CVE-2020-8597: Buffer Overflow
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eaprequest and eapresponse functions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/pppto a version that resolves this vulnerability.Fixed in 2.4.8-1+1~exp1Fixed in 2.4.7-2+4.1+deb10u1Fixed in 2.4.7-1+4+deb9u1 - Upgrade
Upgrade
Siemens RuggedCom RM1224 LTEto a version that resolves this vulnerability.Fixed in 6.3 - Upgrade
Upgrade
Siemens SCALANCE S615 firmwareto a version that resolves this vulnerability.Fixed in 6.3 - Upgrade
Upgrade
debian/lwipto a version that resolves this vulnerability.Fixed in 2.1.2+dfsg1-8+deb11u1Fixed in 2.1.3+dfsg1-2Fixed in 2.2.1+dfsg1-1Fixed in 2.2.1+dfsg1-5Fixed in 2.2.1+dfsg1-6 - Upgrade
Upgrade
debian/pppto a version that resolves this vulnerability.Fixed in 2.4.9-1+1Fixed in 2.4.9-1+1.1Fixed in 2.5.2-1+1Fixed in 2.5.2-1+2 - Upgrade
Upgrade
ppp/pppdto a version that resolves this vulnerability.Fixed in 2.4.2 through 2.4.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 8d7970b8f3db727fe798b65f3377fe6787575426
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-8597.
What is the severity of CVE-2020-8597?
The severity of CVE-2020-8597 is critical with a severity value of 9.8.
What is the affected software?
The affected software includes ppp versions 2.4.2 through 2.4.8 on Debian and Ubuntu systems, lwip on Debian systems, and Android devices.
How can I fix the vulnerability in pppd?
To fix the vulnerability in pppd, update to version 2.4.9-1+1 or later on Debian systems, and follow the recommended updates for Ubuntu and Android devices.
Where can I find more information about CVE-2020-8597?
You can find more information about CVE-2020-8597 at the following references: [Link 1](https://android.googlesource.com/platform/external/ppp/+/f9fec5c36952301e585a420f31e96d35a60d0498), [Link 2](https://source.android.com/docs/security/bulletin/2020-06-01), [Link 3](https://github.com/paulusmack/ppp/commit/8d7970b8f3db727fe798b65f3377fe6787575426).