RedHat traceroute root exploit

Some folks have discovered a security problem with traceroute. The issue is that traceroute is a setuid program and can be made to crash by supplying certain options (multiple -g.) If this happens, which it does, it is feasible for an exploit to then be used in the suid process to gain root access.

The users whom discovered it announced it, redHat has made a patch available and AGAIN, open source is FAR MORE secure than closed proprietary oh-there-isnt-a-bug-that-we-know-of crap.

Get the update via the links.   RedHat traceroute root exploit: securityFocus