VDB
Sign up
—

PYSEC-2020-211

Quick fix

PYSEC-2020-211 — pyrad: upgrade to the fixed version with the command below.

pip install --upgrade 'pyrad>=38f74b36814ca5b1a27d9898141126af4953bee5'

Details

packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pyrad
Introduced in: 0Fixed in: 38f74b36814ca5b1a27d9898141126af4953bee5
Fixpip install --upgrade 'pyrad>=38f74b36814ca5b1a27d9898141126af4953bee5'

References