First published: Thu Sep 05 2002(Updated: )
l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libp2p | =0.62 | |
Libp2p | =0.63 | |
Libp2p | =0.64 | |
Libp2p | =0.65 | |
Libp2p | =0.66 | |
Libp2p | =0.67 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0872 is considered a critical vulnerability due to its potential to allow remote session hijacking.
To fix CVE-2002-0872, it is recommended to upgrade to a version of l2tpd that has been patched for this issue, specifically version 0.68 or later.
CVE-2002-0872 affects l2tpd versions 0.62 through 0.67.
CVE-2002-0872 can be exploited by remote attackers with the ability to hijack L2TP sessions.
The impact of CVE-2002-0872 includes the potential for unauthorized access to sensitive data and disruption of services.