Re: Critical PPP Daemon Flaw

Cy Schubert <[email protected]>
Newsgroups gmane.os.freebsd.security.general
Message-ID <[email protected]>
On March 9, 2020 4:23:10 AM PDT, Miroslav Lachman <[email protected]> wrote:
>I don't know if FreeBSD is vulnerable or not. There are main Linux 
>distros and NetBSD listed in the article.
>
>https://thehackernews.com/2020/03/ppp-daemon-vulnerability.html
>
>The vulnerability, tracked as CVE-2020-8597 [1] with CVSS Score 9.8,
>can 
>be exploited by unauthenticated attackers to remotely execute arbitrary
>
>code on affected systems and take full control over them.
>
>[1] https://www.kb.cert.org/vuls/id/782301/
>
>Kind regards
>Miroslav Lachman
>_______________________________________________
>[email protected] mailing list
>https://lists.freebsd.org/mailman/listinfo/freebsd-security
>To unsubscribe, send any mail to
>"[email protected]"

Probably not. Ours is a different codebase from NetBSD. I haven't looked at what Red Hat has, no comment about theirs. However it would be prudent to verify our pppd isn't also vulnerable.



-- 
Pardon the typos and autocorrect, small keyboard in use. 
Cy Schubert <[email protected]>
FreeBSD UNIX: <[email protected]> Web: https://www.FreeBSD.org

The need of the many outweighs the greed of the few.

Sent from my Android device with K-9 Mail. Please excuse my brevity.
_______________________________________________
[email protected] mailing list
https://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[email protected]"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.