PT-2002-2297 · Nanog · Traceroute-Nanog

Published

2002-12-31

·

Updated

2016-10-18

·

CVE-2002-1387

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions traceroute-nanog (affected versions not specified)
Description The issue concerns the spray mode in traceroute-nanog, where local users may be able to overwrite arbitrary memory locations due to an array index overflow. This overflow can be triggered using the nprobes argument.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1387
DSA-254

Affected Products

Traceroute-Nanog