rad_packet_recv() currently parses attributes based on the received byte count (bytes_read-20) rather than the packet length field (pack->len). This can allow attributes beyond pack->len to be processed even though they are not authenticated.
Description
Description
Details
Details
- Version
- rolling
- Is it a breaking change?
- Perfectly compatible
- Issue type
- Security vulnerability
Related Objects
Related Objects