Alerts This Week
Warning Icon 1 1,153
Alerts This Week
Warning Icon 1 1,153

Ubuntu: 4451-1 Critical: ppp Arbitrary Module Loading Issue

ubuntu
Calendar Grey August 4, 2020
Dist Ubuntu Esm H88
=========================================================================Ubuntu Security Notice USN-
ppp could be made to load arbitrary kernel modules and possibly run programs.

Summary

ppp could be made to load arbitrary kernel modules and possibly run

programs.

Software Description:

- ppp: Point-to-Point Protocol (PPP)

Details:

Thomas Chauchefoin discovered that ppp incorrectly handled module loading.

A local attacker could use this issue to load arbitrary kernel modules and

possibly execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  ppp                             2.4.7-2+4.1ubuntu5.1

Ubuntu 18.04 LTS:
  ppp                             2.4.7-2+2ubuntu1.3

Ubuntu 16.04 LTS:
  ppp                             2.4.7-1+2ubuntu1.16.04.3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4451-1

CVE-2020-15704

Severity
critical
Lowest
Low
Medium
High
Critical

August 04, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here