CVE-2015-3310
published 2015-04-24CVE-2015-3310: Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535…
PriorityP425medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
5.44%
91.9th percentile
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | ppp | < ppp 2.4.6-3.1 (bookworm) | ppp 2.4.6-3.1 (bookworm) |
| point-to-point_protocol_project | point-to-point_protocol | <= 2.4.6 | — |
| samba | ppp | >= 0 < 2.4.6-3.1 | 2.4.6-3.1 |
| samba | ppp | >= 0 < 2.4.6-3.1 | 2.4.6-3.1 |
| samba | ppp | >= 0 < 2.4.6-3.1 | 2.4.6-3.1 |
| samba | ppp | >= 0 < 2.4.6-3.1 | 2.4.6-3.1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial
vendor_msrc·2025-08-12·CVSS 4.3
CVE-2015-3310 [MEDIUM] CWE-119 Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more informat
Ubuntu
ppp vulnerability
vendor_ubuntu·2015-05-05
CVE-2015-3310 ppp vulnerability
Title: ppp vulnerability
Summary: ppp could be made to crash if it received specially crafted network
traffic.
It was discovered that ppp incorrectly handled large PIDs. When pppd is
used with a RADIUS server, a remote attacker could use this issue to cause
it to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ppp: buffer overflow in radius plug-in's rc_mksid()
vendor_redhat·2015-04-13·CVSS 4.3
CVE-2015-3310 [MEDIUM] CWE-120 ppp: buffer overflow in radius plug-in's rc_mksid()
ppp: buffer overflow in radius plug-in's rc_mksid()
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
Package: ppp (Red Hat Enterprise Linux 5) - Will not fix
Package: ppp (Red Hat Enterprise Linux 6) - Will not fix
Package: ppp (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-3310: ppp - Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP ...
vendor_debian·2015·CVSS 4.3
CVE-2015-3310 [MEDIUM] CVE-2015-3310: ppp - Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP ...
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
Scope: local
bookworm: resolved (fixed in 2.4.6-3.1)
bullseye: resolved (fixed in 2.4.6-3.1)
forky: resolved (fixed in 2.4.6-3.1)
sid: resolved (fixed in 2.4.6-3.1)
trixie: resolved (fixed in 2.4.6-3.1)
GHSA
GHSA-fm2f-v6g4-x3jw: Buffer overflow in the rc_mksid function in plugins/radius/util
ghsa_unreviewed·2022-05-13
CVE-2015-3310 [MEDIUM] CWE-119 GHSA-fm2f-v6g4-x3jw: Buffer overflow in the rc_mksid function in plugins/radius/util
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
OSV
CVE-2015-3310: Buffer overflow in the rc_mksid function in plugins/radius/util
osv·2015-04-24·CVSS 4.3
CVE-2015-3310 [MEDIUM] CVE-2015-3310: Buffer overflow in the rc_mksid function in plugins/radius/util
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
No detection rules found.
No public exploits indexed.
http://advisories.mageia.org/MGASA-2015-0173.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00147.htmlhttp://www.debian.org/security/2015/dsa-3228http://www.mandriva.com/security/advisories?name=MDVSA-2015:222http://www.securityfocus.com/bid/74163http://www.ubuntu.com/usn/USN-2595-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=782450https://security.gentoo.org/glsa/201701-50http://advisories.mageia.org/MGASA-2015-0173.htmlhttp://lists.opensuse.org/opensuse-updates/2015-11/msg00147.htmlhttp://www.debian.org/security/2015/dsa-3228http://www.mandriva.com/security/advisories?name=MDVSA-2015:222http://www.securityfocus.com/bid/74163http://www.ubuntu.com/usn/USN-2595-1https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=782450https://security.gentoo.org/glsa/201701-50
2015-04-24
Published