"evaluatorSolution":"This vulnerability is addressed in the following product release:\r\nGNU, Radius, 1.4",
"descriptions":[
{
"lang":"en",
"value":"Format string vulnerability in the sqllog function in the SQL accounting code for radiusd in GNU Radius 1.2 and 1.3 allows remote attackers to execute arbitrary code via unknown vectors."
},
{
"lang":"es",
"value":"Vulnerabilidad de cadena de formato en la funci\u00f3n sqllog en el c\u00f3digo de tarificaci\u00f3n SQL para radiusd en GNU Radius 1.2 y 1.3 permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de vectores no especificados."
}
],
"vendorComments":[
{
"organization":"Red Hat",
"comment":"Not Vulnerable. Red Hat does not ship GNU Radius in Red Hat Enterprise Linux 2.1, 3, or 4.",