traceroute-nanog: buffer overflow and root exploit
Package(s):
traceroute-nanog/nkitb
CVE #(s):
Created:
November 12, 2002
Updated:
February 27, 2003
Description:
Traceroute is a tool that can be used to track packets in a TCP/IP network
to determine it's route or to find out about not working routers.
Traceroute-nanog requires root privilege to open a raw socket. It does not
relinquish these privileges after doing so. This allows a malicious user to
gain root access by exploiting a buffer overflow at a later point.