Posted: Thu Aug 04, 2005 12:04 am Post subject: Radiusd-cistron
Cistron RADIUS is an authentication and accounting system for
terminal servers that speak the RADIUS (Remote Authentication Dial In
User Service) protocol.
David Luyer reported[1] a buffer overflow vulnerability in
radiusd-cistron versions <= 1.6.6 that could allow remote attackers
to cause a denial of service (DoS) and possibly execute arbitrary
code in the server context. The vulnerability resides in the handling
of the NAS-Port attribute, which can be interpreted as a negative
number, causing a buffer overflow.
SOLUTION
All radius-cistron users should upgrade. This update will
automatically restart the service if it is already running.