A vulnerability in pppd and lwIP allows remote code execution with root privileges.

In the pppd package identified vulnerability (CVE-2020-8597), allowing for the execution of one's code by sending specially crafted authentication requests to systems using the PPP (Point-to-Point Protocol) or PPPoE (PPP over Ethernet) protocols. These protocols are typically used by providers to establish connections via Ethernet or DSL, and are also used in some VPNs (for example, pptpd and openfortivpn). To check for vulnerability in your systems regarding this issue prepared a proof of concept exploit.

The vulnerability is caused by a buffer overflow in the implementation of the EAP (Extensible Authentication Protocol) authentication protocol. An attack can be carried out before authentication by sending a packet with the type EAPT_MD5CHAP, which includes a very long host name that exceeds the allocated buffer. Due to a miscalculation in the size-checking code of the rhostname field, an attacker can overwrite data beyond the buffer in the stack and achieve remote code execution with root privileges. The vulnerability manifests on both server and client sides, meaning that not only the server can be attacked, but also a client attempting to connect to a server controlled by the attacker (for instance, an attacker may first compromise the server through the vulnerability and then start attacking connecting clients).

The problem affects versions pppd from 2.4.2 to 2.4.8 inclusive and has been fixed in the form of a patch. The vulnerability is also present in affects the stack lwIP, but in the default configuration of lwIP, EAP support is not enabled.

The status of the issue resolution in distributions can be viewed on these pages: Debian, Ubuntu, SUSE/openSUSE, Alpine, openSUSE, OpenWRT, ALT, NetBSD. In RHEL, OpenWRT, and SUSE, the pppd package is built with 'Stack Smashing Protection' enabled (the '-fstack-protector' mode in gcc), which limits exploitation through crashes. Besides distributions, the vulnerability is also confirmed in some products Cisco (CallManager), TP-LINK and Synology (DiskStation Manager, VisualStation VS960HD, and Router Manager), which utilize the pppd or lwIP code.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster