First published: Fri Mar 01 2024(Updated: )
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
Credit: 9119a7d8-5eab-497f-8521-727c672e3725
Affected Software | Affected Version | How to fix |
---|---|---|
OpenBSD | <7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-52557 is considered a moderate severity vulnerability due to the potential for npppd to crash when processing malicious l2tp messages.
To fix CVE-2023-52557, apply errata 016 or update to a version of OpenBSD later than 7.3.
CVE-2023-52557 affects OpenBSD versions prior to errata 016 in version 7.3.
CVE-2023-52557 impacts the npppd component in OpenBSD, specifically related to handling l2tp messages.
Currently, there are no documented workarounds for CVE-2023-52557 aside from patching or upgrading the affected software.