Cistron RADIUS Remote Signed NAS-Port Number Expansion Memory Corruption Vulnerability
BID:7892
Info
Cistron RADIUS Remote Signed NAS-Port Number Expansion Memory Corruption Vulnerability
| Bugtraq ID: | 7892 |
| Class: | Design Error |
| CVE: |
CVE-2003-0450 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 13 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | The discovery of this vulnerability has been credited to "David Luyer" <[email protected]>. |
| Vulnerable: |
Miquel van Smoorenburg Cistron Radius 1.6.6 Miquel van Smoorenburg Cistron Radius 1.6.5 Miquel van Smoorenburg Cistron Radius 1.6.4 |
| Not Vulnerable: | |
Discussion
Cistron RADIUS Remote Signed NAS-Port Number Expansion Memory Corruption Vulnerability
A remote vulnerability has been discovered in Cistron RADIUS. The problem occurs due to a design error when processing user-supplied data. As a result, an attacker may transmit a signed value which when interperted could cause memory corruption.
The vulnerability occurs due to the incorrect usage of the '%d' format specifier when calling the sprintf() function.
A remote attacker could potentially exploit this issue to seize control of the RADIUS server's execution flow. If successful, this could be leveraged to execute arbitrary code with the privileges of the user invoking the process.
A remote vulnerability has been discovered in Cistron RADIUS. The problem occurs due to a design error when processing user-supplied data. As a result, an attacker may transmit a signed value which when interperted could cause memory corruption.
The vulnerability occurs due to the incorrect usage of the '%d' format specifier when calling the sprintf() function.
A remote attacker could potentially exploit this issue to seize control of the RADIUS server's execution flow. If successful, this could be leveraged to execute arbitrary code with the privileges of the user invoking the process.
References
Cistron RADIUS Remote Signed NAS-Port Number Expansion Memory Corruption Vulnerability
References:
References:
- Debian Bug report logs - #196063 (Debian)