Merit RADIUS Buffer Overflow Vulnerability
BID:2991
Info
Merit RADIUS Buffer Overflow Vulnerability
| Bugtraq ID: | 2991 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2001 12:00AM |
| Updated: | Jul 05 2001 12:00AM |
| Credit: | This vulnerability was announced in an ISS X-Force Security Advisory on July 5, 2001. |
| Vulnerable: |
Merit RADIUS 3.6 B |
| Not Vulnerable: |
Merit RADIUS 3.6 B1 |
Discussion
Merit RADIUS Buffer Overflow Vulnerability
The Merit RADIUS implementation is a user authentication software package designed to offer enhanced security services to users needing remote access to various resources.
Numerous buffer overflows have been discovered in the package, which could allow a user to exploit the radius daemon. The radius daemon by default runs as UID root. A remote user may be able to overwrite stack variables, including the return address.
This makes it possible for a remote user to execute arbitrary code, and potentially gain local root access.
The Merit RADIUS implementation is a user authentication software package designed to offer enhanced security services to users needing remote access to various resources.
Numerous buffer overflows have been discovered in the package, which could allow a user to exploit the radius daemon. The radius daemon by default runs as UID root. A remote user may be able to overwrite stack variables, including the return address.
This makes it possible for a remote user to execute arbitrary code, and potentially gain local root access.
Solution / Fix
Merit RADIUS Buffer Overflow Vulnerability
Solution:
Upgrade available:
Merit RADIUS 3.6 B
Solution:
Upgrade available:
Merit RADIUS 3.6 B
-
Merit radius.3.6B1.basic.tar.gz
ftp://ftp.merit.edu/radius/releases/radius.3.6B1.basic.tar.gz