The package radiusd-cistron is an implementation of the RADIUS protocol. Unfortunately the RADIUS server handles too large NAS numbers not correctly. This leads to overwriting internal memory of the server process and may be abused to gain remote access to the system the RADIUS server is running on.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
openSUSE | 7.3 | i386 | radiusd-cistron | < 1.6.4-182 | radiusd-cistron-1.6.4-182.i386.rpm |
openSUSE | 7.3 | ppc | radiusd-cistron | < 1.6.4-108 | radiusd-cistron-1.6.4-108.ppc.rpm |
openSUSE | 7.3 | sparc | radiusd-cistron | < 1.6.4-70 | radiusd-cistron-1.6.4-70.sparc.rpm |
openSUSE | 8.0 | i386 | radiusd-cistron | < 1.6.6-88 | radiusd-cistron-1.6.6-88.i386.rpm |
openSUSE | 7.2 | i386 | radiusd-cistron | < 1.6.4-182 | radiusd-cistron-1.6.4-182.i386.rpm |