Heap
06-09-08, 02:43
CSRadius.exe in Cisco Secure ACS does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a crafted (1) EAP-Response/Identity, (2) EAP-Response/MD5, or (3) EAP-Response/TLS packet.
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2441)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-2441)