LWN.net Logo

ppp: denial of service

Package(s):ppp CVE #(s):
Created:October 29, 2004 Updated:November 3, 2004
Description: Improper verification of header fields lets an attacker make the pppd server access memory it isn't allowed to, and crash the server. There is no possibility of code execution, as there is no data being copied, just a pointer dereferenced. It is not even entirely clear that this vulnerability can be exploited to deny service to anybody other than the attacker.

See this security focus advisory for details.

Alerts:
Gentoo 200411-01 2004-11-01
Ubuntu USN-12-1 2004-10-29

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds