CVE-2002-0872: High severity l2tpd l2tpd vulnerability
Published Sep 5, 2002
·Updated
l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
Affected Software
6 affected components
l2tpd l2tpd=0.62
l2tpd l2tpd=0.63
l2tpd l2tpd=0.64
l2tpd l2tpd=0.65
l2tpd l2tpd=0.66
l2tpd l2tpd=0.67
Event History
Sep 5, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0872?
CVE-2002-0872 is considered a critical vulnerability due to its potential to allow remote session hijacking.
2
How do I fix CVE-2002-0872?
To fix CVE-2002-0872, it is recommended to upgrade to a version of l2tpd that has been patched for this issue, specifically version 0.68 or later.
3
What versions are affected by CVE-2002-0872?
CVE-2002-0872 affects l2tpd versions 0.62 through 0.67.
4
Who can exploit CVE-2002-0872?
CVE-2002-0872 can be exploited by remote attackers with the ability to hijack L2TP sessions.
5
What impact does CVE-2002-0872 have on systems?
The impact of CVE-2002-0872 includes the potential for unauthorized access to sensitive data and disruption of services.