LWN.net Logo

tcptraceroute: problems dropping root privileges

Package(s):tcptraceroute CVE #(s):CAN-2003-0489
Created:June 28, 2003 Updated:July 10, 2003
Description: tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets. This may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.
Alerts:
Gentoo 200306-14 2003-06-28
Debian DSA-330-1 2003-06-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds