VDB
Sign up
—

PYSEC-2019-154

Quick fix

PYSEC-2019-154 — pyrad: upgrade to the fixed version with the command below.

pip install --upgrade 'pyrad>=38f74b36814ca5b1a27d9898141126af4953bee5'

Details

The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pyrad
Introduced in: 0Fixed in: 38f74b36814ca5b1a27d9898141126af4953bee5
Fixpip install --upgrade 'pyrad>=38f74b36814ca5b1a27d9898141126af4953bee5'

References