FreeRADIUS versions 0.9.2 and below have a tunnel-password attribute handling vulnerability. When a malformed attribute trigger gets passed, the server invokes memcpy() with a negative third argument, causing a crash.
1dadd2e3ca40a13e9ce1eb8ddd2ae503f4b94a7f5a399a92dc7c8e84b1a03849
Debian Security Advisory - Within the last thirty hours, some Debian project machines have been compromised, including the bug tracking system, the mailing list, the cvs server, and more.
0ef12d03e523eef94f8b0292d280440a7f426a02ad7d189e7d7177ba2242a834