CVE-2023-52557

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/03/2024
Last modified:
10/10/2025

Description

In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* 7.3 (excluding)
cpe:2.3:o:openbsd:openbsd:7.3:-:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_001:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_002:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_003:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_004:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_005:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_006:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_007:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_008:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_009:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_010:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_011:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_012:*:*:*:*:*:*
cpe:2.3:o:openbsd:openbsd:7.3:errata_013:*:*:*:*:*:*