Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11574

Опубликовано: 12 июн. 2018
Источник: redhat
CVSS3: 7.5

Описание

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the refuse-app option are unaffected.

Меры по смягчению последствий

PPP instances must be configured for EAP-TLS authentication to expose this vulnerability. For ppp servers, the file /etc/ppp/eaptls-server' must exist. For clients, either /etc/ppp/eaptls-clientmust exist or command-line optionsca, certandkey` must be provided.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pppNot affected
Red Hat Enterprise Linux 6pppNot affected
Red Hat Enterprise Linux 7pppWill not fix
Red Hat Enterprise Linux 8pppNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1586071ppp: Remote client crash in ppp EAP-TLS patch

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.

CVSS3: 9.8
nvd
больше 7 лет назад

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.

CVSS3: 9.8
debian
больше 7 лет назад

Improper input validation together with an integer overflow in the EAP ...

CVSS3: 9.8
github
больше 3 лет назад

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.

7.5 High

CVSS3