Ehud Gavron TrACESroute Terminator Function Format String Vulnerability

A format string vulnerability exists in TrACESroute. The problem exists in the terminator (-T) function of the program. Due to improper use of the fprintf function, an attacker may be able to supply a malicious format string to the program that reults in writing of attacker-supplied values to arbitrary locations in memory.


 

Privacy Statement
Copyright 2010, SecurityFocus