CVE-2007-0244 describes a denial-of-service vulnerability in PoPToP Point to Point Tunneling Server (pptpd) versions prior to 1.3.4, affecting Debian Linux and PoPToP pptp_server. Remote attackers can exploit this flaw by sending specially crafted GRE packets, either with out-of-order sequence numbers or those improperly processed due to a wrong pointer, leading to the termination of PPTP connections. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with a low attack complexity and no authentication required, but only impacts availability. There is no evidence of active exploitation, and no public exploit code or community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.3CPE matchmatch criteria | cpe:2.3:a:poptop:pptp_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.