CVE-2004-0849: Integer Overflow
Integer overflow in the asndecodestring() function defined in asn1.c in radiusd for GNU Radius 1.1 and 1.2 before 1.2.94, when compiled with the --enable-snmp option, allows remote attackers to cause a denial of service (daemon crash) via certain SNMP requests.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0849?
CVE-2004-0849 is classified as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2004-0849?
To fix CVE-2004-0849, users should upgrade to GNU Radius version 1.2.94 or later.
What systems are affected by CVE-2004-0849?
CVE-2004-0849 affects GNU Radius versions 0.92.1, 0.93, 0.94, 0.95, 0.96, 1.1, and 1.2 when compiled with the --enable-snmp option.
What is the impact of exploiting CVE-2004-0849?
Exploiting CVE-2004-0849 can lead to a crash of the radiusd daemon, resulting in denial of service.
Is CVE-2004-0849 a remote vulnerability?
Yes, CVE-2004-0849 is considered a remote vulnerability as it can be triggered by sending specific SNMP requests.