CVE-2020-15704: pppd arbitrary file read information disclosure vulnerability
Last updated 25 August 2025
Other sources
The modprobe child process in the ./debian/patches/loadpppgenericifneeded patch file incorrectly handled module loading. A local non-root attacker could exploit the MODPROBEOPTIONS environment variable to read arbitrary root files. Fixed in 2.4.5-5ubuntu1.4, 2.4.5-5.1ubuntu2.3+esm2, 2.4.7-1+2ubuntu1.16.04.3, 2.4.7-2+2ubuntu1.3, 2.4.7-2+4.1ubuntu5.1, 2.4.7-2+4.1ubuntu6. Was ZDI-CAN-11504.
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15704?
CVE-2020-15704 has a high severity rating due to its potential exploitation by local non-root attackers to read arbitrary root files.
How do I fix CVE-2020-15704?
To fix CVE-2020-15704, update the ppp package to version 2.4.5-5ubuntu1.4 or later.
Which versions of ppp are affected by CVE-2020-15704?
CVE-2020-15704 affects ppp versions prior to 2.4.5-5ubuntu1.4.
Can a non-root user exploit CVE-2020-15704?
Yes, a local non-root user can exploit CVE-2020-15704 to access root-level files.
What systems are vulnerable to CVE-2020-15704?
Systems running affected versions of the ppp package, particularly on Debian and Ubuntu, are vulnerable to CVE-2020-15704.