Resource exhaustion in scapy - CVE-2019-1010142
Published: July 23, 2019 / Updated: July 24, 2019
scapy
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a lack of input validation while reading the length field in the RADIUS packet’s Attribute Value Pairs (AVP). A remote attacker can send a specially crafted packet that has an AVP with a length byte equal to zero and crash the target system.