Lucent RADIUS Remote Buffer Overflow Vulnerability
BID:2989
Info
Lucent RADIUS Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 2989 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0534 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2001 12:00AM |
| Updated: | Jul 11 2009 06:56AM |
| Credit: | This vulnerability was announced in an ISS X-Force Security Advisory on July 5, 2001. |
| Vulnerable: |
Simon Horms RADIUS 2.1 -2 |
| Not Vulnerable: | |
Discussion
Lucent RADIUS Remote Buffer Overflow Vulnerability
The Lucent RADIUS implementation is a user authentication software package designed to offer enhanced security services to users needing remote access to various resources. The package is no longer maintained by Lucent, and is public domain.
Numerous buffer overflows have been discovered in the package, which could allow a user to exploit the radius daemon. The radius daemon by default runs as UID root. A remote user may be able to overwrite stack variables, including the return address.
This makes it possible for a remote user to execute arbitrary code, and potentially gain local root access.
The Lucent RADIUS implementation is a user authentication software package designed to offer enhanced security services to users needing remote access to various resources. The package is no longer maintained by Lucent, and is public domain.
Numerous buffer overflows have been discovered in the package, which could allow a user to exploit the radius daemon. The radius daemon by default runs as UID root. A remote user may be able to overwrite stack variables, including the return address.
This makes it possible for a remote user to execute arbitrary code, and potentially gain local root access.
Exploit / POC
Lucent RADIUS Remote Buffer Overflow Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Lucent RADIUS Remote Buffer Overflow Vulnerability
Solution:
Patches available:
Simon Horms RADIUS 2.1 -2
Solution:
Patches available:
Simon Horms RADIUS 2.1 -2
-
Simon Horms radius-2.1-build.patch
ftp://ftp.vergenet.net/pub/lucent_radius/radius-2.1-build.patch -
Simon Horms radius-2.1-overflow.patch
ftp://ftp.vergenet.net/pub/lucent_radius/radius-2.1-overflow.patch -
Simon Horms radius-2.1-util_segfault.patch
ftp://ftp.vergenet.net/pub/lucent_radius/radius-2.1-util_segfault.patc h -
Simon Horms radius-2.1.va.1.patch.gz
ftp://ftp.vergenet.net/pub/lucent_radius/radius-2.1.va.1.patch.gz -
Simon Horms radius-makefile.patch
ftp://ftp.vergenet.net/pub/lucent_radius/radius-makefile.patch
References
Lucent RADIUS Remote Buffer Overflow Vulnerability
References:
References: