Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-1224

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2004-1224
Last Modified 10 Sep 2008 03:29:35
Published 10 Jan 2005 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2004-1224

Summary

Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.

Vulnerable Systems

Application

  • Mtr 0.55

  • Mtr 0.56

  • Mtr 0.57

  • Mtr 0.58

  • Mtr 0.59

  • Mtr 0.60

  • Mtr 0.61

  • Mtr 0.62

  • Mtr 0.63

  • Mtr 0.64

  • Mtr 0.65


References

BUGTRAQ - 20041211 Local off-by-one in mtr versions 0.55 to 0.65

XF - mtr-mtrcurseskeyaction-offbyone-bo(18428)


Last Updated: 27 May 2016 10:38:56