cve/2022/CVE-2022-24704.md
2024-05-25 21:48:12 +02:00

861 B

CVE-2022-24704

Description

The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby user input len is copied into a fixed buffer &attr->val.integer without any bound checks. If the client connects to the server and sends a large radius packet, a buffer overflow vulnerability will be triggered.

POC

Reference

No PoCs from references.

Github