VYPR
Unrated severityNVD Advisory· Published Jan 10, 2005· Updated Apr 16, 2026

CVE-2004-1224

CVE-2004-1224

Description

Off-by-one error in the mtr_curses_keyaction function for mtr 0.55 through 0.65 allows local users to hijack raw sockets, as demonstrated using the "s" keybinding, which leaves a buffer without a NULL terminator.

Affected products

11
  • Mtr/Mtr11 versions
    cpe:2.3:a:mtr:mtr:0.55:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:mtr:mtr:0.55:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.56:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.57:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.58:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.59:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.60:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.61:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.62:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.63:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.64:*:*:*:*:*:*:*
    • cpe:2.3:a:mtr:mtr:0.65:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.