CVE-2001-1377

5 documents5 sources
Severity
5.0MEDIUM
EPSS
13.3%
top 5.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 4
Latest updateMay 3

Description

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages11 packages

NVDgnu/radius4 versions+3
NVDlucent/radius2.0, 2.0.1, 2.1+2
NVDicradius/icradius7 versions+6
NVDlivingston/radius2.0, 2.0.1, 2.1+2
NVDxtradius/xtradius1.1_pre1, 1.1_pre2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-365r-qwgj-mv9r: Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a2022-05-03
CVEList
CVE-2001-1377: Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a2002-06-11

📋Vendor Advisories

1
Red Hat
security flaw2001-11-13

💬Community

1
Bugzilla
CVE-2001-1377 security flaw2018-08-16