The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.
2020-10-06T14:15:13.243
2024-11-21T05:37:12.073
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mpd_project | mpd | < 5.9 | Yes |
Application | stormshield | stormshield_network_security | < 4.3.17 | Yes |
Application | stormshield | stormshield_network_security | 4.4.0 | Yes |