "tags": [
        "Patch"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/41621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/10/01/3",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/10/01/8",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=35",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=639397",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://freeradius.org/press/index.html#2.1.10",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://github.com/alandekok/freeradius-server/commit/ff94dd35673bba1476594299d31ce8293b8bd223",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/41621",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/10/01/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2010/10/01/8",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.freeradius.org/bugzilla/show_bug.cgi?id=35",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=639397",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests."
    },
    {
      "lang": "es",
      "value": "La función wait_for_child_to_die en main/event.c en FreeRADIUS v2.1.x anterior a v2.1.10, en determinadas ocaciones genera cortes en la base de datos al no controlar correctamente los tiempos largos de la cola de peticiones, permitiendo de esta forma a atacantes remotos provocar una denegación de servicio ( caída del servicio) mediante el envío de muchas peticiones."
    }
  ],
  "lastModified": "2026-06-16T23:23:21.487",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B92B1F7-8139-4D5A-9461-0C7314BCCBC5"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5CAEB64-0676-4C18-8255-DACDA612188E"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "17F7A434-49DC-4005-9161-F2B49559621F"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A54D59A-B832-4EE3-A8D6-A85EC17C268A"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D494932F-F639-44BE-B15C-7F07A67B0502"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D2D45784-C53B-4A11-B1B3-BC68B514002D"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E969979B-2852-453D-AF48-A462448D4C62"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E56E3E2-9142-47F5-B53E-61ACE4FA9A90"
            },
            {
              "criteria": "cpe:2.3:a:freeradius:freeradius:2.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE0CFEA6-1AC0-41AA-BEF0-16FE1A933758"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}