CVE-2023-46316Failure to Handle Missing Parameter in Traceroute

Severity
5.5MEDIUMNVD
EPSS
0.0%
top 88.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 25
Latest updateNov 14

Description

In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not properly parse command lines.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

NVDbuc/traceroute2.0.122.1.3
debiandebian/traceroute< traceroute 1:2.1.3-1 (forky)
Debiantraceroute_project/traceroute< 1:2.1.3-1+1

Also affects: Debian Linux 10.0, 11.0, 12.0

🔴Vulnerability Details

2
OSV
CVE-2023-46316: In buc Traceroute 22023-10-25
GHSA
GHSA-x3vv-qh4r-crf2: In buc Traceroute 22023-10-25

📋Vendor Advisories

4
Ubuntu
Traceroute vulnerability2023-11-14
Red Hat
traceroute: improper command line parsing2023-10-25
Microsoft
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3 the wrapper scripts do not properly parse command lines.2023-10-10
Debian
CVE-2023-46316: traceroute - In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3, the wrapper scripts do not ...2023

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft November 2023 Patch Tuesday fixes 5 zero-days, 58 flaws2023-11-14