Back

CRITICAL

ppp: Remote client crash in ppp EAP-TLS patch

Published Jun 14, 2018

Description

Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.

Affected products

Remediation

Red Hat mitigation

PPP instances must be configured for EAP-TLS authentication to expose this vulnerability. For ppp servers, the file `/etc/ppp/eaptls-server' must exist. For clients, either `/etc/ppp/eaptls-client` must exist or command-line options `ca`, `cert` and `key` must be provided.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 14, 2018
Updated Dec 3, 2025
Reserved May 30, 2018
CISA Vulnrichment
Updated Dec 3, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jun 12, 2018