Mandriva Linux Security Advisory 2009-227 – The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes. NOTE: this is a regression error related to CVE-2003-0967. This update provides a solution to this vulnerability. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/85006/MDVSA-2009-227-1.txt
Source: https://packetstormsecurity.com/files/85006/Mandriva-Linux-Security-Advisory-2009-227.html

