Ppp
by Ppp Project
Source repositories
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-58250 | Cri | 0.53 | 9.3 | 0.00 | Apr 22, 2025 | The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges. | ||
| CVE-2022-4603 | 0.00 | — | 0.01 | Dec 18, 2022 | A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this… | |||
| CVE-2014-3158 | 0.00 | — | 0.04 | Nov 15, 2014 | Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options file, which triggers a heap-based buffer overflow that "[corrupts] security-relevant variables." | |||
| CVE-2006-2194 | 0.00 | — | 0.00 | Jul 5, 2006 | The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents… |
- risk 0.53cvss 9.3epss 0.00
The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
- CVE-2022-4603Dec 18, 2022risk 0.00cvss —epss 0.01
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this…
- CVE-2014-3158Nov 15, 2014risk 0.00cvss —epss 0.04
Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options file, which triggers a heap-based buffer overflow that "[corrupts] security-relevant variables."
- CVE-2006-2194Jul 5, 2006risk 0.00cvss —epss 0.00
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents…