Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 7: MGASA-2020-0139 Critical: ppp Buffer Overflow Fix

mageia
Calendar Grey March 12, 2020
Dist Mageia Esm H88
Mageia 2020-0140 resolves a significant security vulnerability in OpenSSL impacting Mageia 8 under particular circumstances.
Updated ppp packages fix security vulnerability: Ilja Van Sprundel discovered a buffer overflow vulnerability in ppp

Summary

Updated ppp packages fix security vulnerability:
Ilja Van Sprundel discovered a buffer overflow vulnerability in ppp. When receiving an EAP Request message in client mode, an attacker was able to overflow the rhostname array by providing a very long name (CVE-2020-8597).

References

- https://bugs.mageia.org/show_bug.cgi?id=26217

- https://lists.debian.org/debian-lts-announce/2020/02/msg00005.html

- https://www.cve.org/CVERecord?id=CVE-2020-8597

Resolution

SRPMS

- 7/core/ppp-2.4.7-13.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0139.html
Type: security
CVE: CVE-2020-8597

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here