PT-2020-14246 · Accel-Ppp+1 · Accel-Ppp+1
Leommxj
+1
·
Published
2020-09-09
·
Updated
2021-11-18
·
CVE-2020-15173
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ACCEL-PPP (affected versions not specified)
Description
A buffer overflow issue occurs when receiving an L2TP control packet with an AVP of type string and no hidden flags, where the length is set to less than 6. This issue is particularly concerning for applications used in open networks or those with untrusted nodes.
Recommendations
Apply the patch from commit 2324bcd5ba12cf28f47357a8f03cd41b7c04c52b to resolve the issue.
As a temporary workaround, changes from commit 2324bcd5ba12cf28f47357a8f03cd41b7c04c52b can be applied to older versions.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Accel-Ppp
Alt Linux