CVE-2004-0849 describes an integer overflow in the asn_decode_string() function within GNU Radius versions 1.1 and 1.2 prior to 1.2.94, specifically when compiled with the --enable-snmp option. This vulnerability allows unauthenticated remote attackers to trigger a denial of service by sending specially crafted SNMP requests, causing the daemon to crash. Rated with a CVSS score of 5.0, it has a low attack complexity and impacts availability. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.92.1CPE matchmatch criteria | cpe:2.3:a:gnu:radius:0.92.1:*:*:*:*:*:*:* | ||
0.93CPE matchmatch criteria | cpe:2.3:a:gnu:radius:0.93:*:*:*:*:*:*:* | ||
0.94CPE matchmatch criteria | cpe:2.3:a:gnu:radius:0.94:*:*:*:*:*:*:* | ||
0.95CPE matchmatch criteria | cpe:2.3:a:gnu:radius:0.95:*:*:*:*:*:*:* | ||
0.96CPE matchmatch criteria | cpe:2.3:a:gnu:radius:0.96:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.