CVE-2005-0108

Publication date 11 January 2005

Last updated 24 July 2024


Ubuntu priority

Apache mod_auth_radius 1.5.4 and libpam-radius-auth allow remote malicious RADIUS servers to cause a denial of service (crash) via a RADIUS_REPLY_MESSAGE with a RADIUS attribute length of 1, which leads to a memcpy operation with a -1 length argument.

Status

Package Ubuntu Release Status
libpam-radius-auth 7.04 feisty
Fixed 1.3.16-4
6.10 edgy
Fixed 1.3.16-4
6.06 LTS dapper
Fixed 1.3.16-4