>> FreeRADIUS EAP-MSCHAPv2 Security Bypass and Denial of Service Vulnerability
Title : FreeRADIUS EAP-MSCHAPv2 Security Bypass and Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-1016 CVE ID : CVE-2006-1354
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-03-21
Technical Description
A vulnerability has been identified in FreeRADIUS, which could be exploited by attackers to cause a denial of service. This flaw is due to an input validation error in the EAP-MSCHAPv2 module when handling an EAP-MSCHAPv2 state machine, which could be exploited by a malicious radius client to bypass server authentication checks and cause a vulnerable server to crash.