[prev in list] [next in list] [prev in thread] [next in thread] 

List:       freeradius-devel
Subject:    Re: Stack corruption
From:       aland () striker ! ottawa ! on ! ca
Date:       2001-11-29 21:34:01
[Download RAW message or body]

3APA3A <3APA3A@SECURITY.NNOV.RU> wrote:
> While  debugging  my  own  RADIUS client I've found remotely exploitable
> stack  corruption  problem in radiusd because of input validation bug in
> lib/radius.c rad_decode().

  That's a big "OUCH!"

  It also means that we should release 0.4 soon.

  Any comments?

  Alan DeKok.

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/devel.html

[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic