Debian Security Advisory
DLA-205-1 ppp -- LTS security update
- Date Reported:
- 19 Apr 2015
- Affected Packages:
- ppp
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 782450.
In Mitre's CVE dictionary: CVE-2015-3310. - More information:
-
Emanuele Rocca discovered that ppp, a daemon implementing the Point-to-Point Protocol, was subject to a buffer overflow when communicating with a RADIUS server. This would allow unauthenticated users to cause a denial-of-service by crashing the daemon.