Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.
| Software | From | Fixed in |
|---|---|---|
| simon_horms / radius | 2.1_2 | 2.1_2.x |
| lucent / radius | 2.1.2 | 2.1.2.x |