7.5
CVSSv2

CVE-2002-0872

Published: 05/09/2002 Updated: 10/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

l2tpd 0.67 does not initialize the random number generator, which allows remote malicious users to hijack sessions.

Vulnerable Product Search on Vulmon Subscribe to Product

l2tpd l2tpd 0.62

l2tpd l2tpd 0.64

l2tpd l2tpd 0.66

l2tpd l2tpd 0.67

l2tpd l2tpd 0.63

l2tpd l2tpd 0.65

Vendor Advisories

Current versions of l2tpd, a layer 2 tunneling client/server program, forgot to initialize the random generator which made it vulnerable since all generated random number were 100% guessable When dealing with the size of the value in an attribute value pair, too many bytes were able to be copied, which could lead into the vendor field being overwr ...