CVE-2000-0949: High severity Lbl Lbl Traceroute vulnerability
Published Dec 19, 2000
·Updated
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
Affected Software
2 affected components
Lbl Lbl Traceroute=1.4a5
Sun SunOS=5.5.1
Remediation
Patch Available
Event History
Dec 19, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-0949?
CVE-2000-0949 has a high severity rating due to the potential for arbitrary command execution.
2
How do I fix CVE-2000-0949?
To fix CVE-2000-0949, upgrade to a version of LBNL traceroute later than 1.4a5.
3
Who is affected by CVE-2000-0949?
CVE-2000-0949 primarily affects local users on systems running vulnerable versions of LBNL traceroute.
4
What is the impact of CVE-2000-0949?
The impact of CVE-2000-0949 allows local users to execute arbitrary commands, leading to potential system compromise.
5
Is CVE-2000-0949 still a relevant vulnerability?
CVE-2000-0949 is considered outdated but is still relevant for systems that have not been updated since the vulnerability was discovered.