See how l2tpd compares to other vendors in security performance
Buffer overflow in writepacket in control.c for l2tpd may allow remote attackers to execute arbitrary code.
l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.
Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow.