ID

VAR-200210-0206


CVE

CVE-2002-1051


TITLE

TrACESroute Format string vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200210-014

DESCRIPTION

Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument. A format string vulnerability exists in TrACESroute. The problem exists in the terminator (-T) function of the program. Due to improper use of the fprintf function, an attacker may be able to supply a malicious format string to the program that reults in writing of attacker-supplied values to arbitrary locations in memory

Trust: 1.26

sources: NVD: CVE-2002-1051 // BID: 4956 // VULHUB: VHN-5440

AFFECTED PRODUCTS

vendor:ehud gavronmodel:tracesroutescope:eqversion:6.1.1

Trust: 1.6

vendor:ehud gavronmodel:tracesroutescope:eqversion:6.0

Trust: 1.6

vendor:ehud gavronmodel:tracesroutescope:eqversion:6.1

Trust: 1.6

vendor:ehudmodel:gavron tracesroutescope:eqversion:6.1.1

Trust: 0.3

vendor:ehudmodel:gavron tracesroutescope:eqversion:6.1

Trust: 0.3

vendor:ehudmodel:gavron tracesroutescope:eqversion:6.0

Trust: 0.3

sources: BID: 4956 // CNNVD: CNNVD-200210-014 // NVD: CVE-2002-1051

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-1051
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200210-014
value: MEDIUM

Trust: 0.6

VULHUB: VHN-5440
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2002-1051
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-5440
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-5440 // CNNVD: CNNVD-200210-014 // NVD: CVE-2002-1051

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-1051

THREAT TYPE

local

Trust: 0.9

sources: BID: 4956 // CNNVD: CNNVD-200210-014

TYPE

format string

Trust: 0.6

sources: CNNVD: CNNVD-200210-014

EXTERNAL IDS

db:BIDid:4956

Trust: 2.0

db:NVDid:CVE-2002-1051

Trust: 1.7

db:CNNVDid:CNNVD-200210-014

Trust: 0.7

db:SUSEid:SUSE-SA:2000:041

Trust: 0.6

db:BUGTRAQid:20020606 FORMAT STRING BUG IN TRACESROUTE 6.0 GOLD

Trust: 0.6

db:BUGTRAQid:20020724 RE: NANOG TRACEROUTE FORMAT STRING EXPLOIT.

Trust: 0.6

db:BUGTRAQid:20020723 RE: NANOG TRACEROUTE FORMAT STRING EXPLOIT.

Trust: 0.6

db:BUGTRAQid:20020721 NANOG TRACEROUTE FORMAT STRING EXPLOIT.

Trust: 0.6

db:XFid:9291

Trust: 0.6

db:VULHUBid:VHN-5440

Trust: 0.1

sources: VULHUB: VHN-5440 // BID: 4956 // CNNVD: CNNVD-200210-014 // NVD: CVE-2002-1051

REFERENCES

url:http://www.securityfocus.com/bid/4956

Trust: 1.7

url:http://archives.neohapsis.com/archives/bugtraq/2002-06/0040.html

Trust: 1.7

url:http://archives.neohapsis.com/archives/bugtraq/2002-07/0254.html

Trust: 1.7

url:http://www.novell.com/linux/security/advisories/2000_041_traceroute_txt.html

Trust: 1.7

url:http://www.iss.net/security_center/static/9291.php

Trust: 1.7

url:http://marc.info/?l=bugtraq&m=102737546927749&w=2

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=102753136231920&w=2

Trust: 1.1

url:http://marc.theaimsgroup.com/?l=bugtraq&m=102753136231920&w=2

Trust: 0.6

url:http://marc.theaimsgroup.com/?l=bugtraq&m=102737546927749&w=2

Trust: 0.6

sources: VULHUB: VHN-5440 // CNNVD: CNNVD-200210-014 // NVD: CVE-2002-1051

CREDITS

Vulnerability discovery credited to DownBload <downbload@hotmail.com>.

Trust: 0.3

sources: BID: 4956

SOURCES

db:VULHUBid:VHN-5440
db:BIDid:4956
db:CNNVDid:CNNVD-200210-014
db:NVDid:CVE-2002-1051

LAST UPDATE DATE

2024-08-14T15:45:47.204000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-5440date:2016-10-18T00:00:00
db:BIDid:4956date:2002-06-06T00:00:00
db:CNNVDid:CNNVD-200210-014date:2005-05-02T00:00:00
db:NVDid:CVE-2002-1051date:2016-10-18T02:23:30.133

SOURCES RELEASE DATE

db:VULHUBid:VHN-5440date:2002-10-04T00:00:00
db:BIDid:4956date:2002-06-06T00:00:00
db:CNNVDid:CNNVD-200210-014date:2002-10-04T00:00:00
db:NVDid:CVE-2002-1051date:2002-10-04T04:00:00