PT-2014-1917 · Ppp+2 · Ppp+2

Lee Campbell

·

Publicado

2014-09-03

·

Atualizado

2024-06-15

·

CVE-2014-3158

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ppp versions prior to 2.4.7
Description The issue is related to an integer overflow in the getword function in options.c in pppd, which can trigger a heap-based buffer overflow. This overflow can corrupt security-relevant variables, potentially allowing attackers to access privileged options. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 2.4.7, update to version 2.4.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the options file to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09784
CVE-2014-3158
DLA-74-1
DSA-3079-1
MGASA-2014-0368
OPENSUSE-SU-2024:10049-1
SUSE-SU-2014_1088-1
USN-2429-1

Produtos afetados

Suse
Ubuntu
Ppp