Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2003-0213
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2003-0213

Description:
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.

CVE Status:
Candidate

References:

SUSE
  http://www.novell.com/linux/security/advisories/2003_029.html

DEBIAN
  http://www.debian.org/security/2003/dsa-295

CONFIRM
  http://sourceforge.net/project/shownotes.php?release_id=138437

CERT-VN
  673993

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=105154539727967&w=2
  http://www.securityfocus.com/archive/1/319428
  http://marc.theaimsgroup.com/?l=bugtraq&m=105068728421160&w=2
  http://www.securityfocus.com/archive/1/317995

BID
  7316


Return to the previous page.