RSS   Vulnerabilities for 'MTR'   RSS

2005-01-10
 
CVE-2004-1224

 

 
Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.

 
2002-08-12
 
CVE-2002-0497

 

 
Buffer overflow in mtr 0.46 and earlier, when installed setuid root, allows local users to access a raw socket via a long MTR_OPTIONS environment variable.

 


Copyright 2024, cxsecurity.com

 

Back to Top