Unbounded strcpy in parse_framed_route (radius.c:94) copies up to 253 bytes of attacker-supplied RADIUS Framed-Route data (In Access-Accept message) into a 32-byte stack buffer.
Description
Description
Details
Details
- Version
- -
- Is it a breaking change?
- Unspecified (possibly destroys the router)
- Issue type
- Security vulnerability