CVE-2003-0489 Information

Description

tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.

Reference

http://www.debian.org/security/2003/dsa-330

Share on: