Skip to content
This repository was archived by the owner on May 14, 2024. It is now read-only.

Commit a0d3a74

Browse files
committed
new files
1 parent 7e3c073 commit a0d3a74

File tree

1,732 files changed

+24342
-0
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,732 files changed

+24342
-0
lines changed
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "",
3+
"DateLastUpdated": "2020-02-16T16:44:00-05:00",
4+
"DateNotified": "2020-02-05T15:07:34-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 3,
8+
"Status": "Not Affected",
9+
"Vendor": "lwIP",
10+
"VendorInformation": "EAP was never used by any lwIP user. The lwIP PPP support is mostly used with cellular modems only as a framing protocol limited to the serial link between the MCU and the modem were security is less relevant because it is not authenticated anyway. The lwIP so far has had support for PAP, CHAP, MS-CHAP (tied to MPPE keys exchange), but EAP has never been enabled from compile time.",
11+
"VendorRecordID": "CHEU-BLHRNV",
12+
"VendorReferences": "If you plan to compile lwIP with EAP support, please ensure you apply both the patches linked below as it also resolves the issue of preventing response to unsolicited EAP messages as well as buffer overflow due to the bounds check logic flaw. http://git.savannah.nongnu.org/cgit/lwip.git/commit/?id=2ee3cbe69c6d2805e64e7cac2a1c1706e49ffd86\nhttp://git.savannah.nongnu.org/cgit/lwip.git/commit/?id=d281d3e9592a3ca2ad0c3b7840f8036facc02f7b",
13+
"VendorStatement": "lwIP is a bit different than pppd, we added a lot of preprocessor directives to enable or disable features at compile time in order to reduce binary size output and EAP is disabled by default: http://git.savannah.nongnu.org/cgit/lwip.git/tree/src/include/netif/ppp/ppp_opts.h?id=d281d3e9592a3ca2ad0c3b7840f8036facc02f7b#n234 \nhttp://git.savannah.nongnu.org/cgit/lwip.git/tree/src/netif/ppp/eap.c?id=d281d3e9592a3ca2ad0c3b7840f8036facc02f7b#n46 \nThat is, no product using lwIP were ever shipped with the EAP code compiled at all."
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "",
3+
"DateLastUpdated": "2020-02-11T17:04:56-05:00",
4+
"DateNotified": "2020-02-11T17:00:10-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 0,
8+
"Status": "Unknown",
9+
"Vendor": "Alpine Linux",
10+
"VendorInformation": "",
11+
"VendorRecordID": "CHEU-BLPTW4",
12+
"VendorReferences": "",
13+
"VendorStatement": ""
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "",
3+
"DateLastUpdated": "2020-02-11T17:04:57-05:00",
4+
"DateNotified": "2020-02-11T17:00:10-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 0,
8+
"Status": "Unknown",
9+
"Vendor": "Aspera Inc.",
10+
"VendorInformation": "",
11+
"VendorRecordID": "CHEU-BLPTW6",
12+
"VendorReferences": "",
13+
"VendorStatement": ""
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "There are no additional comments at this time.",
3+
"DateLastUpdated": "2020-02-19T13:05:00-05:00",
4+
"DateNotified": "2020-02-11T17:00:10-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 2,
8+
"Status": "Not Affected",
9+
"Vendor": "Apple",
10+
"VendorInformation": "Apple has a forked version of ppp that was modified years earlier. It shows not affected due to the source code changes.",
11+
"VendorRecordID": "CHEU-BLPTW8",
12+
"VendorReferences": "None",
13+
"VendorStatement": "No statement is currently available from the vendor regarding this vulnerability."
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "There are no additional comments at this time.",
3+
"DateLastUpdated": "2020-03-10T10:49:00-04:00",
4+
"DateNotified": "2020-02-11T17:00:10-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 2,
8+
"Status": "Affected",
9+
"Vendor": "Amazon",
10+
"VendorInformation": "Amazon Linux has adopted RedHat advisory and published their own updates. Please see Vendor URL section for details.",
11+
"VendorRecordID": "CHEU-BLPTWA",
12+
"VendorReferences": "https://alas.aws.amazon.com/AL2/ALAS-2020-1400.html",
13+
"VendorStatement": "Visit ALAS post https://alas.aws.amazon.com/AL2/ALAS-2020-1400.html for details of this vulnerability"
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "There are no additional comments at this time.",
3+
"DateLastUpdated": "2020-02-14T12:23:00-05:00",
4+
"DateNotified": "2020-02-11T17:00:10-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 1,
8+
"Status": "Not Affected",
9+
"Vendor": "Arista Networks, Inc.",
10+
"VendorInformation": "We are not aware of further vendor information regarding this vulnerability.",
11+
"VendorRecordID": "CHEU-BLPTWC",
12+
"VendorReferences": "None",
13+
"VendorStatement": "Arista products do not have any features using pppd, hence no Arista products are affected."
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "There are no additional comments at this time.",
3+
"DateLastUpdated": "2020-02-12T19:00:00-05:00",
4+
"DateNotified": "2020-02-11T17:00:12-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 1,
8+
"Status": "Not Affected",
9+
"Vendor": "CoreOS",
10+
"VendorInformation": "We are not aware of further vendor information regarding this vulnerability.",
11+
"VendorRecordID": "CHEU-BLPTWF",
12+
"VendorReferences": "None",
13+
"VendorStatement": "CoreOS Container Linux does not ship pppd."
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "There are no additional comments at this time.",
3+
"DateLastUpdated": "2020-03-09T14:07:00-04:00",
4+
"DateNotified": "2020-02-11T17:00:12-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 1,
8+
"Status": "Affected",
9+
"Vendor": "Arch Linux",
10+
"VendorInformation": "ArchLinux has updated its advisory on March 7 2020, with ASA-202003-3 advisory with resolution statement\n\"Upgrade to 2.4.7-7. # pacman -Syu \"ppp>=2.4.7-7\"\nThe problem has been fixed upstream but no release is available yet.\"",
11+
"VendorRecordID": "CHEU-BLPTWH",
12+
"VendorReferences": "https://security.archlinux.org/ASA-202003-3/generate",
13+
"VendorStatement": "No statement is currently available from the vendor regarding this vulnerability."
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "There are no additional comments at this time.",
3+
"DateLastUpdated": "2020-02-21T18:05:00-05:00",
4+
"DateNotified": "2020-02-11T17:00:12-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 3,
8+
"Status": "Not Affected",
9+
"Vendor": "FreeBSD Project",
10+
"VendorInformation": "A review of the pppd source tree suggests that FreeBSD do not include pppd in the base system (removed in r190751 - ten years ago). The first pppd version that contained the vulnerability was 2.4.2, and FreeBSD has never shipped with that version.",
11+
"VendorRecordID": "CHEU-BLPTWK",
12+
"VendorReferences": "None",
13+
"VendorStatement": "FreeBSD does not distribute pppd."
14+
}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
{
2+
"Addendum": "",
3+
"DateLastUpdated": "2020-02-11T17:04:59-05:00",
4+
"DateNotified": "2020-02-11T17:00:13-05:00",
5+
"DateResponded": "",
6+
"ID": "VU#782301",
7+
"Revision": 0,
8+
"Status": "Unknown",
9+
"Vendor": "DesktopBSD",
10+
"VendorInformation": "",
11+
"VendorRecordID": "CHEU-BLPTWM",
12+
"VendorReferences": "",
13+
"VendorStatement": ""
14+
}

0 commit comments

Comments
 (0)