Unrated severityNVD Advisory· Published Dec 23, 2004· Updated Apr 16, 2026
CVE-2004-0849
CVE-2004-0849
Description
Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.
Affected products
7cpe:2.3:a:gnu:radius:0.92.1:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:gnu:radius:0.92.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:radius:0.93:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:radius:0.94:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:radius:0.95:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:radius:0.96:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:radius:1.1:*:*:*:*:*:*:*
- cpe:2.3:a:gnu:radius:1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.gnu.org/archive/html/info-gnu-radius/2004-09/msg00000.htmlnvdPatchVendor Advisory
- www.idefense.com/application/poi/displaynvdPatchVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/17391nvd
News mentions
0No linked articles in our index yet.