heap-over-read

Tag

Cards List
#heap-over-read

A 27-Year-Old Authentication Bypass in OpenBSD's PPP Stack

Lobsters Hottest · 2026-06-17 Cached

A 27-year-old authentication bypass vulnerability in OpenBSD's PPP stack allows an attacker to gain full PPPoE access without credentials by sending zero-length username and password fields, exploiting a missing bounds check in the PAP handler. The same code also permits a kernel heap over-read.

0 favorites 0 likes
← Back to home

Submit Feedback