CVE-2004-0649: Buffer Overflow
Published Jul 13, 2004
·Updated
Buffer overflow in writepacket in control.c for l2tpd may allow remote attackers to execute arbitrary code.
Affected Software
9 affected components
l2tpd l2tpd=0.62
l2tpd l2tpd=0.63
l2tpd l2tpd=0.64
l2tpd l2tpd=0.65
l2tpd l2tpd=0.66
l2tpd l2tpd=0.67
l2tpd l2tpd=0.68
l2tpd l2tpd=0.69
Gentoo Linux=1.4
Remediation
Patch Available
Event History
Jul 13, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0649?
CVE-2004-0649 is considered critical due to its potential for remote code execution.
2
How do I fix CVE-2004-0649?
To fix CVE-2004-0649, upgrade l2tpd to version 0.70 or later.
3
What software is affected by CVE-2004-0649?
CVE-2004-0649 affects l2tpd versions 0.62 through 0.69.
4
Can CVE-2004-0649 allow an attacker to access my system?
Yes, CVE-2004-0649 may allow remote attackers to execute arbitrary code on affected systems.
5
What systems are vulnerable to CVE-2004-0649?
Gentoo Linux 1.4 and various versions of l2tpd from 0.62 to 0.69 are vulnerable to CVE-2004-0649.