Stack-Based Buffer Overflow in PPP by FreeBSD, OpenBSD, and NetBSD
CVE-2008-1215
Currently unrated
Summary
The vulnerability in PPP stems from a stack-based buffer overflow in the command_Expand_Interpret function. When local users issue long commands that include '~' characters, it may lead to privilege escalation, allowing them to execute commands with elevated permissions. This flaw affects specific versions of FreeBSD, OpenBSD, and NetBSD, posing a significant risk to user systems.
References
Timeline
Vulnerability published
Vulnerability Reserved