Vulnerability Description
traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian | Debian Linux | 2.0.34 |
| Digital | Unix | 4.0 |
| Netbsd | Netbsd | <= 1.3.3 |
| Redhat | Linux | 2.0.34 |
| Slackware | Slackware Linux | 2.0.34 |
References
- ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.aPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=91893782027835&w=2
- http://www.osvdb.org/7575
- ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.aPatchVendor Advisory
- http://marc.info/?l=bugtraq&m=91893782027835&w=2
- http://www.osvdb.org/7575
FAQ
What is CVE-2000-0315?
CVE-2000-0315 is a vulnerability with a CVSS score of 5.0 (MEDIUM). traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.
How severe is CVE-2000-0315?
CVE-2000-0315 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2000-0315?
Check the references section above for vendor advisories and patch information. Affected products include: Debian Debian Linux, Digital Unix, Netbsd Netbsd, Redhat Linux, Slackware Slackware Linux.