GNU Radius asn_decode_string integer overflow
| radius-asndecodestring-bo (17391) |
Description:
GNU Radius (Remote Authentication Dial In User Service) is vulnerable to a denial of service attack, caused by an integer overflow in the asn_decode_string function in the snmplib/asn1.c file. By supplying a large unsigned number, a remote attacker could overflow a buffer to cause the radiusd to crash.
Platforms Affected:
- Digital, OSF/1
- GNU, Radius 1.2
Remedy:
Upgrade to the latest maintenance release version of GNU Radius (1.2.94 or later), available from the GNU Radius Web page. See References.
Consequences:
Denial of Service
References:
- iDEFENSE Security Advisory 09.15.04, GNU Radius SNMP String Length Integer Overflow Denial of Service Vulnerability at http://www.idefense.com/application/poi/display?id=141&type=vulnerabilities&flashstatus=true.
- BID-11198: GNU Radius SNMP String Length Remote Denial Of Service Vulnerability
- CVE-2004-0849: Integer overflow in the asn_decode_string() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.
Reported:
Sep 15, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
