CVE Vulnerabilities

CVE-2002-0872

Published: Sep 05, 2002 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions.

Affected Software

Name Vendor Start Version End Version
L2tpd L2tpd 0.62 (including) 0.62 (including)
L2tpd L2tpd 0.63 (including) 0.63 (including)
L2tpd L2tpd 0.64 (including) 0.64 (including)
L2tpd L2tpd 0.65 (including) 0.65 (including)
L2tpd L2tpd 0.66 (including) 0.66 (including)
L2tpd L2tpd 0.67 (including) 0.67 (including)

References