4.6
CVSSv2

CVE-2008-1215

Published: 09/03/2008 Updated: 08/08/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the command_Expand_Interpret function in command.c in ppp (aka user-ppp), as distributed in FreeBSD 6.3 and 7.0, OpenBSD 4.1 and 4.2, and the net/userppp package for NetBSD, allows local users to gain privileges via long commands containing "~" characters.

Vulnerable Product Search on Vulmon Subscribe to Product

netbsd netbsd

openbsd openbsd 4.1

openbsd openbsd 4.2

freebsd freebsd 6.3

freebsd freebsd 7.0

Exploits

source: wwwsecurityfocuscom/bid/28090/info BSD PPP is prone to a local denial-of-service vulnerability because it fails to perform adequate boundary checks on user-supplied input Attackers can leverage this issue to crash the application and deny service to legitimate users Given the nature of the issue, arbitrary code execution may al ...