MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vulnerability
BID:11884
Info
MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vulnerability
| Bugtraq ID: | 11884 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 11 2004 12:00AM |
| Updated: | Dec 11 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Przemyslaw Frasunek <[email protected]>. |
| Vulnerable: |
mtr mtr 0.65 mtr mtr 0.64 mtr mtr 0.63 mtr mtr 0.62 mtr mtr 0.61 mtr mtr 0.60 mtr mtr 0.59 mtr mtr 0.58 mtr mtr 0.57 mtr mtr 0.56 mtr mtr 0.55 |
| Not Vulnerable: | |
Discussion
MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vulnerability
MTR is reported prone to an off-by-one buffer overflow vulnerability. The issue is present in the mtr_curses_keyaction() function for the key bindings 's', 'b', 'Q', 'i', 'f', 'm' and 'o'.
Exploitation of this vulnerability could allow a local attacker to hijack a raw socket. The possibility of successful exploitation may depend on certain properties of the underlying environment, including the architecture and the compiler version used. These factors may limit the possibility of exploiting the condition to corrupt a sensitive value in memory.
MTR is reported prone to an off-by-one buffer overflow vulnerability. The issue is present in the mtr_curses_keyaction() function for the key bindings 's', 'b', 'Q', 'i', 'f', 'm' and 'o'.
Exploitation of this vulnerability could allow a local attacker to hijack a raw socket. The possibility of successful exploitation may depend on certain properties of the underlying environment, including the architecture and the compiler version used. These factors may limit the possibility of exploiting the condition to corrupt a sensitive value in memory.
Exploit / POC
MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MTR MTR_Curses_KeyAction Local Off-By-One Buffer Overflow Vulnerability
References:
References:
- mtr Homepage (mtr)
- Local off-by-one in mtr versions 0.55 to 0.65 (Przemyslaw Frasunek
)