In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-01-17T00:00:00
Updated: 2024-08-03T12:56:38.237Z
Reserved: 2022-09-30T00:00:00
Link: CVE-2022-41860
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-01-17T18:15:11.387
Modified: 2024-11-21T07:23:57.257
Link: CVE-2022-41860
Redhat