Vulnerability Description
Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mtr | Mtr | 0.55 |
References
- http://marc.info/?l=bugtraq&m=110279034910663&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18428
- http://marc.info/?l=bugtraq&m=110279034910663&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18428
FAQ
What is CVE-2004-1224?
CVE-2004-1224 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL...
How severe is CVE-2004-1224?
CVE-2004-1224 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1224?
Check the references section above for vendor advisories and patch information. Affected products include: Mtr Mtr.