Vulnerabilities > CVE-2001-1377 - Denial Of Service vulnerability in Multiple Vendor Radius Short Vendor-Length Field

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL

Summary

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

Redhat

advisories
rhsa
idRHSA-2002:030