Title: Livingston RADIUS Accounting Hostname Resolution Buffer Overflow Vulnerability
Severity: CRITICAL
Description:
Livingston Remote Authentication Dial In User Service (RADIUS) server is the Livingston implementation of the RFC 2138 defined protocol. It is available for the Unix and Linux operating systems.
A problem with RADIUS could make it possible for remote users to gain unauthorized access to vulnerable systems.
A buffer overflow in Livingston RADIUS has been discovered. Due to insufficient bounds checking in the accounting portion of the software, a buffer overflow may occur when an attempt to authenticate is made by a host with a hostname of excessive length. This could result in the execution of arbitrary code contained in a malicious hostname.
It should be noted that an attacker would require control of a name server to exploit this vulnerability. Additionally, the embedded code in the hostname is limited to the ASCII printable characters. This vulnerability also affects servers derived from the Livingston RADIUS source code.
Affected Products:
- Livingston RADIUS 1.16.0
References:
- Secure Networks, Inc.: Remote Vulnerability in RADIUS Servers Derived from Livingston 1.16
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.