Home

Description

The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

PUBLISHED Reserved 2025-04-22 | Published 2025-04-22 | Updated 2025-04-22 | Assigner mitre




CRITICAL: 9.3CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-426 Untrusted Search Path

Product status

Default status
unaffected

Any version before 2.5.2
affected

References

github.com/...ommit/0a66ad22e54c72690ec2a29a019767c55c5281fc

github.com/ppp-project/ppp/compare/v2.5.1...v2.5.2

ppp.samba.org

cve.org (CVE-2024-58250)

nvd.nist.gov (CVE-2024-58250)

Download JSON