You are here
Home > Preporuke > Sigurnosni nedostatak programskog paketa ppp

Sigurnosni nedostatak programskog paketa ppp

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-2595-1
May 05, 2015

ppp vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.10
– Ubuntu 14.04 LTS
– Ubuntu 12.04 LTS

Summary:

ppp could be made to crash if it received specially crafted network
traffic.

Software Description:
– ppp: Point-to-Point Protocol (PPP)

Details:

It was discovered that ppp incorrectly handled large PIDs. When pppd is
used with a RADIUS server, a remote attacker could use this issue to cause
it to crash, resulting in a denial of service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.10:
ppp 2.4.5-5.1ubuntu3.2

Ubuntu 14.04 LTS:
ppp 2.4.5-5.1ubuntu2.2

Ubuntu 12.04 LTS:
ppp 2.4.5-5ubuntu1.2

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2595-1
CVE-2015-3310

Package Information:
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5.1ubuntu3.2
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5.1ubuntu2.2
https://launchpad.net/ubuntu/+source/ppp/2.4.5-5ubuntu1.2

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJVSQPaAAoJEGVp2FWnRL6T0CsP/3uKRWlPhj65N9FZfesENdae
YtohqC+uJ1Zr4rHXoXw8Lqk0PEWRCC4VcDgiOVCovkq1ULCAtqgXuWqmFdaXfIpb
4DH1YI40rZgL+Qpe6b6PSgJ85K/b9vLg0Sk2MzoiQWsnRXHAjV3wWBqCmq6gHZ1c
Y2yvZU8FXAQ1OY6AYNY9pdsKnlKNF8FyoWL8c4fa4A3E/uqGaydOf/Zm7mf3GpTZ
x0iCTQW4rUbEgQuV9cJ9g6fWE+XsufhsYErnbgrhpQJNwSEFeSV88JHzSR28UYtQ
VRjic/BirmWg/kflxrdY91XNRqOrSIs77YBZhNN/BAKzFYOrKTLlfslSxR3ACLku
8KAa0rUSWcCbTEDBYUPzXCWdesNIW1menLcTYipJLF53oeHqmYJXTr1krYahZZhw
CdhxO4pqE6hyByEKhyqwvqsuQ6ClcnCPUrx0nEZy8+AJUod/ILXg6lBmXc6hhtTU
N1gsOWvFvQei35wMKSE8N/jrfcKBjW5y9cmhthOdE3veuUYI2t7BEYmznErome0z
xlwRj8M4iklzWWbASVwv3BIZenozcG+EJxPnwGV7b0MBVDiyBLfaDlh+iQQ3S57S
tM8An6McV2y0M3zFc5L5XzO4+8DOJduPtu4b4Z0yE3dj1cuJRYGCzE4+5QrBGFfC
W8G4Cmg8O3SDHAdWmPiy
=Ms66
—–END PGP SIGNATURE—–

AutorMarko Stanec
Cert idNCERT-REF-2015-05-0022-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Ranjivosti programskog paketa clamav

Otkriveno je nekoliko ranjivosti u antivirusnom alatu ClamAV za Ubuntu uzrokovane neispravnim upravljanjem preoblikovnim datotekama. Udaljeni napadač ranjivost bi mogao...

Close