Page MenuHomeVyOS Platform

Accel-PPP: parse_framed_route stack buffer overflow via RADIUS Framed-Route in Access-Accept message
Closed, ResolvedPublic

Description

Unbounded strcpy in parse_framed_route (radius.c:94) copies up to 253 bytes of attacker-supplied RADIUS Framed-Route data (In Access-Accept message) into a 32-byte stack buffer.

Details

Version
-
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Security vulnerability

Event Timeline

RC changed the task status from Open to In progress.
RC triaged this task as High priority.
RC created this object in space S1 VyOS Public.
RC created this object with visibility "Administrators".
Viacheslav changed the visibility from "Administrators" to "Public (No Login Required)".Mon, Oct 5, 8:59 AM
Viacheslav moved this task from Need Triage to Completed on the VyOS Rolling board.