CVE-2002-0873: Buffer Overflow
Published Sep 5, 2002
·Updated
Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.
Affected Software
6 affected components
l2tpd l2tpd=0.62
l2tpd l2tpd=0.63
l2tpd l2tpd=0.64
l2tpd l2tpd=0.65
l2tpd l2tpd=0.66
l2tpd l2tpd=0.67
Event History
Sep 5, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0873?
CVE-2002-0873 is considered to be a medium severity vulnerability.
2
How do I fix CVE-2002-0873?
To fix CVE-2002-0873, you need to upgrade l2tpd to version 0.68 or later.
3
What software versions are affected by CVE-2002-0873?
CVE-2002-0873 affects l2tpd versions 0.62 to 0.67.
4
What type of attack does CVE-2002-0873 allow?
CVE-2002-0873 allows remote attackers to perform a buffer overflow via long attributes in attribute/value pairs.
5
Is there a direct exploit for CVE-2002-0873?
Yes, there are potential exploit vectors for CVE-2002-0873 that could allow an attacker to overwrite the vendor field.