[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2020-8597Date: (C)2020-02-04   (M)2023-12-22


eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 9.8CVSS Score : 7.5
Exploit Score: 3.9Exploit Score: 10.0
Impact Score: 5.9Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector: NETWORK
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: NONEAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: UNCHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
http://seclists.org/fulldisclosure/2020/Mar/6
DSA-4632
FEDORA-2020-4304397fe0
FEDORA-2020-571091c70b
GLSA-202003-19
RHSA-2020:0630
RHSA-2020:0631
RHSA-2020:0633
RHSA-2020:0634
USN-4288-1
USN-4288-2
VU#782301
https://lists.debian.org/debian-lts-announce/2020/02/msg00005.html
http://packetstormsecurity.com/files/156662/pppd-2.4.8-Buffer-Overflow.html
http://packetstormsecurity.com/files/156802/pppd-2.4.8-Buffer-Overflow.html
https://cert-portal.siemens.com/productcert/pdf/ssa-809841.pdf
https://github.com/paulusmack/ppp/commit/8d7970b8f3db727fe798b65f3377fe6787575426
https://kb.netgear.com/000061806/Security-Advisory-for-Unauthenticated-Remote-Buffer-Overflow-Attack-in-PPPD-on-WAC510-PSV-2020-0136
https://security.netapp.com/advisory/ntap-20200313-0004/
https://us-cert.cisa.gov/ics/advisories/icsa-20-224-04
https://www.synology.com/security/advisory/Synology_SA_20_02
openSUSE-SU-2020:0286

CPE    2
cpe:/o:debian:debian_linux:9.0
cpe:/o:canonical:ubuntu_linux:18.04::~~lts~~~
CWE    1
CWE-120
OVAL    21
oval:org.secpod.oval:def:62011
oval:org.secpod.oval:def:503541
oval:org.secpod.oval:def:89043921
oval:org.secpod.oval:def:503542
...

© SecPod Technologies