Check Point Advisories

GNU Radius SQL Accounting Format String (CVE-2006-4181)

Check Point Reference: CPAI-2006-283
Date Published: 27 Oct 2009
Severity: High
Last Updated: 10 Aug 2016
Industry Reference:CVE-2006-4181
Protection Provided by:

Security Gateway
R80, R77, R76, R75

Who is Vulnerable?
Vulnerability Description GNU Radius is a suite of applications which perform user authentication and accounting using the Remote Authentication Dial In User Service (RADIUS) protocol. The RADIUS protocol is specifically designed for authentication, authorization and accounting of various network services. RADIUS is most often used by operating systems and hardware devices that provide network access to remote users. There is a large number of RADIUS implementations available, both commercial and open source. The GNU Radius server is an open source implementation of the RADIUS protocol.There exists a format string vulnerability in the GNU Radius suite. The flaw may be exploited by sending a malicious request message to the Radius daemon. Successful exploitation may allow an attacker to inject and execute arbitrary code on the target host within the privileges of the Radius process.If the attack is not successful in code injection and execution, the target Radius server child process will terminate upon exploitation. The main Radius server process is not affected.If an attack results in successful code injection and its subsequent execution, the behaviour of the target host will depend on the intention of the attacker. Note that any code execution will occur within the security context of the affected service, normally root.

Protection Overview

This protection will detect and block attempts to exploit this vulnerability

In order for the protection to be activated, update your Security Gateway product to the latest IPS update.For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.

Security Gateway R80 / R77 / R76 / R75

  1. In the IPS tab, click Protections and find the GNU Radius SQL Accounting Format String protection using the Search tool and Edit the protection's settings.
  2. Install policy on all modules.

This protection's log will contain the following information:

Attack Name:  Application Servers Protection Violation
Attack Information:  GNU Radius SQL Accounting Format String

This website uses cookies to ensure you get the best experience. Got it, Thanks! MORE INFO