CVE-2014-4943
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
- Linux Linux Kernel
- < 3.2.62, 3.4.102, 3.10.52, 3.12.27, 3.14.16, 3.15.9
- Fix
- Available
- CVSS 2.0
- 6.9 MEDIUM
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-269
- NVD status
- Modified
- Published
- 2014-07-19
CVE-2014-4943 at NVD
7 known exploits for CVE-2014-4943
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Privilege Management in Linux Linux_Kernel
Linux Kernel PPP-over-L2TP Socket Level Handling - Crash PoC
Linux Kernel 3.15.6 - PPP-over-L2TP Socket Level Handling Crash (PoC)
Linux Kernel 3.15.6 - PPP-over-L2TP Socket Level Handling Crash (PoC)
Tails 1.1.1 - The Amnesic Incognito Live System
Immunity Canvas: LINUX_PPPOL2TP
Linux x86 - Socket Re-use Shellcode 50 bytes