Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability

An integer overflow vulnerability has been reported for Traceroute-Nanog. It has been reported that when processing certain max_ttl and nprobes values from a traceroute invocation, some functions or utilities may fail to sufficiently handle the size of data returned.

Because an attacker can control arbitrary memory corruption, although conjectured and unconfirmed, an attacker might exploit this condition to execute arbitrary instructions with elevated privileges.

It should be noted that this vulnerability might only affect the Debian implementation of Traceroute-Nanog.







 

Privacy Statement
Copyright 2008, SecurityFocus