VYPR

ppp

by FreeBSD

CVEs (6)

  • CVE-2026-58096HigAug 26, 2026
    risk 0.57cvss 8.8epss 0.01

    LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or…

  • CVE-2026-58095HigAug 26, 2026
    risk 0.57cvss 8.8epss 0.01

    mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.

  • CVE-2026-58097HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.

  • CVE-2008-1215Mar 9, 2008
    risk 0.03cvss —epss 0.01

    Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~"…

  • CVE-2000-1167Jan 9, 2001
    risk 0.00cvss —epss 0.02

    ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target system.

  • CVE-1999-1385Dec 19, 1996
    risk 0.00cvss —epss 0.00

    Buffer overflow in ppp program in FreeBSD 2.1 and earlier allows local users to gain privileges via a long HOME environment variable.