GLSA Advocate
![Advocate Advocate](/images/ranks/rank-G-1-advocate.gif)
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Dec 13, 2014 11:26 pm Post subject: [ GLSA 201412-19 ] PPP: Information disclosure |
|
|
Gentoo Linux Security Advisory
Title: PPP: Information disclosure (GLSA 201412-19)
Severity: normal
Exploitable: local
Date: December 13, 2014
Bug(s): #519650
ID: 201412-19
Synopsis
An integer overflow in PPP might allow local attackers to obtain
sensitive information.
Background
PPP is a Unix implementation of the Point-to-Point Protocol
Affected Packages
Package: net-dialup/ppp
Vulnerable: < 2.4.7
Unaffected: >= 2.4.7
Architectures: All supported architectures
Description
Integer overflow is discovered in the getword function in options.c in
PPP
Impact
A local attacker could execute process with extremely long options list,
possibly obtaining sensitive information.
Workaround
There is no known workaround at this time.
Resolution
All PPP users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-dialup/ppp-2.4.7"
|
References
CVE-2014-3158 |
|