vendor:
Scotty
by:
Larry W. Cashdollar
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Scotty
Affected Version From: Scotty 2.1.9
Affected Version To: Scotty 2.1.9
Patch Exists: YES
Related CWE: N/A
CPE: a:scotty:scotty
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2001
Buffer Overflow in ntping
ntping is a component of scotty, a Tcl interpreter used to retrieve status and configuration information for TCP/IP networks. The utility, which runs with root privileges, contains a locally exploitable buffer overflow vulnerability. A local attacker can supply a long string as a command line argument to ntping, which, if the argument is of sufficient length (approximately 9000 characters) will induce a segfault. If the input is carefully constructed, a local attacker can exploit this vulnerability to execute arbitrary code on the target host.
Mitigation:
Upgrade to the latest version of ntping