xebd / accel-ppp

High performance PPTP/L2TP/PPPoE/IPoE server for Linux
GNU General Public License v2.0
296 stars 108 forks source link

Several vulnerabilities for accel-ppp #131

Open hac425xxx opened 4 years ago

hac425xxx commented 4 years ago

I try to send email to contact@accel-ppp.org and dima@accel-ppp.org, but my email is blocked.

The vulnerability report is attached to the email. Sorry, it is in Chinese. You can try to use Google Translate. If you have any questions, please contact me

Wait for your reply

DmitriyEshenko commented 4 years ago

Hi @hac425xxx Thanks, very informative. The patch will ready soon. Can you remove the attached file?

hac425xxx commented 4 years ago

removed, and could you please request some cve for these bug, you can requset in github project

https://github.com/xebd/accel-ppp/security

the document for requtest

https://help.github.com/en/github/managing-security-vulnerabilities/publishing-a-security-advisory
DmitriyEshenko commented 4 years ago

Thanks @hac425xxx Patches already available in org repo https://github.com/accel-ppp/accel-ppp/commits/master @xebd can you merge and create CVE request?

DmitriyEshenko commented 4 years ago

Hello @hac425xxx , can you check this version https://github.com/xebd/accel-ppp/commit/ed7b28722ec8513838b49699a862a69055c8c596