cbcvebase.
CVE-2014-3158
published 2014-11-15

CVE-2014-3158: Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a…

PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.50%
88.0th percentile
Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options file, which triggers a heap-based buffer overflow that "[corrupts] security-relevant variables."

Affected

6 ranges
VendorProductVersion rangeFixed in
debianppp< ppp 2.4.6-3 (bookworm)ppp 2.4.6-3 (bookworm)
point-to-point_protocol_projectpoint-to-point_protocol<= 2.4.6
sambappp>= 0 < 2.4.6-32.4.6-3
sambappp>= 0 < 2.4.6-32.4.6-3
sambappp>= 0 < 2.4.6-32.4.6-3
sambappp>= 0 < 2.4.6-32.4.6-3

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.