PT-2015-6143 · Ppp+2 · Ppp+2

Emanuele Rocca

·

Published

2015-04-16

·

Updated

2024-06-15

·

CVE-2015-3310

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ppp versions 2.4.6 and earlier
Description A buffer overflow issue exists in the rc mksid function, located in plugins/radius/util.c, which can be triggered when the PID for pppd exceeds 65535. This allows remote attackers to cause a denial of service by sending a start accounting message to the RADIUS server.
Recommendations For versions 2.4.6 and earlier, consider restricting the PID for pppd to 65535 or less as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-44211
CVE-2015-3310
DLA-205-1
DSA-3228-1
MGASA-2015-0173
OPENSUSE-SU-2024:10049-1
SUSE-SU-2017:0473-1
SUSE-SU-2017:0474-1
SUSE-SU-2017_0473-1
SUSE-SU-2017_0474-1
USN-2595-1

Affected Products

Suse
Ubuntu
Ppp