Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-01-10 05:00
Updated : 2024-02-04 16:52
NVD link : CVE-2004-1224
Mitre link : CVE-2004-1224
CVE.ORG link : CVE-2004-1224
JSON object : View
Products Affected
mtr
- mtr
CWE