Integer Overflow Vulnerability in Paul's PPP Package by Linux Vendors
CVE-2014-3158

Currently unrated

What is CVE-2014-3158?

An integer overflow in the getword function in options.c of the Paul's PPP Package (ppp) before version 2.4.7 can allow attackers to exploit privileged options. By injecting a long word into an options file, a heap-based buffer overflow occurs, leading to corruption of security-relevant variables. This vulnerability can potentially give attackers unauthorized access or control over the affected system, posing significant security risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.