2.2.0 crash at a strange location

Stefan Winter stefan.winter at restena.lu
Mon May 6 12:53:04 CEST 2013


Hi,

>> [pap] login attempt with password "eq346ici"
>> [pap] Using SSHA encryption.
>> [pap] Normalizing SSHA1-Password from base64 encoding
>> Segmentation fault
> 
> this looks very much like another case which was being discussed on the users mailing list
> only last week(?) - same looking crash location.

I found the issue finally, detailed mail coming up, but for short:

Passwords can bei either HEX or BASE64 encoded. FreeRADIUS has a
heuristics to determine what it has to do with the incoming string. In
this case, the heuristics failed quite horribly.

Stefan


-- 
Stefan WINTER
Ingenieur de Recherche
Fondation RESTENA - Réseau Téléinformatique de l'Education Nationale et
de la Recherche
6, rue Richard Coudenhove-Kalergi
L-1359 Luxembourg

Tel: +352 424409 1
Fax: +352 422473

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 263 bytes
Desc: OpenPGP digital signature
URL: <http://lists.freeradius.org/pipermail/freeradius-devel/attachments/20130506/974c5790/attachment.pgp>


More information about the Freeradius-Devel mailing list