← All CVEs

CVE-2020-8597

critical · 9.8

eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.

9.8
CVSS
19.9%
EPSS (exploit prob.)
97th
EPSS percentile
2020-02-03
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-120

Affected products

VendorProductAffected versions
point-to-point_protocol_projectpoint-to-point_protocol>= 2.4.2, <= 2.4.8
wagopfc_firmware< 03.04.10\(16\)
wagopfc100all versions
wagopfc200all versions
debiandebian_linux9.0
debiandebian_linux10.0
canonicalubuntu_linux12.04
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux18.04
canonicalubuntu_linux19.04

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-8597