← Vulnerability feed

Vulnerability record · CVE-2003-0213 · published 12 May 2003

CVE-2003-0213: PoPToP PPTP server buffer overflow via malformed length field

Poptop · Pptp Server

ctrlpacket.c in the PoPToP PPTP server before 1.1.4-b3 mishandles a length field of 0 or 1, feeding a negative value into a read operation that leads to a buffer overflow. The flaw is remotely reachable and can crash or corrupt the PPTP service, making it a serious availability and integrity risk for exposed VPN endpoints.

7.5 CVSS 2.0 High EPSS 71% · top 0.6%
7.5CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated buffer overflow with public exploit references and very high EPSS, though no confirmed code execution or KEV listing.

What it is

ctrlpacket.c in the PoPToP PPTP server before 1.1.4-b3 mishandles a length field of 0 or 1, feeding a negative value into a read operation that leads to a buffer overflow. The flaw is remotely reachable and can crash or corrupt the PPTP service, making it a serious availability and integrity risk for exposed VPN endpoints.

Impact

A remote attacker can trigger a buffer overflow, causing denial of service and potentially corrupting process memory; the record does not establish reliable code execution.

Attack surface

Reachable over the network via the PPTP service with no authentication or user interaction required, per the AV:N/AC:L/Au:N vector. Any host exposing the PoPToP PPTP listener is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.71 (99th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.

What to do

  • Upgrade PoPToP PPTP server to 1.1.4-b3 or later; apply the vendor patches referenced in the Debian DSA-295 and SecurityFocus advisories.
  • If patching is not immediately possible, restrict PPTP port 1723 access to trusted networks and disable the service where it is not required.
  • Replace PPTP with a maintained VPN protocol such as IPsec or WireGuard where feasible, since PPTP is legacy and weak.
  • Monitor vendor and CERT/CC advisories for this issue and confirm the installed version against the fixed release.

Detection

  • Inspect PPTP service logs and packet captures for control packets carrying length fields of 0 or 1.
  • Alert on crashes, restarts or abnormal termination of the PoPToP/pptpd process.
  • Monitor for repeated connection attempts to TCP port 1723 from untrusted sources.
  • Use host-based memory or crash telemetry to detect buffer overflow indicators in the PPTP daemon.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0213 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2003-0213), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.