The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15571
http://www.mandriva.com/security/advisories?name=MDKSA-2004:024
http://www.kb.cert.org/vuls/id/124454
http://security.gentoo.org/glsa/glsa-200403-07.xml
http://marc.info/?l=ethereal-dev&m=107962966700423&w=2