HomeFreeBSD

net/mpd5: fix PPPoE Server remotely exploitable crash

Description

net/mpd5: fix PPPoE Server remotely exploitable crash

This is security fix for PPPoE servers.

Insufficient validation of incoming PPPoE Discovery request
specially crafted by unauthenticated user might lead to unexpected
termination of the process. The problem affects mpd versions since 5.0.
Installations not using PPPoE server configuration were not affected.

Reported by: paul & Yannick C at SourceForge
Tested by: paul & Yannick C at SourceForge
Security: f55921aa-10c9-11ec-8647-00e0670f2660

(cherry picked from commit 1f6fcc264e1dfc53f5cd42cad335e5375abe080d)

Details

Provenance
eugen_grosbein.netAuthored on Sep 8 2021, 10:04 PM
Parents
R11:9cf7566d021e: net/mpd5: add L2TP fix from upstream (r2410, r2411).
Branches
Unknown
Tags
Unknown