Advisories ยป MGASA-2020-0139

Updated ppp packages fix security vulnerability

Publication date: 12 Mar 2020
Modification date: 12 Mar 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-8597

Description

Updated ppp packages fix security vulnerability:

Ilja Van Sprundel discovered a buffer overflow vulnerability in ppp.
When receiving an EAP Request message in client mode, an attacker was
able to overflow the rhostname array by providing a very long name
(CVE-2020-8597).
                

References

SRPMS

7/core