PT-2020-14246 · Accel-Ppp+1 · Accel-Ppp+1

Leommxj

+1

·

Published

2020-09-09

·

Updated

2021-11-18

·

CVE-2020-15173

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ACCEL-PPP (affected versions not specified)
Description A buffer overflow issue occurs when receiving an L2TP control packet with an AVP of type string and no hidden flags, where the length is set to less than 6. This issue is particularly concerning for applications used in open networks or those with untrusted nodes.
Recommendations Apply the patch from commit 2324bcd5ba12cf28f47357a8f03cd41b7c04c52b to resolve the issue. As a temporary workaround, changes from commit 2324bcd5ba12cf28f47357a8f03cd41b7c04c52b can be applied to older versions.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2909
ALT-PU-2020-2941
CVE-2020-15173
GHSA-RR68-FCHR-69VF

Affected Products

Accel-Ppp
Alt Linux