CVE-2008-2357
Summary
| CVE | CVE-2008-2357 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-05-21 13:24:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c in glibc and the proper fix should be in glibc; if so, then this should not be treated as a vulnerability in mtr. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Matt Kimball And Roger Wolff | Mtr | 0.21 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.22 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.23 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.24 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.25 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.26 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.27 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.28 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.29 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.30 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.31 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.32 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.33 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.34 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.35 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.36 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.37 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.38 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.39 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.40 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.41 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.42 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.43 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.44 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.45 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.46 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.47 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.48 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.49 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.50 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.51 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.52 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.53 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.54 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.55 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.56 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.57 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.58 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.59 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.60 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.61 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.62 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.63 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.64 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.65 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.66 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.67 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.68 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.69 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.70 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | 0.71 | All | All | All |
| Application | Matt Kimball And Roger Wolff | Mtr | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| wiki.rpath.com/wiki/Advisories:rPSA-2008-0175 | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| Support / Security / Advisories / / MDVSA-2008:176 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| mtr 'split.c' Remote Stack Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Full Disclosure: Mtr - remote and local stack overflow - uncomment situation in libresolv. | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| rPath update for mtr - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Re: CVE request: mtr | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| SecurityReason - Mtr - remote and local stack overflow - uncomment situation in libresolv. | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Mtr "split_redraw()" Buffer Overflow Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| ftp.bitwizard.nl/mtr/mtr-0.73.diff | af854a3a-2127-422b-91ae-364da2661108 | ftp.bitwizard.nl | |
| oss-security - Re: CVE request: mtr | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Debian update for mtr - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| mtr: Stack-based buffer overflow — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| issues.rpath.com/browse/RPL-2558 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| Debian -- Security Information -- DSA-1587-1 mtr | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| MTR Buffer Overflow in split_redraw() Function May Let Remote and Local Users Execute Arbitrary Code - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Gentoo update for mtr - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| oss-security - Re: CVE request: mtr | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| [security-announce] SUSE Security Summary Report SUSE-SR:2008:014 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2008-06-25 | Mark J Cox | This issue does not affect the versions of mtr as shipped with Red Hat Enterprise Linux 4 or 5. For Red Hat Enterprise Linux 2.1 and 3, this issue can only be exploited if an attacker can convince victim to use mtr to trace path to or via the IP, for which an attacker controls PTR DNS records. Additionally, the victim must run mtr in "split mode" by providing -p or --split command line options. The Red Hat Security Response Team has therefore rated this issue as having low security impact, a future update may address this flaw. |
There are currently no legacy QID mappings associated with this CVE.