Skip to main content

CVE-2004-1224

Description

Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.

nvd
CVE ID: CVE-2004-1224
Base Score: 4.6
Base Severity: MEDIUM
Vector String:AV:L/AC:L/Au:N/C:P/I:P/A:P

Refrence: NVD