Welcome to our website
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Traceroute-nanog Update for Debian
Posted by philipp on: 02/27/2003 11:50 PM [ Print | 0 comment(s) ]
A new security update for Debian GNU/Linux is available:
DSA-254-1 traceroute-nanog -- buffer overflow
A vulnerability has been discovered in NANOG traceroute, an enhanced version of the Van Jacobson/BSD traceroute program. A buffer overflow occurs in the 'get_origin()' function. Due to insufficient bounds checking performed by the whois parser, it may be possible to corrupt memory on the system stack. This vulnerability can be exploited by a remote attacker to gain root privileges on a target host. Though, most probably not in Debian.
Read more
DSA-254-1 traceroute-nanog -- buffer overflow
A vulnerability has been discovered in NANOG traceroute, an enhanced version of the Van Jacobson/BSD traceroute program. A buffer overflow occurs in the 'get_origin()' function. Due to insufficient bounds checking performed by the whois parser, it may be possible to corrupt memory on the system stack. This vulnerability can be exploited by a remote attacker to gain root privileges on a target host. Though, most probably not in Debian.
Read more
