CVE-2006-5873
published 2006-12-12CVE-2006-5873: Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
2.30%
81.6th percentile
Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | l2tpns | < l2tpns 2.1.21-1 (bookworm) | l2tpns 2.1.21-1 (bookworm) |
| l2tpns | l2tpns | — | — |
| l2tpns | l2tpns | — | — |
| l2tpns | l2tpns | — | — |
| l2tpns | l2tpns | >= 0 < 2.1.21-1 | 2.1.21-1 |
| l2tpns | l2tpns | >= 0 < 2.1.21-1 | 2.1.21-1 |
| l2tpns | l2tpns | >= 0 < 2.1.21-1 | 2.1.21-1 |
| l2tpns | l2tpns | >= 0 < 2.1.21-1 | 2.1.21-1 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-548f-88j9-xqq6: Buffer overflow in the cluster_process_heartbeat function in cluster
ghsa_unreviewed·2022-05-01
CVE-2006-5873 [HIGH] GHSA-548f-88j9-xqq6: Buffer overflow in the cluster_process_heartbeat function in cluster
Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.
OSV
CVE-2006-5873: Buffer overflow in the cluster_process_heartbeat function in cluster
osv·2006-12-12·CVSS 7.8
CVE-2006-5873 [HIGH] CVE-2006-5873: Buffer overflow in the cluster_process_heartbeat function in cluster
Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.
Debian
CVE-2006-5873: l2tpns - Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer ...
vendor_debian·2006·CVSS 7.8
CVE-2006-5873 [HIGH] CVE-2006-5873: l2tpns - Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer ...
Buffer overflow in the cluster_process_heartbeat function in cluster.c in layer 2 tunneling protocol network server (l2tpns) before 2.1.21 allows remote attackers to cause a denial of service via a large heartbeat packet.
Scope: local
bookworm: resolved (fixed in 2.1.21-1)
bullseye: resolved (fixed in 2.1.21-1)
forky: resolved (fixed in 2.1.21-1)
sid: resolved (fixed in 2.1.21-1)
trixie: resolved (fixed in 2.1.21-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://l2tpns.cvs.sourceforge.net/l2tpns/l2tpns/cluster.c?r1=1.53&r2=1.54http://secunia.com/advisories/23230http://secunia.com/advisories/23333http://sourceforge.net/project/shownotes.php?group_id=97282&release_id=468202http://www.debian.org/security/2006/dsa-1230http://www.securityfocus.com/bid/21443http://www.vupen.com/english/advisories/2006/4860https://exchange.xforce.ibmcloud.com/vulnerabilities/30732http://l2tpns.cvs.sourceforge.net/l2tpns/l2tpns/cluster.c?r1=1.53&r2=1.54http://secunia.com/advisories/23230http://secunia.com/advisories/23333http://sourceforge.net/project/shownotes.php?group_id=97282&release_id=468202http://www.debian.org/security/2006/dsa-1230http://www.securityfocus.com/bid/21443http://www.vupen.com/english/advisories/2006/4860https://exchange.xforce.ibmcloud.com/vulnerabilities/30732
2006-12-12
Published