The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ethereal | Ethereal | 0.8.13 (including) | 0.10.3 (excluding) |
Red Hat Enterprise Linux 3 | RedHat | ethereal-0:0.10.3-0.30E.1 | * |
Red Hat Linux 9 | RedHat | * |