PoPToP PPTP Negative read() Argument Remote Buffer Overflow Vulnerability
BID:7316
Info
PoPToP PPTP Negative read() Argument Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 7316 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0213 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2003 12:00AM |
| Updated: | Nov 15 2007 12:39AM |
| Credit: | The discovery of this vulnerability has been credited to Timo Sirainen <[email protected]> |
| Vulnerable: |
Redhat Linux 9.0 i386 PoPToP PPTP Server 1.1.4 -b2 PoPToP PPTP Server 1.1.4 -b1 PoPToP PPTP Server 1.1.3 -20021009 PoPToP PPTP Server 1.1.3 PoPToP PPTP Server 1.1.2 PoPToP PPTP Server 1.0.1 PoPToP PPTP Server 1.0 |
| Not Vulnerable: |
PoPToP PPTP Server 1.1.4 -b3 PoPToP PPTP Server 1.1.3 -20030409 |
Discussion
PoPToP PPTP Negative read() Argument Remote Buffer Overflow Vulnerability
A buffer-overflow vulnerability has been discovered in PoPToP PPTP. The problem occurs because the software fails to do sufficient sanity checks when referencing user-supplied input used in various calculations. As a result, an attacker may be able to trigger a condition that would corrupt sensitive memory.
Successful exploits of this issue may allow attackers to execute arbitrary code with the privileges of the affected server.
A buffer-overflow vulnerability has been discovered in PoPToP PPTP. The problem occurs because the software fails to do sufficient sanity checks when referencing user-supplied input used in various calculations. As a result, an attacker may be able to trigger a condition that would corrupt sensitive memory.
Successful exploits of this issue may allow attackers to execute arbitrary code with the privileges of the affected server.