Vulnerability Description
The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would result in a denial of service condition.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mpd Project | Mpd | < 5.9 |
| Stormshield | Stormshield Network Security | >= 4.0.0, < 4.3.17 |
Related Weaknesses (CWE)
References
- https://sourceforge.net/p/mpd/bugs/69/ExploitThird Party Advisory
- https://sourceforge.net/p/mpd/svn/2374/PatchThird Party Advisory
- https://sourceforge.net/p/mpd/bugs/69/ExploitThird Party Advisory
- https://sourceforge.net/p/mpd/svn/2374/PatchThird Party Advisory
FAQ
What is CVE-2020-7466?
CVE-2020-7466 is a vulnerability with a CVSS score of 7.5 (HIGH). The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory buffer, which would r...
How severe is CVE-2020-7466?
CVE-2020-7466 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-7466?
Check the references section above for vendor advisories and patch information. Affected products include: Mpd Project Mpd, Stormshield Stormshield Network Security.