HIGH 7.5 Microsoft
CVE-2022-41860
In freeradius when an EAP-SIM supplicant sends an unknown SIM option the server will try to look that option up in the internal dictionaries. This lookup will fail but the SIM code will not check for that failure. Instead it will dereference a NULL pointer and cause the server to crash.
Microsoft Security Update 2023-Jan: In freeradius when an EAP-SIM supplicant sends an unknown SIM option the server will try to look that option up in the internal dictionaries. This lookup will fail but the SIM code will not check for that failure. Instead it will dereference a NULL pointer and cause the server to crash.
Affected Products
- cbl2 freeradius 3.2.3-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41860
- https://nvd.nist.gov/vuln/detail/CVE-2022-41860
This high severity vulnerability with a CVSS score of 7.5 was published on 2023-01-10 via Microsoft. Affected: cbl2 freeradius 3.2.3-1 on CBL Mariner 2.0.
vulnfeed aggregates 9214 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.