HomeSecurityCritical vulnerability in ppp Daemon allows remote access to Linux systems

Critical vulnerability in ppp Daemon allows remote access to Linux systems

A critical Buffer overflow vulnerability, which allowed remote users to access Linux and gain root-level privileges, was discovered in pppD (Point to Point Protocol Daemon).

pppD (Point to Point Daemon), is often used to manage network connections in Unix-based operating systems and is also used to manage broadband connections such as DSL, if PPPoE or PPPoA is used.

A researcher discovered this critical vulnerability located in the Extensible Authentication Protocol (EAP) packet processor in the Point-to-Point Protocol Daemon (pppd).

A remote attacker could exploit this vulnerability to cause a buffer overflow, which could allow attackers to execute arbitrary code on the target system.

vulnerability

The vulnerability, discovered by Ilja Van Sprundel and called CVE-2020-8597, is rated 9.3 CVE. GBHackers has not found any currently exploited code for this vulnerability.

The following are the Linux distributions in which this vulnerability has been confirmed to be present, running with pppd (Point to Point Daemon) versions 2.4.2 to 2.4.8.

Debian GNU/Linux

Fedora Project

Red Hat

SUSE Linux

Ubuntu

An updated version is also being released to the following vendors,

Cisco

NetBSD

OpenWRT

Synology

TP-LINK

The buffer overflow vulnerability affected several Linux due to a bug that invalidates the input size before copying the supplied data into memory.

During input size validation, if the data size validation is incorrect, it leads to Copying arbitrary data to memory and causes memory corruption which in turn allows attackers to remotely execute arbitrary code.

Since the data is unverified and the size is unknown, the vulnerability corrupts the system .

Also, PPP runs with elevated privileges and works in conjunction with driver , which allows attackers to gain root-.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS