CVE-2023-52557
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/03/2024
Last modified:
10/10/2025
Description
In OpenBSD 7.3 before errata 016, npppd(8) could crash by a l2tp message which has an AVP (Attribute-Value Pair) with wrong length.<br />
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:* | 7.3 (excluding) | |
| cpe:2.3:o:openbsd:openbsd:7.3:-:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_001:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_002:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_003:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_004:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_005:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_006:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_007:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_008:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_009:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_010:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_011:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_012:*:*:*:*:*:* | ||
| cpe:2.3:o:openbsd:openbsd:7.3:errata_013:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/016_npppd.patch.sig
- https://github.com/openbsd/src/commit/abf3a29384c582c807a621e7fc6e7c68d0cafe9b
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/016_npppd.patch.sig
- https://github.com/openbsd/src/commit/abf3a29384c582c807a621e7fc6e7c68d0cafe9b



