CVE Vulnerabilities

CVE-2002-0872

Published: Sep 05, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.

Affected Software

NameVendorStart VersionEnd Version
L2tpdL2tpd0.62 (including)0.62 (including)
L2tpdL2tpd0.63 (including)0.63 (including)
L2tpdL2tpd0.64 (including)0.64 (including)
L2tpdL2tpd0.65 (including)0.65 (including)
L2tpdL2tpd0.66 (including)0.66 (including)
L2tpdL2tpd0.67 (including)0.67 (including)

References