Article 506CK [pppd] how to check the security issue CVE-2020-8597

[pppd] how to check the security issue CVE-2020-8597

by
beziabdelkarim
from LinuxQuestions.org on (#506CK)
Hello,

I need to check the following security issue on my ppp client machine (linux)

-eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

I'm using pppd 2.4.5.

Unfortunately no useful details is available on forums regarding this.

The idea is to have a reproduction scenario (test, tool, commands, setup) to reproduce this problem.

If reproduced, I'llupgrade my pppd daemon to the latest version (containing the fix) and redo the same check to confirm.

Any useful information is welcome.

THANKS FOR YOUR HELPlatest?d=yIl2AUoC8zA latest?i=ZnGjJJkcYS4:5owWk5K1yR4:F7zBnMy latest?i=ZnGjJJkcYS4:5owWk5K1yR4:V_sGLiP latest?d=qj6IDK7rITs latest?i=ZnGjJJkcYS4:5owWk5K1yR4:gIN9vFwZnGjJJkcYS4
External Content
Source RSS or Atom Feed
Feed Location https://feeds.feedburner.com/linuxquestions/latest
Feed Title LinuxQuestions.org
Feed Link https://www.linuxquestions.org/questions/
Reply 0 comments