Skip to content

Topic

Unmaintained open-source software

Open-source projects whose maintainers have stopped releasing updates or responding to reports, leaving users without upstream security fixes.

Current clusters

build1 publisher

Elttam's two-packet exploit runs code on TACACS+ servers before anyone logs in

Elttam says a TACACS+ server flaw lets attackers run code before login with two packets and an offline crack of the protocol's weak encryption. Of the two main server codebases, Shrubbery Networks' has a fix that still has no CVE and Facebook's archived fork will get none, so the first job is finding out which daemon answers on port 49.

Publishers:news.risky.biz

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence40