Multiple buffer overflows in the launch_bcrelay function in pptpctrl.c in PoPToP 1.1.4-b1 through PoPToP 1.1.4-b3 allow local users to execute arbitrary code.
| Software | From | Fixed in |
|---|---|---|
| poptop / pptp_server | 1.1.4b3 | 1.1.4b3.x |
| poptop / pptp_server | 1.1.4b1 | 1.1.4b1.x |
| poptop / pptp_server | 1.1.4b2 | 1.1.4b2.x |