CVE-2020-8597

CRITICAL

ppp <2.4.8 - Buffer Overflow

Title source: llm

Description

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

Exploits (5)

nomisec WORKING POC 49 stars
by winmin · poc
https://github.com/winmin/CVE-2020-8597
nomisec WORKING POC 6 stars
by lakwsh · poc
https://github.com/lakwsh/CVE-2020-8597
nomisec WRITEUP
by Dilan-Diaz · poc
https://github.com/Dilan-Diaz/Point-to-Point-Protocol-Daemon-RCE-Vulnerability-CVE-2020-8597-
nomisec WRITEUP
by dointisme · poc
https://github.com/dointisme/CVE-2020-8597

References (22)

... and 2 more

Scores

CVSS v3 9.8
EPSS 0.6284
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-120
Status published
Products (9)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.04
debian/debian_linux 9.0
debian/debian_linux 10.0
point-to-point_protocol_project/point-to-point_protocol 2.4.2 - 2.4.8
wago/pfc_firmware < 03.04.10\(16\)
Published Feb 03, 2020
Tracked Since Feb 18, 2026