Package name freeradius
Date April 16th, 2007
Advisory ID MDKSA-2007:085
Affected versions 2007.0, CS4.0, 2007.1
Synopsis Updated freeradius packages fix DoS vulnerability
Problem Description
Memory leak in freeRADIUS 1.1.5 and earlier allows remote attackers to
cause a denial of service (memory consumption) via a large number of
EAP-TTLS tunnel connections using malformed Diameter format attributes,
which causes the authentication request to be rejected but does not
reclaim VALUE_PAIR data structures.
Updated packages have been patched to correct this issue.