OSVDB ID: 6726

Title: l2tpd control.c write_packet Function Remote Overflow

Info

Disclosure

Jun 07, 2004

Discovery

Unknown

Dates

Exploit

Jun 04, 2004

Solution

Unknown

Description

A remote overflow exists in l2tpd. The l2tpd program fails to check the boundary in the write_packet() function in control.c, resulting in a buffer overflow. By establishing an L2TP tunnel and then sending a specially crafted packet, a remote attacker can overflow a buffer, resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: Vendor Verified

Solution

Currently, there are no known upgrades, patches, or workarounds available to correct this issue.

Products

l2tpd.org

l2tpd

0.69

Secure Computing Corporation

SnapGear SG300

2.0.2

SnapGear SG530

2.0.2

SnapGear SG550

2.0.2

SnapGear SG570

2.0.2

SnapGear SG575

2.0.2

References

Credit

  • Thomas Walpuski - thomas-bugtraqunproved.org -


Direct URL: http://osvdb.org/6726