CVE-2003-0213

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/05/2003
Last modified:
18/10/2016

Description

ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:poptop:pptp_server:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:poptop:pptp_server:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:poptop:pptp_server:1.1.3:*:*:*:*:*:*:*
cpe:2.3:a:poptop:pptp_server:1.1.3_2002-10-09:*:*:*:*:*:*:*
cpe:2.3:a:poptop:pptp_server:1.1.4b1:*:*:*:*:*:*:*
cpe:2.3:a:poptop:pptp_server:1.1.4b2:*:*:*:*:*:*:*