Gentoo Archives: gentoo-announce

From: Luke Macken <lewk@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200411-01 ] ppp: Remote denial of service vulnerability
Date: Mon, 01 Nov 2004 17:23:33
Message-Id: 1099329711.11514.24.camel@tomservo.rh.rit.edu
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200411-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: ppp: Remote denial of service vulnerability
9 Date: November 01, 2004
10 Bugs: #69152
11 ID: 200411-01
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 pppd contains a vulnerability that may allow an attacker to crash the
19 server.
20
21 Background
22 ==========
23
24 ppp is a Unix implementation of the Point-to-Point Protocol.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-dialup/ppp < 2.4.2-r7 >= 2.4.2-r7
33
34 Description
35 ===========
36
37 The pppd server improperly verifies header fields, making it vulnerable
38 to denial of service attacks.
39
40 Impact
41 ======
42
43 An attacker can cause the pppd server to access memory that it isn't
44 allowed to, causing the server to crash. No code execution is possible
45 with this vulnerability, because no data is getting copied.
46
47 Workaround
48 ==========
49
50 There is no known workaround at this time.
51
52 Resolution
53 ==========
54
55 All ppp users should upgrade to the latest version:
56
57 # emerge --sync
58 # emerge --ask --oneshot --verbose ">=net-dialup/ppp-2.4.2-r7"
59
60 References
61 ==========
62
63 [ 1 ] BugTraq Advisory
64 http://www.securityfocus.com/archive/1/379450
65
66 Availability
67 ============
68
69 This GLSA and any updates to it are available for viewing at
70 the Gentoo Security Website:
71
72 http://security.gentoo.org/glsa/glsa-200411-01.xml
73
74 Concerns?
75 =========
76
77 Security is a primary focus of Gentoo Linux and ensuring the
78 confidentiality and security of our users machines is of utmost
79 importance to us. Any security concerns should be addressed to
80 security@g.o or alternatively, you may file a bug at
81 http://bugs.gentoo.org.
82
83 License
84 =======
85
86 Copyright 2004 Gentoo Foundation, Inc; referenced text
87 belongs to its owner(s).
88
89 The contents of this document are licensed under the
90 Creative Commons - Attribution / Share Alike license.
91
92 http://creativecommons.org/licenses/by-sa/1.0

Attachments

File name MIME type
signature.asc application/pgp-signature