CVE-2020-8597
03.02.2020, 23:15
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| point-to-point_protocol_project | point-to-point_protocol | 2.4.2 ≤ 𝑥 ≤ 2.4.8 |
| wago | pfc_firmware | 𝑥 < 03.04.10\(16\) |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.04 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| lwip |
| ||||||||||||||||||||||||||
| ppp |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ppp |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| ppp-devel |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| network-scripts-ppp |
| ||||||||||
| ppp |
| ||||||||||
| ppp-devel |
|
References