freeradius -- sql injection and denial of service vulnerability

Affected packages
freeradius <= 1.0.2_1
freeradius-devel <= 1.0.2


VuXML ID 2fbe16c2-cab6-11d9-9aed-000e0c2e438a
Discovery 2005-05-17
Entry 2005-05-22
Modified 2008-01-20

A Gentoo Advisory reports:

The FreeRADIUS server is vulnerable to an SQL injection attack and a buffer overflow, possibly resulting in disclosure and modification of data and Denial of Service.


Bugtraq ID 13540
Bugtraq ID 13541