yocto ▾
›
master ▾
›
vulnerability
›
CVE-2020-7465
Component Overview
Vulnerability Overview
Name
CVE-2020-7465
Source
NVD (
link
)
Debian (
link
)
Description
The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or cause a denial of service (memory corruption).
CWEs
CWE-787
CWE-787
Published Date
Oct 6, 2020
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://sourceforge.net/p/mpd/bugs/70/
Exploit
https://sourceforge.net/p/mpd/svn/2377/
Patch
https://sourceforge.net/p/mpd/bugs/70/
Exploit
https://sourceforge.net/p/mpd/svn/2377/
Patch
Analysis
#
Affected Component
Analysis
mpd
False Positive
Vulnerability Ratings
#
9.8
CVSSv31
7.5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
mpd
yocto
kirkstone
0.23.12
Not Affected
mpd
yocto
scarthgap
0.23.14
False Positive