Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hhg-rh8g-2x9h

Опубликовано: 15 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and overwrites arbitrary memory. If the server connects with a malicious client, crafted client requests can remotely trigger this vulnerability.

The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and overwrites arbitrary memory. If the server connects with a malicious client, crafted client requests can remotely trigger this vulnerability.

EPSS

Процентиль: 64%
0.00459
Низкий

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

The rad_packet_recv function in radius/packet.c suffers from a memcpy buffer overflow, resulting in an overly-large recvfrom into a fixed buffer that causes a buffer overflow and overwrites arbitrary memory. If the server connects with a malicious client, crafted client requests can remotely trigger this vulnerability.

EPSS

Процентиль: 64%
0.00459
Низкий

Дефекты

CWE-120