Overview
There is a remotely exploitable buffer overflow in PopTop. An exploit for this vulnerability exists and is publicly available.
Description
From the PopTop web site: PopToP is the PPTP server solution for Linux (ports exist for Solaris 2.6, OpenBSD and FreeBSD and others). |
Impact
A remote attacker may be able to crash the PPTP server or execute arbitrary code with the privileges of the PopTop server. |
Solution
Upgrade to the latest version of PopTop. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://opensource.lineo.com/cgi-bin/cvsweb/~checkout~/poptop/ctrlpacket.c?rev=1.1.1.1&content-type=text/plain&sortby=file
- http://sourceforge.net/mailarchive/forum.php?thread_id=1947395&forum_id=8250
- http://marc.theaimsgroup.com/?l=bugtraq&m=105068728421160&w=2
- http://marc.theaimsgroup.com/?l=bugtraq&m=105154539727967&w=2
- http://www.poptop.org/
Acknowledgements
This vulnerability was discovered by Timo Sirainen.
This document was written by Ian A Finlay.
Other Information
CVE IDs: | CVE-2003-0213 |
Severity Metric: | 27.75 |
Date Public: | 2003-04-09 |
Date First Published: | 2003-04-29 |
Date Last Updated: | 2003-05-01 13:53 UTC |
Document Revision: | 9 |