CVE-2015-9542
published 2020-02-24CVE-2015-9542: add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.54%
88.1th percentile
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libpam-radius-auth | < libpam-radius-auth 1.4.0-3 (bookworm) | libpam-radius-auth 1.4.0-3 (bookworm) |
| freeradius | pam_radius | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libpam-radius-auth vulnerability
vendor_ubuntu·2020-03-03
CVE-2015-9542 libpam-radius-auth vulnerability
Title: libpam-radius-auth vulnerability
Summary: libpam-radius-auth could be made to crash if it received specially crafted
network traffic.
USN-4290-1 fixed a vulnerability in libpam-radius-auth. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that libpam-radius-auth incorrectly handled certain long
passwords. A remote attacker could possibly use this issue to cause
libpam-radius-auth to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libpam-radius-auth vulnerability
vendor_ubuntu·2020-02-24
CVE-2015-9542 libpam-radius-auth vulnerability
Title: libpam-radius-auth vulnerability
Summary: libpam-radius-auth could be made to crash if it received specially crafted
network traffic.
It was discovered that libpam-radius-auth incorrectly handled certain long
passwords. A remote attacker could possibly use this issue to cause
libpam-radius-auth to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pam_radius: buffer overflow in password field
vendor_redhat·2020-02-12·CVSS 7.5
CVE-2015-9542 [HIGH] CWE-121 pam_radius: buffer overflow in password field
pam_radius: buffer overflow in password field
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
Statement: As shipped in epel-6, the gcc compiler opts for __memcpy_chk() [with the correct buffer length] to ensure that there is a crash instead of an an overflow. Thus it is believed that only a Deianl of Service can be triggered using this flaw.
Debian
CVE-2015-9542: libpam-radius-auth - add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check t...
vendor_debian·2015·CVSS 7.5
CVE-2015-9542 [HIGH] CVE-2015-9542: libpam-radius-auth - add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check t...
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
Scope: local
bookworm: resolved (fixed in 1.4.0-3)
bullseye: resolved (fixed in 1.4.0-3)
forky: resolved (fixed in 1.4.0-3)
sid: resolved (fixed in 1.4.0-3)
trixie: resolved (fixed in 1.4.0-3)
GHSA
GHSA-x66h-w4xq-44q4: add_password in pam_radius_auth
ghsa_unreviewed·2022-05-24
CVE-2015-9542 [HIGH] CWE-787 GHSA-x66h-w4xq-44q4: add_password in pam_radius_auth
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
OSV
CVE-2015-9542: add_password in pam_radius_auth
osv·2020-02-24·CVSS 7.5
CVE-2015-9542 [HIGH] CVE-2015-9542: add_password in pam_radius_auth
add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might be possible, depending on the application, C library, compiler, and other factors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-9542 pam_radius: buffer overflow in password field [epel-6]
bugzilla·2020-02-12·CVSS 7.5
CVE-2015-9542 [HIGH] CVE-2015-9542 pam_radius: buffer overflow in password field [epel-6]
CVE-2015-9542 pam_radius: buffer overflow in password field [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update
Bugzilla
CVE-2015-9542 pam_radius: buffer overflow in password field
bugzilla·2019-03-08·CVSS 7.5
CVE-2015-9542 [HIGH] CVE-2015-9542 pam_radius: buffer overflow in password field
CVE-2015-9542 pam_radius: buffer overflow in password field
A vulnerability was found in pam_radius : the password length check was done incorrectly in the add_password() function, resulting in a stack based buffer overflow.
This could be used to crash (DoS) an application using the PAM stack for authentication.
Discussion:
Upstream fixes :
https://github.com/FreeRADIUS/pam_radius/commit/01173ec
https://github.com/FreeRADIUS/pam_radius/commit/6bae92d
https://github.com/FreeRADIUS/pam_radius/commit/ac2c1677
---
Created pam_radius tracking bugs for this issue:
Affects: epel-6 [bug 1802060]
---
- Fixed in epel-8 since release,
- Fixed in Fedora since pam_radius-1.4.0-14 (in Fedora 28),
- Fixed in epel-7 since pam_radius-1.4.0-4.
---
Statement:
As shipped in epel-6, the gcc compile
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-9542https://github.com/FreeRADIUS/pam_radius/commit/01173ec2426627dbb1e0d96c06c3ffa0b14d36d0https://lists.debian.org/debian-lts-announce/2020/02/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00000.htmlhttps://usn.ubuntu.com/4290-1/https://usn.ubuntu.com/4290-2/https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-9542https://github.com/FreeRADIUS/pam_radius/commit/01173ec2426627dbb1e0d96c06c3ffa0b14d36d0https://lists.debian.org/debian-lts-announce/2020/02/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00000.htmlhttps://usn.ubuntu.com/4290-1/https://usn.ubuntu.com/4290-2/
2020-02-24
Published