Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8597

Опубликовано: 03 фев. 2020
Источник: redhat
CVSS3: 9.8

Описание

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

A buffer overflow flaw was found in the ppp package in versions 2.4.2 through 2.4.8. The bounds check for the rhostname was improperly constructed in the EAP request and response functions which could allow a buffer overflow to occur. Data confidentiality and integrity, as well as system availability, are all at risk with this vulnerability.

Отчет

The ppp packages distributed with Red Hat Enterprise Linux versions are compiled using gcc's stack-protector feature. The "Stack Smashing Protection" may help mitigate code execution attacks for this flaw and limit its impact to crash only.

Меры по смягчению последствий

Red Hat is working on providing updates packages which patches this flaw. This flaw can only be mitigated by updating to these package versions. The "Stack Smashing Protection" may help mitigate code execution attacks for this flaw and limit its impact to crash only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pppOut of support scope
Red Hat Enterprise Linux 5rp-pppoeNot affected
Red Hat Enterprise Linux 6rp-pppoeNot affected
Red Hat Enterprise Linux 7rp-pppoeNot affected
Red Hat Enterprise Linux 6pppFixedRHSA-2020:063127.02.2020
Red Hat Enterprise Linux 7pppFixedRHSA-2020:063027.02.2020
Red Hat Enterprise Linux 8pppFixedRHSA-2020:063327.02.2020
Red Hat Enterprise Linux 8pppFixedRHSA-2020:063327.02.2020
Red Hat Enterprise Linux 8.0 Update Services for SAP SolutionspppFixedRHSA-2020:063427.02.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1800727ppp: Buffer overflow in the eap_request and eap_response functions in eap.c

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 5 лет назад

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

CVSS3: 9.8
nvd
больше 5 лет назад

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

CVSS3: 9.8
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 9.8
debian
больше 5 лет назад

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overf ...

suse-cvrf
больше 5 лет назад

Security update for ppp

9.8 Critical

CVSS3

Уязвимость CVE-2020-8597