First published: Fri Jul 06 2001(Updated: )
Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simon Horms Radius | =2.1_2 | |
Lucent RADIUS | =2.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1081 is considered a high severity vulnerability due to its potential for remote code execution and denial of service.
To fix CVE-2001-1081, upgrade to a version of Livingston/Lucent RADIUS that is not vulnerable, specifically version 2.1.va.1 or later.
CVE-2001-1081 affects users of Livingston/Lucent RADIUS versions before 2.1.va.1, including 2.1_2 and 2.1.2.
The implications of CVE-2001-1081 include the potential for attackers to execute arbitrary code and disrupt services by causing a denial of service.
Yes, CVE-2001-1081 can be exploited remotely, allowing attackers to potentially gain unauthorized access to systems.