|
Multiple Vendor Radius Short Vendor-Length Field Denial Of Service Vulnerability
RADIUS is the RFC 2865-specified Remote Authentication Dial In User Service. The protocol has been developed and implemented by numerous vendors, and used on Microsoft Windows, Unix, and Linux operating systems. A problem has been discovered in the handling of vendor-specific options. When a RADIUS packet is passed to a client or server, neither the client nor server validate the contents of the vendor-length field. When a RADIUS packet with a vendor-length specification of less than 2 is sent, the contents of the vendor-length field is interpretted as a negative number. This number may be passed to other functions of the RADIUS server or client, resulting in an unpredictable reaction, and a likely crash of the server or client. |
|
|
Privacy Statement |