Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.11388
Category:Gain root remotely
Title:l2tpd < 0.68 overflow
Summary:NOSUMMARY
Description:Description:

The remote host is running a version of l2tpd which is older or
equal to 0.67.

This version is vulnerable to a buffer overflow
which may allow an attacker to gain a root shell on this host.

In addition, this program does not initialize its random number generator.
Therefore, an attacker may predict some key values and hijack L2TP sessions
established to this host.

Solution : upgrade to l2tpd 0.68 or newer
Risk factor : High

Cross-Ref: BugTraq ID: 5451
Common Vulnerability Exposure (CVE) ID: CVE-2002-0872
http://www.securityfocus.com/bid/5451
Bugtraq: 20020813 New l2tpd release 0.68 (Google Search)
Debian Security Information: DSA-152 (Google Search)
http://www.debian.org/security/2002/dsa-152
http://www.iss.net/security_center/static/9845.php
Common Vulnerability Exposure (CVE) ID: CVE-2002-0873
http://www.iss.net/security_center/static/10460.php
CopyrightThis script is Copyright (C) 2003 Renaud Deraison

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.