CVE-2022-4603
published 2022-12-18CVE-2022-4603: A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.82%
53.7th percentile
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ppp | < ppp 2.5.0-1+2 (forky) | ppp 2.5.0-1+2 (forky) |
| msrc | cbl2_ppp_2.4.7-36_on_cbl_mariner_2.0 | — | — |
| samba | ppp | < 2.5.0 | 2.5.0 |
| samba | ppp | >= 0 < 2.5.0-1+2 | 2.5.0-1+2 |
| samba | ppp | >= 0 < 2.5.0-1+2 | 2.5.0-1+2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian4.3LOW
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
ppp: improper validation of array index of the component pppdump
vendor_redhat·2022-12-19·CVSS 4.3
CVE-2022-4603 [MEDIUM] CWE-119 ppp: improper validation of array index of the component pppdump
ppp: improper validation of array index of the component pppdump
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.
A potential buffer overflow vulnerability was found in ppp. This issue o
Microsoft
ppp pppdump pppdump.c dumpppp array index
vendor_msrc·2022-12-13·CVSS 4.3
CVE-2022-4603 [MEDIUM] CWE-119 ppp pppdump pppdump.c dumpppp array index
ppp pppdump pppdump.c dumpppp array index
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
VulDB: VulDB
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com
Debian
CVE-2022-4603: ppp - A vulnerability classified as problematic has been found in ppp. Affected is the...
vendor_debian·2022·CVSS 4.3
CVE-2022-4603 [MEDIUM] CVE-2022-4603: ppp - A vulnerability classified as problematic has been found in ppp. Affected is the...
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.5.0-1+2)
sid: resolved (fixed in 2.5.0-1+2)
trixie: resolved (fixed
OSV
CVE-2022-4603: A vulnerability classified as problematic has been found in ppp
osv·2022-12-18·CVSS 6.5
CVE-2022-4603 [MEDIUM] CVE-2022-4603: A vulnerability classified as problematic has been found in ppp
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.
GHSA
GHSA-82mr-xx64-4rjv: ** DISPUTED ** A vulnerability classified as problematic has been found in ppp
ghsa_unreviewed·2022-12-18
CVE-2022-4603 [HIGH] CWE-119 GHSA-82mr-xx64-4rjv: ** DISPUTED ** A vulnerability classified as problematic has been found in ppp
** DISPUTED ** A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/ppp-project/ppp/commit/a75fb7b198eed50d769c80c36629f38346882cbfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J43NP7ABHOCIWOFHWCH6ZCZOYKZH6723/https://vuldb.com/?id.216198https://github.com/ppp-project/ppp/commit/a75fb7b198eed50d769c80c36629f38346882cbfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J43NP7ABHOCIWOFHWCH6ZCZOYKZH6723/https://lists.fedoraproject.org/archives/list/[email protected]/message/J43NP7ABHOCIWOFHWCH6ZCZOYKZH6723/https://vuldb.com/?id.216198
2022-12-18
Published