First published: Tue Oct 06 2020(Updated: )
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).
Credit: secteam@freebsd.org secteam@freebsd.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mpd Project Mpd | <5.9 | |
Stormshield Stormshield Network Security | >=4.0.0<4.3.17 | |
Stormshield Stormshield Network Security | =4.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7465.
CVE-2020-7465 has a severity rating of 9.8 (critical).
The affected software for CVE-2020-7465 includes MPD (version up to exclusive 5.9) and Stormshield Network Security (version between inclusive 4.0.0 and exclusive 4.3.17, as well as version 4.4.0).
CVE-2020-7465 is a vulnerability in the L2TP implementation of MPD before 5.9 that allows a remote attacker to execute arbitrary code or cause a denial of service through a specifically crafted L2TP control packet with AVP Q.931 Cause Code, resulting in memory corruption.
To fix CVE-2020-7465, it is recommended to update MPD to version 5.9 or higher and Stormshield Network Security to a version higher than 4.3.17, as well as apply any patches or security updates provided by the vendors.