Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

Gentoo: 200307-03 Critical: Cistron Radius Buffer Overflow Remote Attack

gentoo
Calendar Grey July 11, 2003
Dist Gentoo Esm H88
Gentoo's critical Cistron Radius advisory details a buffer overflow risk leading to remote attacks.
Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remoteattackers to cause a denial of service and possibly execute arbitrarycode via a large value in an NAS-Port at...

Summary


- - ---------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200307-03
- - ---------------------------------------------------------------------

- - ---------------------------------------------------------------------
quote from CVE: "Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow."
SOLUTION
It is recommended that all Gentoo Linux users who are running net-dialup/cistronradius upgrade to cistronradius-1.6.6-r1 as follows
emerge sync emerge cistronradius emerge clean
- - --------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - - ---------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : cistonradius
SUMMARY : buffer overflow
DATE : 2003-07-11 13:57 UTC
EXPLOIT : remote
VERSIONS AFFECTED : =cistronradius-1.6.6-r1
CVE : CAN-2003-0450

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Your message here