Multiple buffer overflows in FreeRADIUS 1.0.3 and 1.0.4 allow remote attackers to cause denial of service (crash) via (1) the rlm_sqlcounter module or (2) unknown vectors "while expanding %t".
http://www.securityfocus.com/bid/17293
http://www.mandriva.com/security/advisories?name=MDKSA-2007:092
http://www.mandriva.com/security/advisories?name=MDKSA-2006:066