cbcvebase.
CVE-2015-3310
published 2015-04-24

CVE-2015-3310: Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535…

PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
5.44%
91.9th percentile
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianppp< ppp 2.4.6-3.1 (bookworm)ppp 2.4.6-3.1 (bookworm)
point-to-point_protocol_projectpoint-to-point_protocol<= 2.4.6
sambappp>= 0 < 2.4.6-3.12.4.6-3.1
sambappp>= 0 < 2.4.6-3.12.4.6-3.1
sambappp>= 0 < 2.4.6-3.12.4.6-3.1
sambappp>= 0 < 2.4.6-3.12.4.6-3.1

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.