CVE-2024-58250

Publication date 22 April 2025

Last updated 11 July 2025


Ubuntu priority

Cvss 3 Severity Score

9.3 · Critical

Score breakdown

Description

The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

Read the notes from the security team

Mitigation

This issue can be mitigated by not using the promptprog configuration option.

Status

Package Ubuntu Release Status
ppp 25.04 plucky
Not affected
24.10 oracular Ignored end of life, was ignored [see notes]
24.04 LTS noble Ignored see notes
22.04 LTS jammy Ignored see notes
20.04 LTS focal Ignored end of standard support, was ignored [see notes]
18.04 LTS bionic Ignored see notes
16.04 LTS xenial Ignored end of ESM support, was ignored [see notes]
14.04 LTS trusty Ignored see notes

Notes


rodrigo-zaiden

the fix is to remove the passpromt feature, which could break any existing usage that depends on this specific feature.


mdeslaur

This feature is not enabled by default. We will not fix this issue in stable releases, we recommend not using the feature if this is an issue in your environment.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
ppp

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.3 · Critical

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


Access our resources on patching vulnerabilities