Stack-Based Buffer Overflow in PPP by FreeBSD, OpenBSD, and NetBSD
CVE-2008-1215

Currently unrated

Key Information:

Vendor
OpenBSD
Vendor
CVE Published:
9 March 2008

Summary

The vulnerability in PPP stems from a stack-based buffer overflow in the command_Expand_Interpret function. When local users issue long commands that include '~' characters, it may lead to privilege escalation, allowing them to execute commands with elevated permissions. This flaw affects specific versions of FreeBSD, OpenBSD, and NetBSD, posing a significant risk to user systems.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.