First published: Mon Mar 12 2001(Updated: )
traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD current | <=1.3.3 | |
Slackware Linux | =2.0.34 | |
Digital OpenVMS | =4.0 | |
Debian | =2.0.34 | |
Red Hat Linux | =2.0.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0314 is a vulnerability in the traceroute utility that allows local users to flood other systems by improperly parsing the waittime option.
CVE-2000-0314 affects NetBSD 1.3.3, Slackware Linux 2.0.34, Digital UNIX 4.0, Debian Linux 2.0.34, and Red Hat Linux 2.0.34.
CVE-2000-0314 is considered a local denial-of-service vulnerability.
To fix CVE-2000-0314, you should update the affected systems to a version of traceroute that does not have the vulnerability.
CVE-2000-0314 cannot be exploited remotely as it requires local user access to the affected system.