CVE-2020-28194

Publication date

2021-02-01 13:13:47

Family

mitre

State

PUBLISHED

Description

Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.