PEAR Net_Traceroute 'traceroute()' Function Arbitrary Argument Injection Vulnerability
BID:37094
Info
PEAR Net_Traceroute 'traceroute()' Function Arbitrary Argument Injection Vulnerability
| Bugtraq ID: | 37094 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4025 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2009 12:00AM |
| Updated: | Apr 13 2015 10:25PM |
| Credit: | Alex Legler |
| Vulnerable: |
PEAR Net_Traceroute 0.21.1 Gentoo Linux |
| Not Vulnerable: |
PEAR Net_Traceroute 0.21.2 |
Discussion
PEAR Net_Traceroute 'traceroute()' Function Arbitrary Argument Injection Vulnerability
PEAR Net_Traceroute is prone to a remote argument-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary commands within the context of the affected application. Successful exploits will compromise the affected application and possibly the computer.
Versions prior to PEAR Net_Traceroute 0.21.2 are vulnerable.
PEAR Net_Traceroute is prone to a remote argument-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary commands within the context of the affected application. Successful exploits will compromise the affected application and possibly the computer.
Versions prior to PEAR Net_Traceroute 0.21.2 are vulnerable.
Exploit / POC
PEAR Net_Traceroute 'traceroute()' Function Arbitrary Argument Injection Vulnerability
An attacker can exploit the issue via a browser.
An attacker can exploit the issue via a browser.
Solution / Fix
PEAR Net_Traceroute 'traceroute()' Function Arbitrary Argument Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
PEAR Net_Traceroute 'traceroute()' Function Arbitrary Argument Injection Vulnerability
References:
References:
- Bugzilla Bug 294264 (Alex Legler)
- PEAR Home Page (PEAR)
- PEAR Net_Ping and Net_Traceroute Remote Arbitrary Command Injection (PEAR)
- Revision 232735 (PEAR)