Resource exhaustion in scapy - CVE-2019-1010142
Published: July 23, 2019 / Updated: July 24, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a lack of input validation while reading the length field in the RADIUS packet’s Attribute Value Pairs (AVP). A remote attacker can send a specially crafted packet that has an AVP with a length byte equal to zero and crash the target system.
Affected software
Fedora
scapy
How to mitigate CVE-2019-1010142
scapy - addressed in versions 2.4.3-1.fc30, 2.4.3-1.fc31, 2.4.3-2.el7, 2.4.3-2.el8, 2.4.3-2.fc29