| /// File Name: | cisco-acs.txt | Description:
| Cisco Secure ACS does not correctly parse the length of EAP-Response packets which allows remote attackers to cause a denial of service and possibly execute arbitrary code. A remote attacker (acting as a RADIUS client) could send a specially crafted EAP Response packet against a Cisco Secure ACS server in such a way as to cause the CSRadius service to crash (reliable). This bug may be triggered if the length field of an EAP-Response packet has a certain big value, greater than the real packet length. | | Author: | Laurent Butti, Gabriel Campana | | File Size: | 2541 | | Related CVE(s): | CVE-2008-2441 | | Last Modified: | Sep 3 17:30:13 2008 | | MD5 Checksum: | af42d10de51f46d9fd8a6bf7ca0cf4ad |
|