CVE Database
/

CVE-2008-2357

Back to search

CVE-2008-2357

Published: May 21, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c in glibc and the proper fix should be in glibc; if so, then this should not be treated as a vulnerability in mtr.

VendorProductVersions

n/a

n/a

affected
n/a

References

30340
third-party-advisory
x_refsource_SECUNIA
30522
third-party-advisory
x_refsource_SECUNIA
30312
third-party-advisory
x_refsource_SECUNIA
MDVSA-2008:176
vendor-advisory
x_refsource_MANDRIVA
29290
vdb-entry
x_refsource_BID
GLSA-200806-01
vendor-advisory
x_refsource_GENTOO
30967
third-party-advisory
x_refsource_SECUNIA
30359
third-party-advisory
x_refsource_SECUNIA
mtr-splitredraw-bo(42535)
vdb-entry
x_refsource_XF
3903
third-party-advisory
x_refsource_SREASON
DSA-1587
vendor-advisory
x_refsource_DEBIAN
SUSE-SR:2008:014
vendor-advisory
x_refsource_SUSE
1020046
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now