Описание
pyrad uses sequential packet IDs
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-0342
- https://github.com/pyradius/pyrad/commit/38f74b36814ca5b1a27d9898141126af4953bee5
- https://bugzilla.redhat.com/show_bug.cgi?id=911685
- https://exchange.xforce.ibmcloud.com/vulnerabilities/82134
- https://github.com/pypa/advisory-database/tree/main/vulns/pyrad/PYSEC-2019-154.yaml
- https://web.archive.org/web/20200302193833/http://www.securityfocus.com/bid/57984
- http://www.openwall.com/lists/oss-security/2013/02/15/9
- http://www.openwall.com/lists/oss-security/2013/02/21/27
- http://www.openwall.com/lists/oss-security/2013/02/22/2
Пакеты
pyrad
< 2.1
2.1
Связанные уязвимости
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
The CreateID function in packet.py in pyrad before 2.1 uses sequential ...