Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-49809

Опубликовано: 04 июл. 2025
Источник: debian
EPSS Низкий

Описание

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mtrunfixedpackage

Примечания

  • In Debian, mtr runs unprivileged and exec-s mtr-packet (or env[MTR_PACKAGE])

  • which has cap_net_raw.

  • Mitigation: if running mtr through sudo (typically MacOSX), requires

  • touching /etc/mtr.is.run.under.sudo to disable ENV[MTR_PACKET] fallback.

  • Fixed by: https://github.com/traviscross/mtr/commit/5226f105f087c29d3cfad9f28000e7536af91ac6

  • Introduced by: https://github.com/traviscross/mtr/commit/fcda9e8b82ca354049fa0ee9cfcb2eaaae623ee0 (v0.88)

  • Negligible security impact on Debian

EPSS

Процентиль: 2%
0.00013
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 1 месяца назад

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

CVSS3: 7.8
redhat
около 1 месяца назад

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

CVSS3: 7.8
nvd
около 1 месяца назад

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

CVSS3: 7.8
msrc
18 дней назад

Описание отсутствует

CVSS3: 7.8
github
около 1 месяца назад

mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.

EPSS

Процентиль: 2%
0.00013
Низкий