CVE-2003-0213 describes a denial-of-service vulnerability in PoPToP PPTP server versions prior to 1.1.4-b3. A remote attacker can exploit this by sending a malformed PPTP control packet with a length field of 0 or 1, leading to a negative value being used in a read operation and subsequently a buffer overflow. This vulnerability carries a CVSS score of 7.5, indicating high severity with network-based exploitation, low attack complexity, and potential for partial confidentiality, integrity, and availability impact. While not listed on the KEV catalog, multiple Metasploit modules and ExploitDB entries confirm the existence of public exploit code, demonstrating its exploitability. Despite this, there is no recorded community discussion or media coverage, suggesting limited public awareness or active exploitation in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.1CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.0.1:*:*:*:*:*:*:* | ||
1.1.2CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.1.2:*:*:*:*:*:*:* | ||
1.1.3CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.1.3:*:*:*:*:*:*:* | ||
1.1.3_2002-10-09CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.1.3_2002-10-09:*:*:*:*:*:*:* | ||
1.1.4b1CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.1.4b1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.