27-Year-Old OpenBSD Vulnerability Allows Attackers to Bypass PAP Authentication Entirely
ID: a6bed0b9-4ade-5d69-8dee-bbf286be88a7
STIX ID: report--a6bed0b9-4ade-5d69-8dee-bbf286be88a7
Feed Name: cybersecurityNews.com
A 27-year-old logic flaw in OpenBSD's PPP PAP handler (sppp_pap_input) allows attackers to bypass PAP authentication by supplying attacker-controlled length fields (e.g., zero-length credentials) and can trigger kernel heap overreads when providing oversized lengths. The vulnerability is reachable via the PPPoE data path, a proof-of-concept shows full session establishment and traffic routing through a rogue PPPoE server, and a fix adding strict length checks was released promptly—organisations using OpenBSD with PPPoE/PAP should apply patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
