Logo
vulnerabilityCVE-2025-49809
Name
CVE-2025-49809
Source
NVD ( link)Debian ( link)
Description
mtr through 0.95, in certain privileged contexts, mishandles execution of a program specified by the MTR_PACKET environment variable. NOTE: mtr on macOS may often have Sudo rules, as an indirect consequence of Homebrew not installing setuid binaries.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
mtr
Patched

Vulnerability Ratings#


7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
0.95-r3
Not Affected
openwrt
openwrt-25.12
0.95-r3
Not Affected
yocto
kirkstone
0.95
Patched
yocto
master
0.96
Not Affected

Resolved with patches#


mtr (yocto:kirkstone)

#
Title
Author
Resolve
1
Added protection against use of MTR_PACKET under special
"R.E. Wolff" <R.E.Wolff@BitWizard.nl>
CVE-2025-49809

mtr (yocto:scarthgap)

#
Title
Author
Resolve
1
Added protection against use of MTR_PACKET under special
"R.E. Wolff" <R.E.Wolff@BitWizard.nl>
CVE-2025-49809