Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.61039
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1587-1)
Summary:The remote host is missing an update for the Debian 'mtr' package(s) announced via the DSA-1587-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mtr' package(s) announced via the DSA-1587-1 advisory.

Vulnerability Insight:
Adam Zabrocki discovered that under certain circumstances mtr, a full screen ncurses and X11 traceroute tool, could be tricked into executing arbitrary code via overly long reverse DNS records.

For the stable distribution (etch), this problem has been fixed in version 0.71-2etch1.

For the unstable distribution (sid), this problem has been fixed in version 0.73-1.

We recommend that you upgrade your mtr package.

Affected Software/OS:
'mtr' package(s) on Debian 4.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-2357
BugTraq ID: 29290
http://www.securityfocus.com/bid/29290
Bugtraq: 20080519 Mtr - remote and local stack overflow - uncomment situation in libresolv. (Google Search)
http://www.securityfocus.com/archive/1/492260/100/0/threaded
Debian Security Information: DSA-1587 (Google Search)
http://www.debian.org/security/2008/dsa-1587
http://seclists.org/fulldisclosure/2008/May/0488.html
http://security.gentoo.org/glsa/glsa-200806-01.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2008:176
http://www.openwall.com/lists/oss-security/2008/05/21/1
http://www.openwall.com/lists/oss-security/2008/05/21/3
http://www.openwall.com/lists/oss-security/2008/05/21/4
http://www.securitytracker.com/id?1020046
http://secunia.com/advisories/30312
http://secunia.com/advisories/30340
http://secunia.com/advisories/30359
http://secunia.com/advisories/30522
http://secunia.com/advisories/30967
http://securityreason.com/securityalert/3903
SuSE Security Announcement: SUSE-SR:2008:014 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html
XForce ISS Database: mtr-splitredraw-bo(42535)
https://exchange.xforce.ibmcloud.com/vulnerabilities/42535
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.