A stack-based buffer overflow was found in mtr, possibly resulting in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200806-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: mtr: Stack-based buffer overflow Date: June 03, 2008 Bugs: #223017 ID: 200806-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A stack-based buffer overflow was found in mtr, possibly resulting in the execution of arbitrary code. Background ========= mtr combines the functionality of the 'traceroute' and 'ping' programs in a single network diagnostic tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/mtr < 0.73-r1 > = 0.73-r1 Description ========== Adam Zabrocki reported a boundary error within the split_redraw() function in the file split.c, possibly leading to a stack-based buffer overflow. Impact ===== A remote attacker could use a specially crafted resolved hostname to execute arbitrary code with root privileges. However, it is required that the attacker controls the DNS server used by the victim, and that the "-p" (or "--split") command line option is used. Workaround ========= There is no known workaround at this time. Resolution ========= All mtr users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/mtr-0.73-r1" References ========= [ 1 ] CVE-2008-2357 https://www.cve.org/CVERecord?id=CVE-2008-2357 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200806-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-226 2006-03-27 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mtr Version : 0.71 Release : 0.FC4.1 Summary : A network diagnostic tool. Description : Mtr is a network diagnostic tool that combines ping and traceroute into one program. Mtr provides two interfaces: an ncurses interface, useful for using Mtr from a telnet session; and a GTK+ interface for X (provided in the mtr-gtk package). ---------------------------------------------------------------------* Mon Mar 27 2006 Miroslav Lichvar - 2:0.71-0.FC4.1 - update to mtr-0.71 (fixes #162029, #165339) ---------------------------------------------------------------------This update can be downloaded from: b068a80943de18fe01fba49403c171b0a9bc7578 SRPMS/mtr-0.71-0.FC4.1.src.rpm 0b2484a42cad4a86fc990e8eb1ca0b5ba8baa07d ppc/mtr-0.71-0.FC4.1.ppc.rpm b74ee64188f42502e4a2c4f6b315cfa4e4a5c44a ppc/mtr-gtk-0.71-0.FC4.1.ppc.rpm 068c211ce3eca9c415281798dc677bcc7255cb2d ppc/debug/mtr-debuginfo-0.71-0.FC4.1.ppc.rpm 34b15276d0d804c823c737a48047325b7503a74c x86_64/mtr-0.71-0.FC4.1.x86_64.rpm 46a57a129920f878f724f7a53ec11e1aae7cdfad x86_64/mtr-gtk-0.71-0.FC4.1.x86_64.rpm 89addcbcdc49de3f1f4087b278ece5fba02894c8 x86_64/debug/mtr-debuginfo-0.71-0.FC4.1.x86_64.rpm e72d434c12ca0f5b20b6451c9d27ca5019e62564 i386/mtr-0.71-0.FC4.1.i386.rpm d9d805adedc81079ca7a20543b3d670c463e3d7a i386/mtr-gtk-0.71-0.FC4.1.i386.rpm d068fa52419b5003b7c314019a5f9eee6a6e83a8 i386/debug/mtr-debuginfo-0.71-0.FC4.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailinglist
Get the latest Linux and open source security news straight to your inbox.