VYPR
Critical severity9.8OSV Advisory· Published Jun 14, 2018· Updated Jun 17, 2026

CVE-2018-11574

CVE-2018-11574

Description

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the refuse-app option are unaffected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Range: ppp-2.0.4, ppp-2.1.1, ppp-2.1.2, …
  • cpe:2.3:a:point-to-point_protocol_project:point-to-point_protocol:*:*:*:*:*:*:*:*
    Range: <2.4.9
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*+ 2 more
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
  • PPPD/PPPDllm-create
    Range: 0.91

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.