PT-2002-2297 · Nanog · Traceroute-Nanog

Publicado

2002-12-31

·

Atualizado

2016-10-18

·

CVE-2002-1387

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions traceroute-nanog (affected versions not specified)
Description The issue concerns the spray mode in traceroute-nanog, where local users may be able to overwrite arbitrary memory locations due to an array index overflow. This overflow can be triggered using the nprobes argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1387
DSA-254

Produtos afetados

Traceroute-Nanog