The web server in IEA Software RadiusNT and RadiusX 5.1.38...
Vulnerability Description
The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Marshal 2.0.4 and other versions before 2.0.8, and Radius test client (aka Radlogin) 4.0.20 and earlier, allows remote attackers to cause a denial of service (crash) via an HTTP Content-Length header with a negative value, which triggers a single byte overwrite of memory using a NULL terminator. NOTE: some of these details are obtained from third party information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-5284
Credits & Attribution
No credits recorded in the NVD database.
References
- http://aluigi.altervista.org/adv/emerdal-adv.txt
- http://www.iea-software.com/docs/Radius40/changes.txt
- http://www.securityfocus.com/bid/27701
- http://secunia.com/advisories/28846
- http://www.vupen.com/english/advisories/2008/0484
- http://www.securityfocus.com/archive/1/487810/100/200/threaded
- http://www.iea-software.com/docs/airmarshal1/changes.txt
- http://www.iea-software.com/docs/Emerald5/changes.txt
Affected Vendor
iea software
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.