CVE-2003-0489 affects tcptraceroute versions 1.4 and earlier, where the software fails to fully relinquish privileges after acquiring a packet capture file descriptor. This oversight could allow local users to gain unauthorized access to this descriptor through a separate vulnerability within tcptraceroute. With a CVSS score of 7.2, this vulnerability is considered highly severe, enabling local attackers to achieve complete confidentiality, integrity, and availability compromise with low attack complexity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, indicating awareness despite a lack of media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4CPE matchmatch criteria | cpe:2.3:a:michael_c._toren:tcptraceroute:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.