Tag
A 27-year-old authentication bypass vulnerability in OpenBSD's PPP stack allows an attacker to gain full PPPoE access without credentials by sending zero-length username and password fields, exploiting a missing bounds check in the PAP handler. The same code also permits a kernel heap over-read.