PopTop PPTP Server GRE Packet Denial Of Service Vulnerability
BID:23886
Info
PopTop PPTP Server GRE Packet Denial Of Service Vulnerability
| Bugtraq ID: | 23886 |
| Class: | Design Error |
| CVE: |
CVE-2007-0244 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2007 12:00AM |
| Updated: | Oct 01 2007 07:29PM |
| Credit: | This issue was disclosed to Debian Security Advisory DSA 1288-1. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 PoPToP PPTP Server 1.3.4 PoPToP PPTP Server 1.3 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: | |
Discussion
PopTop PPTP Server GRE Packet Denial Of Service Vulnerability
PoPToP PPTP Server is prone to a denial-of-service vulnerability because it fails to adequately handle certain malformed packet data.
Attackers can exploit this issue to disconnect arbitrary PPTP connections.
PoPToP PPTP Server 1.3.4 is vulnerable; other versions may also be affected.
PoPToP PPTP Server is prone to a denial-of-service vulnerability because it fails to adequately handle certain malformed packet data.
Attackers can exploit this issue to disconnect arbitrary PPTP connections.
PoPToP PPTP Server 1.3.4 is vulnerable; other versions may also be affected.
Exploit / POC
PopTop PPTP Server GRE Packet Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution / Fix
PopTop PPTP Server GRE Packet Denial Of Service Vulnerability
Solution:
Please see the referenced advisories for more information.
PoPToP PPTP Server 1.3
Solution:
Please see the referenced advisories for more information.
PoPToP PPTP Server 1.3
-
Debian bcrelay_1.3.0-2etch2_alpha.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_alpha.deb -
Debian bcrelay_1.3.0-2etch2_amd64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_amd64.deb -
Debian bcrelay_1.3.0-2etch2_arm.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_arm.deb -
Debian bcrelay_1.3.0-2etch2_hppa.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_hppa.deb -
Debian bcrelay_1.3.0-2etch2_i386.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_i386.deb -
Debian bcrelay_1.3.0-2etch2_ia64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_ia64.deb -
Debian bcrelay_1.3.0-2etch2_mips.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_mips.deb -
Debian bcrelay_1.3.0-2etch2_mipsel.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_mipsel.deb -
Debian bcrelay_1.3.0-2etch2_powerpc.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_powerpc.deb -
Debian bcrelay_1.3.0-2etch2_s390.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_s390.deb -
Debian bcrelay_1.3.0-2etch2_sparc.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/bcrelay_1.3.0-2et ch2_sparc.deb -
Debian pptpd_1.3.0-2etch2_alpha.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_alpha.deb -
Debian pptpd_1.3.0-2etch2_amd64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_amd64.deb -
Debian pptpd_1.3.0-2etch2_arm.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_arm.deb -
Debian pptpd_1.3.0-2etch2_hppa.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_hppa.deb -
Debian pptpd_1.3.0-2etch2_i386.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_i386.deb -
Debian pptpd_1.3.0-2etch2_ia64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_ia64.deb -
Debian pptpd_1.3.0-2etch2_mips.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_mips.deb -
Debian pptpd_1.3.0-2etch2_mipsel.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_mipsel.deb -
Debian pptpd_1.3.0-2etch2_powerpc.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_powerpc.deb -
Debian pptpd_1.3.0-2etch2_s390.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_s390.deb -
Debian pptpd_1.3.0-2etch2_sparc.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/p/pptpd/pptpd_1.3.0-2etch 2_sparc.deb
References
PopTop PPTP Server GRE Packet Denial Of Service Vulnerability
References:
References:
- PoPToP PPTP Homepage (PoPToP)