PPTPD: Denial of Service attack A vulnerability has been reported in PPTPD which could lead to a Denial of Service. pptpd 2007-05-20 2007-05-20 176936 remote 1.3.4 1.3.4

PPTPD is a Point-to-Point Tunnelling Protocol Daemon for Linux.

James Cameron from HP has reported a vulnerability in PPTPD caused by malformed GRE packets.

A remote attacker could exploit this vulnerability to cause a Denial of Service on the PPTPD connection.

There is no known workaround at this time.

All PPTPD users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-dialup/pptpd-1.3.4"
CVE-2007-0244 jaervosz jaervosz dizzutch