CVE-2005-0108 describes a denial-of-service vulnerability affecting Apache mod_auth_radius versions 1.5.4 and libpam-radius-auth. A malicious RADIUS server can trigger a crash by sending a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, leading to an invalid memcpy operation. The vulnerability has a CVSS score of 5.0 (medium severity) with an AV:N/AC:L/Au:N/C:N/I:N/A:P vector, indicating it can be exploited remotely with low complexity, requiring no authentication, and resulting in a partial denial of service. Its EPSS score is low, suggesting a low probability of exploitation. There is no known active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the CVE has garnered significant community discussion with 10 mentions, indicating a level of awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.4CPE matchmatch criteria | cpe:2.3:a:apache:mod_auth_radius:1.5.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.