Integer Overflow Vulnerability in Paul's PPP Package by Linux Vendors
CVE-2014-3158
Currently unrated
Key Information:
- Status
- Vendor
- CVE Published:
- 15 November 2014
What is CVE-2014-3158?
An integer overflow in the getword function in options.c of the Paul's PPP Package (ppp) before version 2.4.7 can allow attackers to exploit privileged options. By injecting a long word into an options file, a heap-based buffer overflow occurs, leading to corruption of security-relevant variables. This vulnerability can potentially give attackers unauthorized access or control over the affected system, posing significant security risks.
