|
|
|
![]() |
Vulnerability Note VU#673993PopTop PPTP Server contains buffer overflow in "ctrlpacket.c"OverviewThere is a remotely exploitable buffer overflow in PopTop. An exploit for this vulnerability exists and is publicly available.I. DescriptionFrom the PopTop web site:PopToP is the PPTP server solution for Linux (ports exist for Solaris 2.6, OpenBSD and FreeBSD and others). II. ImpactA remote attacker may be able to crash the PPTP server or execute arbitrary code with the privileges of the PopTop server.III. SolutionUpgrade to the latest version of PopTop.
Referenceshttp://opensource.lineo.com/cgi-bin/cvsweb/~checkout~/poptop/ctrlpacket.c?rev=1.1.1.1&content-type=text/plain&sortby=file This vulnerability was discovered by Timo Sirainen. This document was written by Ian A Finlay.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||