CVE-2024-58250

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-58250
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58250.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58250
Downstream
Published
2025-04-22T01:15:17Z
Modified
2025-10-22T07:35:42.300530Z
Severity
  • 9.3 (Critical) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.

References

Affected packages

Git / github.com/ppp-project/ppp

Affected ranges

Type
GIT
Repo
https://github.com/ppp-project/ppp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.4.9

ppp-2.*

ppp-2.0.4
ppp-2.1.1
ppp-2.1.2
ppp-2.2
ppp-2.3.0
ppp-2.3.1
ppp-2.3.10
ppp-2.3.11
ppp-2.3.2
ppp-2.3.3
ppp-2.3.4
ppp-2.3.5
ppp-2.3.6
ppp-2.3.7
ppp-2.3.8
ppp-2.3.9
ppp-2.4.0
ppp-2.4.1
ppp-2.4.2
ppp-2.4.3
ppp-2.4.4
ppp-2.4.5
ppp-2.4.6
ppp-2.4.7
ppp-2.4.8
ppp-2.4.9
ppp-2.5.0
ppp-2.5.1

v2.*

v2.0.4
v2.1.1
v2.1.2
v2.2
v2.3.0
v2.3.1
v2.3.10
v2.3.11
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v2.5.0
v2.5.1

Database specific

vanir_signatures

[
    {
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "218419416106868612692001950399526289755",
                "26098963097629720016175480823664259492",
                "11277872571951261794390533937726509707",
                "300845896995725006912751940465419903831",
                "23913852176040480469294533295493292060",
                "189572804204316302220873176751679348755",
                "226907145479450602133228091659834150659",
                "325492084172867617119930705577171197821",
                "286816195843998234452911272599828370244",
                "68524530567394243761461941153864045860",
                "111182192184458524136740286996973692149",
                "128064866473575169584359682692440872185",
                "103600722241962253934586649254949504885",
                "4235437195996845055271848344514663415",
                "197494378568166418643971530090736329271",
                "120794266114703832822210204207968717873",
                "22422006041596591744092057307173644634",
                "325019686821717380222541799833000414170",
                "154857079880827515788492893680522338191",
                "316808985472916706430836552899336692790",
                "183583732877702692312557600450636648475",
                "121845919133443114815433324662622695812",
                "256172883374660797886264272981453676547",
                "121805933878395407030587582342652653380",
                "218868654542077296482241586855741988388",
                "139285260637155763253780362719581625513",
                "185081812503042879362680615514129610133",
                "149856781965961023115157732246329366380",
                "311207116839436497512108046797390927429",
                "162103506558030894884337299868883751649",
                "47353566169770232494123455819127062366",
                "152910265254223846387646505731123951468",
                "76530838091450375425193059304933017592",
                "12012090133133563633555365538473356460",
                "323910896863485223625641108870926971978",
                "151654903624620832447087530618148366121",
                "85112952154804117625497269205396339421",
                "175652845108142256083796009002485118799",
                "56185807995109956453080581110527419555",
                "173242098958299033260415329422652525755",
                "64593087277801717699901276657972594700",
                "47403570050465565680066695907115845642",
                "136254344823299089641632103160989644858",
                "297688909824151913766654872262739588309",
                "216729976097115013255701814776289798047",
                "180185616441964989058287363288954897461",
                "51470065149850132163381222019676406371",
                "211116963791258958430153155681741650593",
                "142819131296753291870282252203574107320",
                "99641317539062043800076396353247814941",
                "20062751000800966714424885991095582494",
                "3524829391655607785736054488625959590",
                "285308711308608853525200222490651530726",
                "221213303338563526862413804533158369195",
                "106110530139280483479486341109625407704",
                "18659954621680435469011642667672464748",
                "9707982969585472577793436794979358989",
                "160965529961078887916455312187749788818",
                "146013391718374784487426976873975109258",
                "206373883379033059189226203615049593238",
                "303801799138821698487157043930441392762",
                "326825386241819393728690683195463159476",
                "84532527657212884274646249861099423933",
                "28341361983840020349876385719441377887",
                "303135365304106130322451635473446890950",
                "133774146605694156132630324053735069672",
                "45299260123010201326425676196676710013",
                "119976215894314200880985142473997147879",
                "271550180351889998255102230767094516515",
                "246155403759525558575071166048596234938",
                "134404795502670172313026274632041667577",
                "221735843384022462417203641124807329630",
                "123571575254868753463363884863603325649",
                "92352107853826473518107212005043978130",
                "227892680943522340615524733761526662839",
                "52749102258157006428373534529235152213",
                "68827352053686924516863135133233763909",
                "160754761318703538444245697300284266828",
                "106019209441420949756784238779566842306",
                "169530382517219150431846753428033340510",
                "147839322358190006629032385871813120126",
                "51855169629946393522042946351752976833",
                "114504449870094081080417756134779720254",
                "27533436467246426533520354858622398241",
                "76638868974851344155499799396267205559",
                "247364925531303169626765243158693386338",
                "295231727983073914821410681232832177859",
                "163562483916400001335743481656966910353",
                "147852939056727779580982537173362197760",
                "186985602710958603773420940336845750901",
                "5834442170461206754016615551418886870",
                "241973585149243573392592379212618975713",
                "1316972826486589182748758675081283185",
                "77476179255754766227494953541587300503",
                "15862558724900052454657031896543463013",
                "3616596361239758904890490433495509544",
                "62991281482507324638070959725663390924",
                "325414020009275013428983387330051810959",
                "43425641103644655887180880214818059531",
                "263156113863300464732232884496421787410",
                "106982275064989569324946884180848395959",
                "121076191746619287121145000634125047181",
                "75118385033213809365033478711102484347",
                "120501407754542513216173080816792553326",
                "177593310002318759785547663719102144225",
                "328725216999340989219421924303960209782",
                "156436837066571774439954317116723675882"
            ]
        },
        "target": {
            "file": "pppd/plugins/passprompt.c"
        },
        "source": "https://github.com/ppp-project/ppp/commit/0a66ad22e54c72690ec2a29a019767c55c5281fc",
        "id": "CVE-2024-58250-094d03d7",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "329138925455264730414232949883314204464",
            "length": 1873.0
        },
        "target": {
            "file": "pppd/plugins/passprompt.c",
            "function": "promptpass"
        },
        "source": "https://github.com/ppp-project/ppp/commit/0a66ad22e54c72690ec2a29a019767c55c5281fc",
        "id": "CVE-2024-58250-62841c3d",
        "deprecated": false,
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "digest": {
            "function_hash": "113713398001538128005221545403910223221",
            "length": 148.0
        },
        "target": {
            "file": "pppd/plugins/passprompt.c",
            "function": "plugin_init"
        },
        "source": "https://github.com/ppp-project/ppp/commit/0a66ad22e54c72690ec2a29a019767c55c5281fc",
        "id": "CVE-2024-58250-a173fbc2",
        "deprecated": false,
        "signature_version": "v1"
    }
]