← Back

CVE-2001-1377

nvd nist
Published: Mar 4, 2002Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

Affected (40)

Products: Freeradius: Freeradius · Gnu: Radius · Icradius: Icradius · +8 more
Show all products
1 product
Freeradius
1 product
Radius
1 product
Icradius
1 product
Radius
1 product
Radius
Radius
1 product
Openradius
1 product
Radiusclient
1 product
Xtradius
1 product
Yard Radius
Yard Radius
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Freeradius
Version 0.2
Version 0.3
Gnu
Version 0.92.1
Version 0.93
Version 0.94
Version 0.95
Icradius
Version 0.14
Version 0.15
Version 0.16
Version 0.17
Version 0.17b
Version 0.18.1
Version 0.18
Livingston
Version 2.0.1
Version 2.0
Version 2.1
Lucent
Version 2.0.1
Version 2.0
Version 2.1
Version 1.6.1
Version 1.6.2
Version 1.6.3
Version 1.6.4
Version 1.6.5
Version 1.6_.0
Openradius
Version 0.8
Version 0.9.1
Version 0.9.2
Version 0.9.3
Version 0.9
Version 0.3.1
Xtradius
Version 1.1_pre1
Version 1.1_pre2
Yard Radius
Version 1.0.17
Version 1.0.18
Version 1.0.19
Version 1.0_pre13
Version 1.0_pre14
Version 1.0_pre15
Version 1.0.16

References (18)

ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:02.asc (unsafe URL)
Source: cve@mitre.org
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
PatchVendor Advisory
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:02.asc (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.