CVE-2001-1377

Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

Date published : 2002-06-11

http://www.securityfocus.com/bid/4230

http://marc.info/?l=bugtraq&m=101537153021792&w=2