Integer Underflow in PPP Daemon Affects Remote Connectivity
CVE-2004-1002

7.5HIGH

What is CVE-2004-1002?

An integer underflow vulnerability exists in the PPP daemon (pppd) version 2.4.1, specifically in the cbcp.c file, which can be exploited by remote attackers. By sending a crafted CBCP packet with an invalid length value, an attacker could trigger a denial of service condition, leading to a crash of the pppd daemon. This would result in interrupted connectivity and potential denial of service for users relying on the PPP service.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.