Vulnerability record · CVE-2003-0213 · published 12 May 2003
CVE-2003-0213: PoPToP PPTP server buffer overflow via malformed length field
Poptop · Pptp Server
ctrlpacket.c in the PoPToP PPTP server before 1.1.4-b3 mishandles a length field of 0 or 1, feeding a negative value into a read operation that leads to a buffer overflow. The flaw is remotely reachable and can crash or corrupt the PPTP service, making it a serious availability and integrity risk for exposed VPN endpoints.
Description
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length field of 0 or 1, which causes a negative value to be fed into a read operation, leading to a buffer overflow.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated buffer overflow with public exploit references and very high EPSS, though no confirmed code execution or KEV listing.
What it is
ctrlpacket.c in the PoPToP PPTP server before 1.1.4-b3 mishandles a length field of 0 or 1, feeding a negative value into a read operation that leads to a buffer overflow. The flaw is remotely reachable and can crash or corrupt the PPTP service, making it a serious availability and integrity risk for exposed VPN endpoints.
Impact
A remote attacker can trigger a buffer overflow, causing denial of service and potentially corrupting process memory; the record does not establish reliable code execution.
Attack surface
Reachable over the network via the PPTP service with no authentication or user interaction required, per the AV:N/AC:L/Au:N vector. Any host exposing the PoPToP PPTP listener is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.71 (99th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists. No ransomware association is documented.
What to do
- Upgrade PoPToP PPTP server to 1.1.4-b3 or later; apply the vendor patches referenced in the Debian DSA-295 and SecurityFocus advisories.
- If patching is not immediately possible, restrict PPTP port 1723 access to trusted networks and disable the service where it is not required.
- Replace PPTP with a maintained VPN protocol such as IPsec or WireGuard where feasible, since PPTP is legacy and weak.
- Monitor vendor and CERT/CC advisories for this issue and confirm the installed version against the fixed release.
Detection
- Inspect PPTP service logs and packet captures for control packets carrying length fields of 0 or 1.
- Alert on crashes, restarts or abnormal termination of the PoPToP/pptpd process.
- Monitor for repeated connection attempts to TCP port 1723 from untrusted sources.
- Use host-based memory or crash telemetry to detect buffer overflow indicators in the PPTP daemon.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2003-0213 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0213), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.