Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Traceroute-nanog本地缓冲区溢出漏洞
Vulnerability Description
Traceroute-nanog是一款开放源代码路由跟踪信息搜寻程序,可以对每一跳点进行DNS解析,获得管理员EMAIL地址等信息。 Traceroute-nanog中的'traceroute.c'文件中'get_origin()'函数缺少正确的边界缓冲区检查,本地攻击者可以利用这个漏洞进行基于堆的缓冲区溢出,精心构建提交数据可以获得root用户权限。 'traceroute.c'文件中get_origin()函数被调用的时候,其堆栈情况如下如示: char buf[256] tmp4[100] tmp3
CVSS Information
N/A
Vulnerability Type
N/A