The passprompt plugin in pppd in ppp before 2.5.2 mishandles privileges.
The passprompt plugin, loaded by the pppd process, does not properly handle the permission context — this has been classified as CWE-426 (Untrusted Search Path), which means the possibility of substituting an untrusted component or library during the execution of a process with elevated privileges. The CVSS vector indicates local access (AV:L), no required user interaction (UI:N) and no required attacker privileges (PR:N), and the scope of the attack extends beyond the attacked component (S:C).
An attacker with local access to the system can obtain unauthorized privilege escalation, potentially taking full control of the system — with full impact on confidentiality, integrity and availability of data.
The ppp package should be updated to version 2.5.2 or newer. A patch is available in the project repository (commit 0a66ad22e54c72690ec2a29a019767c55c5281fc). It is also recommended to track distribution updates for the ppp package.
The ppp package in versions before 2.5.2 — affects systems using the pppd daemon with the passprompt plugin.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H