CVE-2001-1377

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/03/2002
Last modified:
03/04/2025

Description

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freeradius:freeradius:0.2:*:*:*:*:*:*:*
cpe:2.3:a:freeradius:freeradius:0.3:*:*:*:*:*:*:*
cpe:2.3:a:gnu:radius:0.92.1:*:*:*:*:*:*:*
cpe:2.3:a:gnu:radius:0.93:*:*:*:*:*:*:*
cpe:2.3:a:gnu:radius:0.94:*:*:*:*:*:*:*
cpe:2.3:a:gnu:radius:0.95:*:*:*:*:*:*:*
cpe:2.3:a:icradius:icradius:0.14:*:*:*:*:*:*:*
cpe:2.3:a:icradius:icradius:0.15:*:*:*:*:*:*:*
cpe:2.3:a:icradius:icradius:0.16:*:*:*:*:*:*:*
cpe:2.3:a:icradius:icradius:0.17:*:*:*:*:*:*:*
cpe:2.3:a:icradius:icradius:0.17b:*:*:*:*:*:*:*
cpe:2.3:a:icradius:icradius:0.18:*:*:*:*:*:*:*
cpe:2.3:a:icradius:icradius:0.18.1:*:*:*:*:*:*:*
cpe:2.3:a:livingston:radius:2.0:*:*:*:*:*:*:*
cpe:2.3:a:livingston:radius:2.0.1:*:*:*:*:*:*:*