Description
Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function in version.c.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Hamid Zamani · textlocalwindows
https://www.exploit-db.com/exploits/38672
References (5)
Scores
EPSS
0.1057
EPSS Percentile
93.3%
Details
CWE
CWE-134
Status
published
Products (1)
yard_radius_project/yard_radius
1.1.2-4
Published
Aug 09, 2013
Tracked Since
Feb 18, 2026