traceroute in NetBSD 1.3.3 and Linux systems allows local users to flood other systems by providing traceroute with a large waittime (-w) option, which is not parsed properly and sets the time delay for sending packets to zero.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=91893782027835&w=2 | mailing list |
http://www.osvdb.org/7574 | vdb entry |
ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-004.txt.asc | patch vendor advisory |