Executive brief
Livingston RADIUS is a software component used to manage user authentication and access for network services. A security flaw in this software allows a remote attacker to take complete control of the server by executing commands with administrative (root) privileges. This could lead to a total compromise of the authentication system and any sensitive data it manages.
Technical details
A buffer overflow vulnerability exists in the Livingston RADIUS server implementation. The flaw is located within the code responsible for processing incoming network requests, where insufficient bounds checking allows an attacker to overwrite memory. By sending a specially crafted packet over the network, an unauthenticated remote attacker can trigger the overflow to redirect execution flow and run arbitrary commands as the root user. This vulnerability is exploitable without user interaction and poses a significant risk to the integrity and availability of the authentication service.
Affected products
- Livingston Enterprises RADIUS
Timeline
- 1997-12-01: disclosed