Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability
BID:7994
Info
Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability
| Bugtraq ID: | 7994 |
| Class: | Design Error |
| CVE: |
CVE-2003-0453 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 20 2003 12:00AM |
| Updated: | Jul 11 2009 10:06PM |
| Credit: | Discovery of this vulnerability has been credited to "assasa sasasaaa" <[email protected]>. |
| Vulnerable: |
NANOG Traceroute 6.1.1 |
| Not Vulnerable: | |
Discussion
Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability
An integer overflow vulnerability has been reported for Traceroute-Nanog. It has been reported that when processing certain max_ttl and nprobes values from a traceroute invocation, some functions or utilities may fail to sufficiently handle the size of data returned.
Because an attacker can control arbitrary memory corruption, although conjectured and unconfirmed, an attacker might exploit this condition to execute arbitrary instructions with elevated privileges.
It should be noted that this vulnerability might only affect the Debian implementation of Traceroute-Nanog.
An integer overflow vulnerability has been reported for Traceroute-Nanog. It has been reported that when processing certain max_ttl and nprobes values from a traceroute invocation, some functions or utilities may fail to sufficiently handle the size of data returned.
Because an attacker can control arbitrary memory corruption, although conjectured and unconfirmed, an attacker might exploit this condition to execute arbitrary instructions with elevated privileges.
It should be noted that this vulnerability might only affect the Debian implementation of Traceroute-Nanog.
Exploit / POC
Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability
Solution:
Debian has released advisory DSA 348-1 to address this issue. For fix information, see referenced advisory.
NANOG Traceroute 6.1.1
Solution:
Debian has released advisory DSA 348-1 to address this issue. For fix information, see referenced advisory.
NANOG Traceroute 6.1.1
-
Debian traceroute-nanog_6.1.1-1.3_alpha.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_alpha.deb -
Debian traceroute-nanog_6.1.1-1.3_arm.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_arm.deb -
Debian traceroute-nanog_6.1.1-1.3_hppa.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_hppa.deb -
Debian traceroute-nanog_6.1.1-1.3_i386.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_i386.deb -
Debian traceroute-nanog_6.1.1-1.3_ia64.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_ia64.deb -
Debian traceroute-nanog_6.1.1-1.3_m68k.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_m68k.deb -
Debian traceroute-nanog_6.1.1-1.3_mips.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_mips.deb -
Debian traceroute-nanog_6.1.1-1.3_mipsel.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_mipsel.deb -
Debian traceroute-nanog_6.1.1-1.3_powerpc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_powerpc.deb -
Debian traceroute-nanog_6.1.1-1.3_s390.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_s390.deb -
Debian traceroute-nanog_6.1.1-1.3_sparc.deb
Debian GNU/Linux 3.0 (woody)
http://security.debian.org/pool/updates/main/t/traceroute-nanog/tracer oute-nanog_6.1.1-1.3_sparc.deb
References
Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability
References:
References:
- BAZARR FAREWELL ("assasa sasasaaa"
)