SecurityTeam US
 
 Welcome to SecurityTeam US
 Monday, February 06 2012 @ 12:43 PM EST

Apache mod_auth_radius Module Denial of Service Vulnerability

   
ApacheLSS has reported a vulnerability in the mod_auth_radius module for Apache, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an error in the handling of certain "RADIUS_ACCESS_CHALLENGE" RADIUS packets. This may be exploited via a man-in-the-middle attack to cause the mod_auth_radius service to crash.

The vulnerability has been reported in version 1.5.7 and prior.

SOFTWARE:
mod_auth_radius 1.x (module for Apache)

SOLUTION:
Only connect to trusted RADIUS servers and over trusted connections.

PROVIDED AND/OR DISCOVERED BY:
LSS

ORIGINAL ADVISORY:
http://security.lss.hr/en/index.php?page=details&ID=LSS-2005-01-02

VERIFY ADVISORY:
http://secunia.com/advisories/13773/

Secunia Security Advisories

 

What's Related

Story Options

Apache mod_auth_radius Module Denial of Service Vulnerability | 0 comments | Create New Account
The following comments are owned by whomever posted them. This site is not responsible for what they say.
 Copyright © 2012 SecurityTeam US
 All trademarks and copyrights on this page are owned by their respective owners.
  Get Firefox!
Dedicated Servers
Created this page in 0.15 seconds