CVE-2000-0949 describes a heap overflow vulnerability in the savestr function of LBNL traceroute version 1.4a5 and earlier, affecting systems running LBL traceroute on SunOS. This flaw allows a local attacker to execute arbitrary commands by leveraging the -g option. With a CVSS score of 7.2 (High), it presents a significant risk due to its local attack vector and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, multiple exploit proofs-of-concept are available on ExploitDB, indicating its exploitability, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4a5CPE matchmatch criteria | cpe:2.3:a:lbl:lbl_traceroute:1.4a5:*:*:*:*:*:*:* | ||
5.5.1CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.