In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.
References
Configurations
No configuration.
History
21 Nov 2024, 08:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/016_npppd.patch.sig - | |
References | () https://github.com/openbsd/src/commit/abf3a29384c582c807a621e7fc6e7c68d0cafe9b - |
01 Aug 2024, 13:45
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-805 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
01 Mar 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-01 17:15
Updated : 2024-11-21 08:40
NVD link : CVE-2023-52557
Mitre link : CVE-2023-52557
CVE.ORG link : CVE-2023-52557
JSON object : View
Products Affected
No product.