USN-12-1: ppp Denial of Service
Posted on: 10/29/2004 04:10 PM

A ppp security update has been released for Ubuntu Linux 4.10

Ubuntu Security Notice USN-12-1 October 29, 2004
ppp Denial of Service

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:


The problem can be corrected by upgrading the affected packages to version 2.4.2+20040428-2ubuntu6.2. In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

It has been discovered that ppp does not properly verify certain data structures used in the CBCP protocol. This vulnerability could allow an attacker to cause the pppd server to crash due to an invalid memory access, leading to a denial of service. However, there is no possibility of code execution or privilege escalation.

