CVE-2014-3158: Point-To-Point Protocol Project Point-To-Point Protocol

High severity, CVSS 7.5. EPSS: 3.5% chance of exploitation in the next 30 days.

Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options file, which triggers a heap-based buffer overflow that "[corrupts] security-relevant variables."

Affected products

Published 2014-11-15. Last modified 2026-06-17.