Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function in version.c.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Livingston YardRadius 多个本地格式化字符串漏洞
Vulnerability Description
Yet Another Radius Daemon(又名YARD RADIUS)是美国Livingston公司的一款开源的Radius认证服务器。该服务器提供身份验证、远程和无线登录等功能。 Yet Another Radius Daemon (YARD RADIUS) 1.1.2版本中的src/log.c文件和src/version.c文件中存在多个格式化字符串漏洞。上下文相关的攻击者可通过发送包含恶意的格式字符串说明符的请求,利用这些漏洞造成拒绝服务(应用程序崩溃)或可能在受影响系统执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A