PT-2026-57151 · Mtr · Mtr
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
mtr versions prior to 0.97
Description
An out-of-bound read exists in the
ipinfo lookup() function. An attacker capable of influencing the TXT response used for AS lookups can trigger a reliable crash by providing a DNS response larger than 512 bytes containing a crafted compression pointer in the answer NAME field. This occurs because the ipinfo lookup() function incorrectly uses the response length as the end-of-message boundary for the dn expand() function.Recommendations
Update mtr to a version containing the fix implemented in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.
As a temporary mitigation, restrict the use of the
ipinfo lookup() function or disable AS lookups.Exploit
Fix
DoS
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mtr