The traceroute program on multiple systems contains a flaw that may allow a malicious user to forge the source address on packets created and sent out by the program. It is possible that the flaw may allow unprivileged users to spoof packets, resulting in a loss of integrity.
Classification
Location:
Local Access Required,
Remote/Network Access Required
Attack Type:
Denial of Service,
Misconfiguration
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Upgrade to NetBSD version 1.3.4 or higher, or the appropriate version from your vendor, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by applying the vendor-supplied patch.