Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3111 http://freeradius.org/security.html
http://www.milw0rm.com/exploits/9642
http://www.vuxml.org/freebsd/1b3f854b-e4bd-11de-b276-000d8787e1be.html
Insight
The following package is affected: freeradius
CVE-2009-3111
The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes. NOTE: this is a regression error related to CVE-2003-0967.
Severity
Classification
-
CVE CVE-2009-3111 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities