UBUNTU-CVE-2018-11574
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-11574
UBUNTU-CVE-2018-11574
Summary:
Details: Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.
References: https://ubuntu.com/security/CVE-2018-11574, http://www.openwall.com/lists/oss-security/2018/06/11/1, https://www.nikhef.nl/~janjust/ppp/ppp-2.4.7-eaptls-mppe-1.101.patch, https://ubuntu.com/security/notices/USN-3810-1, https://www.cve.org/CVERecord?id=CVE-2018-11574
Affected packages
Package
Name: ppp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
