CVE detail
CVE-2020-8597
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
Google has started rolling out the June 2020 security patches for the Android operating system, which address a total of 43 vulnerabilities, including several rated critical.
newswww.securityweek.comJun 2, 2020, 2:36 PM- Millions of routers running OpenWRT vulnerable to attackHelp Net Security
A vulnerability (CVE-2020-7982) discovered in the package manager of the OpenWRT open source operating system could allow attackers to compromise the embedded and networking devices running it. About OpenWRT OpenWRT is an open source, Linux-based operating system that can be run of various types of networking devices (home routers, gateways, repeaters, access points, single board computers, etc.) instead of the software/firmware that vendors usually ship with them. For example, it can be used on popular … More →
newswww.helpnetsecurity.comApr 1, 2020, 12:20 PM - Week in review: Trojanized hacking tools, coronavirus scams, (IN)SECURE Magazine special issueHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles and podcasts: The haphazard response to COVID-19 demonstrates the value of enterprise risk management Just 12% of more than 1,500 respondents believe their businesses are highly prepared for the impact of coronavirus, while 26% believe that the virus will have little or no impact on their business, according to a survey by Gartner. Coronavirus-themed scams and attacks intensify With the Western world conducting … More →
newswww.helpnetsecurity.comMar 15, 2020, 10:00 AM A vulnerability (CVE-2020-8597) in the Point-to-Point Protocol Daemon (pppd) software, which comes installed on many Linux-based and Unix-like operating systems and networking devices, can be exploited by unauthenticated attackers to achieve code execution on – and takeover of – a targeted system. The vulnerability affects Debian GNU/Linux, NetBSD, Red Hat, Ubuntu, OpenWRT, TP-LINK and Cisco offerings, and other software/products. About the vulnerability (CVE-2020-8597) Pppd is a daemon that is used to manage PPP session establishment … More →
newswww.helpnetsecurity.comMar 10, 2020, 5:00 AM- 9th March – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 9th March 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Global fear of the Corona virus epidemic continues to be exploited for malicious cyber operations. Check Point Research reports of thousands of newly registered coronavirus related domains, which are 50% more […]
vendorresearch.checkpoint.comMar 9, 2020, 2:52 PM A critical remote code execution vulnerability affecting the PPP Daemon exposes most Linux systems to cyber attacks. A 17-year-old critical remote code execution vulnerability affecting the PPP Daemon software exposes most Linux systems to hack. The US-CERT issued a security advisory warning users of the RCE in the PPP daemon (pppd) software that is part of almost […]
newssecurityaffairs.comMar 6, 2020, 9:08 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-14355CVSS 6.6 · Medium
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk)…
- CVE-2020-8927CVSS 5.3 · Medium
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger…
- CVE-2020-16302CVSS 5.5 · Medium
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted…
- CVE-2020-16301CVSS 5.5 · Medium
A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a cra…
- CVE-2020-16298CVSS 5.5 · Medium
A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via…
- CVE-2020-16294CVSS 5.5 · Medium
A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafte…