CVE-2004-1002Integer Underflow (Wrap or Wraparound) in PPP

Severity
7.5HIGHNVD
EPSS
2.1%
top 15.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateApr 29

Description

Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/ppp< ppp 2.4.2+20040428-3 (bookworm)
Debiansamba/ppp< 2.4.2+20040428-3+3
NVDsamba/ppp2.4.1

Also affects: Ubuntu Linux 4.10

🔴Vulnerability Details

2
GHSA
GHSA-2wm2-cfr8-8vw9: Integer underflow in pppd in cbcp2022-04-29
OSV
CVE-2004-1002: Integer underflow in pppd in cbcp2005-03-01

💥Exploits & PoCs

1
Exploit-DB
OpenText FirstClass 8.0 - HTTP Daemon /Search Remote Denial of Service2004-12-15

📋Vendor Advisories

2
Debian
CVE-2004-1002: ppp - Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cau...2004
Red Hat
CVE-2004-1002: Integer underflow in pppd in cbcp

📐Framework References

1
CWE
Integer Underflow (Wrap or Wraparound)