20000928 Very interesting traceroute flawmailing list
http://archives.neohapsis.com/archives/bugtraq/2000-09/0344.html CVE-2000-0949
LBL Traceroute - Local Privilege Escalation
Record summary
CVE-2000-0949 has a selected CVSS score of 7.2; EIP currently links 4 catalogued exploits.
Description
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 4
Proofs of concept
4Catalogued exploits
ExploitDBLBL Traceroute - Local Privilege EscalationExploitDB exploitby Michel KaempfNot analyzed1 file
ExploitDBLBL Traceroute 1.4 a5 - Heap Corruption (1)ExploitDB exploitby DvorakNot analyzed1 file
ExploitDBLBL Traceroute 1.4 a5 - Heap Corruption (2)ExploitDB exploitby Perry HarringtonNot analyzed1 file
ExploitDBLBL Traceroute 1.4 a5 - Heap Corruption (3)ExploitDB exploitby Michel KaempfNot analyzed1 file
References
1020000930 Conectiva Linux Security Announcement - traceroutemailing list
http://archives.neohapsis.com/archives/bugtraq/2000-09/0357.html CSSA-2000-034.0Vendor advisory
http://www.calderasystems.com/support/security/advisories/CSSA-2000-034.0.txt 20001013 traceroute: local root exploitVendor advisory
http://www.debian.org/security/2000/20001013 MDKSA-2000:053Vendor advisory
http://www.linux-mandrake.com/en/security/MDKSA-2000-053.php3?dis=7.1 RHSA-2000:078Vendor advisory
http://www.redhat.com/support/errata/RHSA-2000-078.html 1739vdb entry
http://www.securityfocus.com/bid/1739 TLSA2000023-1Vendor advisory
http://www.turbolinux.com/pipermail/tl-security-announce/2000-October/000025.html traceroute-heap-overflow(5311)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/5311 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2000-0949