Vulnerability Name: | CVE-2003-0453 (CCN-12400) | ||||||||
Assigned: | 2003-06-20 | ||||||||
Published: | 2003-06-20 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | traceroute-nanog 6.1.1 allows local users to overwrite unauthorized memory and possibly execute arbitrary code via certain "nprobes" and "max_ttl" arguments that cause an integer overflow that is used when allocating memory, which leads to a buffer overflow. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Jun 20 2003 - 01:09:30 CDT BAZARR FAREWELL Source: MITRE Type: CNA CVE-2003-0453 Source: BUGTRAQ Type: UNKNOWN 20030620 BAZARR FAREWELL Source: DEBIAN Type: UNKNOWN DSA-348 Source: DEBIAN Type: DSA 348-1 traceroute-nanog Source: DEBIAN Type: DSA-348 traceroute-nanog -- integer overflow Source: CCN Type: OSVDB ID: 4634 NANOG traceroute max_ttl Arbitrary Memory Overwrite Source: CCN Type: OSVDB ID: 4635 NANOG traceroute nprobes Arbitrary Memory Overwrite Source: CCN Type: BID-7994 Traceroute-Nanog Integer Overflow Memory Corruption Vulnerability Source: XF Type: UNKNOWN tracesroute-nanog-integer-overflow(12400) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |