CVE-2018-11574: Input Validation
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the refuse-app option are unaffected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-11574?
CVE-2018-11574 is a vulnerability that involves improper input validation and an integer overflow in the EAP-TLS protocol implementation in PPPD.
What is the severity of CVE-2018-11574?
The severity of CVE-2018-11574 is critical with a CVSS score of 9.8.
How does CVE-2018-11574 impact affected software?
CVE-2018-11574 may cause a crash, information disclosure, or authentication bypass on affected systems.
Which software versions are affected by CVE-2018-11574?
PPPD versions up to and including 2.4.9, Canonical Ubuntu Linux 14.04, 16.04, and 18.04, and certain versions of the ppp package in Debian and Ubuntu are affected by CVE-2018-11574.
How can I fix CVE-2018-11574?
To fix CVE-2018-11574, upgrade to a patched version of PPPD (version 2.4.9 or higher) or update the ppp package to the recommended versions provided by the respective vendors.