{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "integer overflow in option parsing",
    "tracking": {
      "current_release_date": "2026-08-11T14:05:09+00:00",
      "generator": {
        "date": "2026-08-11T14:05:09+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-3158",
      "initial_release_date": "2014-08-10T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:05:09+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 5.11",
            "product": {
              "name": "Red Hat Enterprise Linux 5.11",
              "product_id": "rhel-5.11.z.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:5"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 6-els",
            "product": {
              "name": "Red Hat Enterprise Linux 6-els",
              "product_id": "rhel-6-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7-els",
            "product": {
              "name": "Red Hat Enterprise Linux 7-els",
              "product_id": "rhel-7-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ppp",
            "product": {
              "name": "ppp",
              "product_id": "ppp",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ppp"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ppp-debuginfo",
            "product": {
              "name": "ppp-debuginfo",
              "product_id": "ppp-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ppp-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ppp-devel",
            "product": {
              "name": "ppp-devel",
              "product_id": "ppp-devel",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ppp-devel"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ppp",
            "product": {
              "name": "ppp",
              "product_id": "ppp.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ppp?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:ppp"
        },
        "product_reference": "ppp",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:ppp"
        },
        "product_reference": "ppp",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:ppp-debuginfo"
        },
        "product_reference": "ppp-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp-debuginfo as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:ppp-debuginfo"
        },
        "product_reference": "ppp-debuginfo",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp-devel as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:ppp-devel"
        },
        "product_reference": "ppp-devel",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp-devel as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:ppp-devel"
        },
        "product_reference": "ppp-devel",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp.src as a component of Red Hat Enterprise Linux 5.11",
          "product_id": "rhel-5.11.z.els:ppp.src"
        },
        "product_reference": "ppp.src",
        "relates_to_product_reference": "rhel-5.11.z.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:ppp.src"
        },
        "product_reference": "ppp.src",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ppp.src as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:ppp.src"
        },
        "product_reference": "ppp.src",
        "relates_to_product_reference": "rhel-6-els.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-3158",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "discovery_date": "2014-08-11T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-6-els.els:ppp-debuginfo",
            "rhel-6-els.els:ppp-devel",
            "rhel-7-els.els:ppp-debuginfo",
            "rhel-7-els.els:ppp-devel"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.\n\nThis issue affects the versions of ppp as shipped with Red Hat Enterprise Linux 6 and 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/clasification/.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to \"access privileged options\" via a long word in an options file, which triggers a heap-based buffer overflow that \"[corrupts] security-relevant variables.\"",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhel-5.11.z.els:ppp.src",
          "rhel-6-els.els:ppp",
          "rhel-6-els.els:ppp.src",
          "rhel-7-els.els:ppp",
          "rhel-7-els.els:ppp.src"
        ],
        "known_not_affected": [
          "rhel-6-els.els:ppp-debuginfo",
          "rhel-6-els.els:ppp-devel",
          "rhel-7-els.els:ppp-debuginfo",
          "rhel-7-els.els:ppp-devel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-3158"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3158"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-3158"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "rhel-5.11.z.els:ppp.src",
            "rhel-6-els.els:ppp",
            "rhel-6-els.els:ppp.src",
            "rhel-7-els.els:ppp",
            "rhel-7-els.els:ppp.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:L/AC:M/Au:N/C:N/I:P/A:N",
            "baseScore": 1.9
          },
          "products": [
            "rhel-5.11.z.els:ppp.src",
            "rhel-6-els.els:ppp",
            "rhel-6-els.els:ppp-debuginfo",
            "rhel-6-els.els:ppp-devel",
            "rhel-6-els.els:ppp.src",
            "rhel-7-els.els:ppp",
            "rhel-7-els.els:ppp-debuginfo",
            "rhel-7-els.els:ppp-devel",
            "rhel-7-els.els:ppp.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhel-5.11.z.els:ppp.src",
            "rhel-6-els.els:ppp",
            "rhel-6-els.els:ppp-debuginfo",
            "rhel-6-els.els:ppp-devel",
            "rhel-6-els.els:ppp.src",
            "rhel-7-els.els:ppp",
            "rhel-7-els.els:ppp-debuginfo",
            "rhel-7-els.els:ppp-devel",
            "rhel-7-els.els:ppp.src"
          ]
        }
      ],
      "title": "integer overflow in option parsing"
    }
  ]
}