packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Pyrad | Pyrad_project | * | 2.1 (excluding) |
Pyrad | Ubuntu | hardy | * |
Pyrad | Ubuntu | lucid | * |
Pyrad | Ubuntu | oneiric | * |
Pyrad | Ubuntu | precise | * |
Pyrad | Ubuntu | quantal | * |
Pyrad | Ubuntu | raring | * |
Pyrad | Ubuntu | saucy | * |
Pyrad | Ubuntu | upstream | * |
Pyrad | Ubuntu | utopic | * |
Pyrad | Ubuntu | vivid | * |
Pyrad | Ubuntu | wily | * |