PT-2002-1548 · Mtr · Mtr
Published
2002-08-12
·
Updated
2008-09-05
·
CVE-2002-0497
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
mtr versions 0.46 and earlier
Description
A buffer overflow issue exists when mtr is installed setuid root, allowing local users to access a raw socket via a long
MTR OPTIONS environment variable.Recommendations
For mtr versions 0.46 and earlier, consider removing the setuid root installation to prevent exploitation until a patch is available. As a temporary workaround, restrict the use of the
MTR OPTIONS environment variable to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mtr