CVE-2001-1377: Medium severity yard radius yard radius vulnerability
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1377?
CVE-2001-1377 has been classified as a denial of service vulnerability which could potentially lead to system crashes.
How do I fix CVE-2001-1377?
To mitigate CVE-2001-1377, update your RADIUS implementation to a version that properly validates the Vendor-Length attribute.
Which RADIUS software is affected by CVE-2001-1377?
CVE-2001-1377 affects multiple RADIUS implementations including FreeRADIUS, Lucent RADIUS, and several versions of OpenRADIUS and Yard RADIUS.
Can CVE-2001-1377 be exploited remotely?
Yes, CVE-2001-1377 can be exploited remotely, allowing attackers to cause a denial of service by sending specially crafted requests.
What are the consequences of not addressing CVE-2001-1377?
Failing to address CVE-2001-1377 may result in service interruptions or crashes, affecting the availability of RADIUS services.