5
CVSSv2

CVE-2005-0108

Published: 11/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.

Vulnerable Product Search on Vulmon Subscribe to Product

apache mod auth radius 1.5.4

Vendor Advisories

Two problems have been discovered in the libpam-radius-auth package, the PAM RADIUS authentication module The Common Vulnerabilities and Exposures Project identifies the following problems: CAN-2004-1340 The Debian package accidentally installed its configuration file /etc/pam_radius_authconf world-readable Since it may possibly con ...