7.5

CVE-2023-52557

OpenBSD 7.3 invalid l2tp message npppd crash

In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbsd ≫ Openbsd Version < 7.3
Openbsd ≫ Openbsd Version 7.3 Update -
Openbsd ≫ Openbsd Version 7.3 Update errata_001
Openbsd ≫ Openbsd Version 7.3 Update errata_002
Openbsd ≫ Openbsd Version 7.3 Update errata_003
Openbsd ≫ Openbsd Version 7.3 Update errata_004
Openbsd ≫ Openbsd Version 7.3 Update errata_005
Openbsd ≫ Openbsd Version 7.3 Update errata_006
Openbsd ≫ Openbsd Version 7.3 Update errata_007
Openbsd ≫ Openbsd Version 7.3 Update errata_008
Openbsd ≫ Openbsd Version 7.3 Update errata_009
Openbsd ≫ Openbsd Version 7.3 Update errata_010
Openbsd ≫ Openbsd Version 7.3 Update errata_011
Openbsd ≫ Openbsd Version 7.3 Update errata_012
Openbsd ≫ Openbsd Version 7.3 Update errata_013
Openbsd ≫ Openbsd Version 7.3 Update errata_014
Openbsd ≫ Openbsd Version 7.3 Update errata_015
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.418
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-131 Incorrect Calculation of Buffer Size

The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

CWE-805 Buffer Access with Incorrect Length Value

The product uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer.

https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/016_npppd.patch.sig
Patch
https://github.com/openbsd/src/commit/abf3a29384c582c807a621e7fc6e7c68d0cafe9b
Patch