CVE-2008-2357
mtr - execution of arbitrary code
EPSS 4.7%
Description
Stack-based buffer overflow in the split_redraw function in split.c in mtr before 0.73, when invoked with the -p (aka --split) option, allows remote attackers to execute arbitrary code via a crafted DNS PTR record. NOTE: it could be argued that this is a vulnerability in the ns_name_ntop function in resolv/ns_name.c in glibc and the proper fix should be in glibc; if so, then this should not be treated as a vulnerability in mtr.
How to fix CVE-2008-2357
To remediate CVE-2008-2357, upgrade the affected package to a fixed version below.
- Debian/mtr—upgrade to 0.73-1 or later
- —upgrade to 0.71-2etch1 or later
Is CVE-2008-2357 being exploited?
Low — EPSS is 4.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.73-1
- from 0, < 0.71-2etch1