First published: Tue Dec 19 2000(Updated: )
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands via the -g option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lbl Lbl Traceroute | =1.4a5 | |
Sun SunOS | =5.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0949 has a high severity rating due to the potential for arbitrary command execution.
To fix CVE-2000-0949, upgrade to a version of LBNL traceroute later than 1.4a5.
CVE-2000-0949 primarily affects local users on systems running vulnerable versions of LBNL traceroute.
The impact of CVE-2000-0949 allows local users to execute arbitrary commands, leading to potential system compromise.
CVE-2000-0949 is considered outdated but is still relevant for systems that have not been updated since the vulnerability was discovered.