CVE-2018-11574
published 2018-06-14CVE-2018-11574: Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.90%
77.6th percentile
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ppp | < ppp 2.4.7-2+3 (bookworm) | ppp 2.4.7-2+3 (bookworm) |
| point-to-point_protocol_project | point-to-point_protocol | < 2.4.9 | 2.4.9 |
| samba | ppp | >= 0 < 2.4.7-2+3 | 2.4.7-2+3 |
| samba | ppp | >= 0 < 2.4.7-2+3 | 2.4.7-2+3 |
| samba | ppp | >= 0 < 2.4.7-2+3 | 2.4.7-2+3 |
| samba | ppp | >= 0 < 2.4.7-2+3 | 2.4.7-2+3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ppp vulnerability
vendor_ubuntu·2018-11-06
CVE-2018-11574 ppp vulnerability
Title: ppp vulnerability
Summary: ppp could be made to crash or bypass authentication if it received
specially crafted network traffic.
Ivan Gotovchits discovered that ppp incorrectly handled the EAP-TLS
protocol. A remote attacker could use this issue to cause ppp to crash,
resulting in a denial of service, or possibly bypass authentication.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ppp: Remote client crash in ppp EAP-TLS patch
vendor_redhat·2018-06-12·CVSS 9.8
CVE-2018-11574 [CRITICAL] CWE-190 ppp: Remote client crash in ppp EAP-TLS patch
ppp: Remote client crash in ppp EAP-TLS patch
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.
Mitigation: PPP instances must be configured for EAP-TLS authentication to expose this vulnerability. For ppp servers, the file `/etc/ppp/eaptls-server' must exist. For clients, either `/etc/ppp/eaptls-client` must exist or command-line options `ca`, `cert` and `key` must be provided.
Package: ppp (Red Hat Enterprise Linux 5) - Not affected
Package: ppp (Red Hat Enterprise Linux 6) - Not affec
Debian
CVE-2018-11574: ppp - Improper input validation together with an integer overflow in the EAP-TLS proto...
vendor_debian·2018·CVSS 9.8
CVE-2018-11574 [CRITICAL] CVE-2018-11574: ppp - Improper input validation together with an integer overflow in the EAP-TLS proto...
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.
Scope: local
bookworm: resolved (fixed in 2.4.7-2+3)
bullseye: resolved (fixed in 2.4.7-2+3)
forky: resolved (fixed in 2.4.7-2+3)
sid: resolved (fixed in 2.4.7-2+3)
trixie: resolved (fixed in 2.4.7-2+3)
GHSA
GHSA-hx7c-3c6c-mhm3: Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure,
ghsa_unreviewed·2022-05-13
CVE-2018-11574 [CRITICAL] CWE-190 GHSA-hx7c-3c6c-mhm3: Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure,
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.
OSV
CVE-2018-11574: Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure,
osv·2018-06-14·CVSS 9.8
CVE-2018-11574 [CRITICAL] CVE-2018-11574: Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure,
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11574 ppp: Remote client crash in ppp EAP-TLS patch [fedora-all]
bugzilla·2018-06-12·CVSS 9.8
CVE-2018-11574 [CRITICAL] CVE-2018-11574 ppp: Remote client crash in ppp EAP-TLS patch [fedora-all]
CVE-2018-11574 ppp: Remote client crash in ppp EAP-TLS patch [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2018-11574 ppp: Remote client crash in ppp EAP-TLS patch
bugzilla·2018-06-05·CVSS 9.8
CVE-2018-11574 [CRITICAL] CVE-2018-11574 ppp: Remote client crash in ppp EAP-TLS patch
CVE-2018-11574 ppp: Remote client crash in ppp EAP-TLS patch
A vulnerability was found in pppd+EAP-TLS. A malicious client could cause a pppd server instance to crash.
Upstream patch:
https://www.nikhef.nl/~janjust/ppp/ppp-2.4.7-eaptls-mppe-1.101.patch
Discussion:
Public via:
http://seclists.org/oss-sec/2018/q2/173
---
Created ppp tracking bugs for this issue:
Affects: fedora-all [bug 1590087]
---
This flaw does not affect vanilla ppp, only versions patched and compiled with the EAPTLS patch. It can be triggered in both client and server.
Examining the entry points to eap-tls.c, it seems that EAPTLS negotiation will be aborted if get_eaptls_secret() fails. This will occur if the ppp instance is running without being configured for EAPTLS (see README.eap-tls).
---
Mitigation:
2018-06-14
Published