OSVDB ID: 85313

Title: PacketFence RADIUS Extension Custom VLAN Assignment Extension User-Name RADIUS Attribute Handling User Identity Spoofing

Info

Disclosure

Apr 13, 2012

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Apr 13, 2012

Description

PacketFence contains a flaw related to the RADIUS extension. This issue is triggered when the extension uses different user names for authentication for users using custom VLAN assignment extensions. With a specially crafted User-Name RADIUS attribute, a remote attacker can spoof a user's identity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Upgrade
Exploit: Exploit Unknown
Disclosure: Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 3.3.0 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Inverse

PacketFence

3.2.0

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/85313