L2TPD Weak Random Number Generator Seeding Vulnerability
BID:5451
Info
L2TPD Weak Random Number Generator Seeding Vulnerability
| Bugtraq ID: | 5451 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 13 2002 12:00AM |
| Updated: | Aug 13 2002 12:00AM |
| Credit: | Reported by Jeff Mcadams <[email protected]>. |
| Vulnerable: |
l2tpd l2tpd 0.67 l2tpd l2tpd 0.66 l2tpd l2tpd 0.65 l2tpd l2tpd 0.64 l2tpd l2tpd 0.63 l2tpd l2tpd 0.62 |
| Not Vulnerable: |
l2tpd l2tpd 0.68 |
Discussion
L2TPD Weak Random Number Generator Seeding Vulnerability
l2tpd is a Layer 2 Tunneling Protocol daemon, implementing the protocol defined in RFC 2661.
Some versions of l2tpd fail to seed the random number generator before calling the function rand(). Predictable random numbers may be used for tunnel and session ids, and within the challenge / response mechanism.
A remote attacker may be able to exploit this weakness to predict the behavior of l2tpd, and possibly to attempt a man in the middle attack or to inject malicious data into a legitimate connection.
l2tpd is a Layer 2 Tunneling Protocol daemon, implementing the protocol defined in RFC 2661.
Some versions of l2tpd fail to seed the random number generator before calling the function rand(). Predictable random numbers may be used for tunnel and session ids, and within the challenge / response mechanism.
A remote attacker may be able to exploit this weakness to predict the behavior of l2tpd, and possibly to attempt a man in the middle attack or to inject malicious data into a legitimate connection.
Exploit / POC
L2TPD Weak Random Number Generator Seeding Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
L2TPD Weak Random Number Generator Seeding Vulnerability
Solution:
An updated version is available:
l2tpd l2tpd 0.62
l2tpd l2tpd 0.63
l2tpd l2tpd 0.64
l2tpd l2tpd 0.65
l2tpd l2tpd 0.66
l2tpd l2tpd 0.67
Solution:
An updated version is available:
l2tpd l2tpd 0.62
-
l2tpd l2tpd-0.68.tar.gz
http://www.l2tpd.org/downloads/l2tpd-0.68.tar.gz
l2tpd l2tpd 0.63
-
l2tpd l2tpd-0.68.tar.gz
http://www.l2tpd.org/downloads/l2tpd-0.68.tar.gz
l2tpd l2tpd 0.64
-
l2tpd l2tpd-0.68.tar.gz
http://www.l2tpd.org/downloads/l2tpd-0.68.tar.gz
l2tpd l2tpd 0.65
-
l2tpd l2tpd-0.68.tar.gz
http://www.l2tpd.org/downloads/l2tpd-0.68.tar.gz
l2tpd l2tpd 0.66
-
l2tpd l2tpd-0.68.tar.gz
http://www.l2tpd.org/downloads/l2tpd-0.68.tar.gz
l2tpd l2tpd 0.67
-
Debian l2tpd_0.67-1.1_alpha.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_al pha.deb -
Debian l2tpd_0.67-1.1_arm.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_ar m.deb -
Debian l2tpd_0.67-1.1_hppa.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_hp pa.deb -
Debian l2tpd_0.67-1.1_i386.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_i3 86.deb -
Debian l2tpd_0.67-1.1_ia64.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_ia 64.deb -
Debian l2tpd_0.67-1.1_m68k.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_m6 8k.deb -
Debian l2tpd_0.67-1.1_mips.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_mi ps.deb -
Debian l2tpd_0.67-1.1_mipsel.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_mi psel.deb -
Debian l2tpd_0.67-1.1_powerpc.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_po werpc.deb -
Debian l2tpd_0.67-1.1_s390.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_s3 90.deb -
Debian l2tpd_0.67-1.1_sparc.deb
http://security.debian.org/pool/updates/main/l/l2tpd/l2tpd_0.67-1.1_sp arc.deb -
l2tpd l2tpd-0.68.tar.gz
http://www.l2tpd.org/downloads/l2tpd-0.68.tar.gz