xebd / accel-ppp

High performance PPTP/L2TP/PPPoE/IPoE server for Linux
GNU General Public License v2.0
296 stars 108 forks source link

Vulnerability Disclosure #164

Open whitesquirrell opened 2 years ago

whitesquirrell commented 2 years ago

Dear accel-ppp Development Team,

I have filed a vulnerability disclosure by email to dev@accel-ppp.org. Please let me know when it is patched and we can use this issue for tracking purposes.

Thanks!

DmitriyEshenko commented 2 years ago

Hi @whitesquirrell , make sense, but unfortunately does not possible to produce buffer overflow via the proposed exploit.

whitesquirrell commented 2 years ago

Hi @DmitriyEshenko, noted. Since the corruption occurs during the exit process, will you still patch the code?

DmitriyEshenko commented 2 years ago

Sure, we definitely will patch code and open CVE but need time, I guess around 2 weeks

whitesquirrell commented 2 years ago

Hi @DmitriyEshenko, may I know if the code is patched?

ajakk commented 1 year ago

Looks like this got CVE-2022-0982, but was it fixed?