CVE-2003-0213
pptpd - buffer overflow
EPSS 71.0%
Description
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.
How to fix CVE-2003-0213
To remediate CVE-2003-0213, upgrade the affected package to a fixed version below.
- Debian/pptpd—upgrade to 1.1.4-0.b3.2 or later
- Debian/pptpd—upgrade to 1.1.2-1.4 or later
Is CVE-2003-0213 being exploited?
Likely — EPSS is 71.0%, placing CVE-2003-0213 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (2)
- from 0, < 1.1.4-0.b3.2
- from 0, < 1.1.2-1.4