Back
CVE-2003-0489
tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor for capturing packets, which may allow local users to gain access to the descriptor via a separate vulnerability in tcptraceroute.
Published: Aug 7, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| michael_c._toren | tcptraceroute | * |
GitHub Security Advisory GHSA-6xvj-44vj-vq8r
tcptraceroute 1.4 and earlier does not fully drop privileges after obtaining a file descriptor...
References (2)
- http://www.debian.org/security/2003/dsa-330 Patch, Vendor Advisory
- http://www.debian.org/security/2003/dsa-330 Patch, Vendor Advisory
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
0.41%
Top 66% most likely to be exploited
Threat Score
28.9 / 100
Data Sources
NVD
EPSS
GitHub