CVE-2003-1455 describes multiple buffer overflow vulnerabilities in the launch_bcrelay function of pptpctrl.c within PoPToP versions 1.1.4-b1 through 1.1.4-b3. This flaw allows local users to execute arbitrary code on affected systems. With a CVSS score of 7.2, it is considered high severity, requiring local access with low attack complexity to achieve complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, with 10 mentions, primarily on GitHub.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1.4b1CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.1.4b1:*:*:*:*:*:*:* | ||
1.1.4b2CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.1.4b2:*:*:*:*:*:*:* | ||
1.1.4b3CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:1.1.4b3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.