Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-93:14.Internet.Security.Scanner |
Description:
|
This advisory alerts Internet sites to a new software tool that is widely available. The advisory describes vulnerabilities probed by the Internet Security Scanner (ISS) software.
| | File Size: | 16137 | | Last Modified: | Sep 14 07:47:36 1999 |
| MD5 Checksum: | 93adaffbce00482e7dcdc9c555938107 |
|
| /// File Name: |
CA-93:15.SunOS.and.Solaris.vulnerab..> |
Description:
|
This advisory describes several vulnerabilities in Sun operating systems: /usr/lib/sendmail (SunOS 4.1.x, Solaris 2.x), /bin/tar (Solaris 2.x), and dev/audio (SunOS 4.1.x, Solaris 2.x). The advisory includes patch and workaround information for these problems. * The sendmail portion of this advisory is superseded by CA-96.20, CA-96.24, and CA-96.25. *
| | File Size: | 8990 | | Last Modified: | Sep 14 07:47:37 1999 |
| MD5 Checksum: | 6667c72dc7c76eaaa77efd3bc25a45cb |
|
| /// File Name: |
CA-93:17.xterm.logging.vulnerabilit..> |
Description:
|
This advisory addresses a vulnerability in the logging function of many versions of xterm. It provides information about several solutions.
| | File Size: | 9694 | | Last Modified: | Sep 14 07:47:38 1999 |
| MD5 Checksum: | 226def934ddb93ece550cb6d23c80cde |
|
| /// File Name: |
CA-93:18.SunOS.Solbourne.loadmodule..> |
Description:
|
** This advisory supersedes CA-91:22. ** The advisory addresses a vulnerability in /usr/etc/modload and $OPENWINHOME/bin/loadmodule in in Sun Microsystems, Inc. SunOS 4.1.1, 4.1.2, 4.1.3, and 4.1.3c and OpenWindows 3.0 on all sun4 and Solbourne Computer, Inc. architectures.
| | File Size: | 4269 | | Last Modified: | Sep 14 07:47:38 1999 |
| MD5 Checksum: | 9cfc9a67ab1ba34854fadc4f6c52bef1 |
|
| /// File Name: |
CA-93:19.Solaris.Startup.vulnerabil..> |
Description:
|
Information about a vulnerability in the system startup scripts on Solaris 2.x and Solaris x86 systems.
| | File Size: | 3637 | | Last Modified: | Sep 14 07:47:39 1999 |
| MD5 Checksum: | 981b2e945dac996d775ce8c2bd61066f |
|
| /// File Name: |
CA-94:01.ongoing.network.monitoring..> |
Description:
|
This advisory describes ongoing network monitoring attacks. All systems that offer remote access through rlogin, telnet, and ftp are at risk. The advisory includes a description of the activity and suggested approaches for addressing the problem.
| | File Size: | 27549 | | Last Modified: | Sep 14 07:47:46 1999 |
| MD5 Checksum: | 9cc5fcb2a1cf7e700a3b19bb1d2d0116 |
|
| /// File Name: |
CA-94:02.REVISED.SunOS.rpc.mountd.v..> |
Description:
|
** This advisory supersedes CA-91:09 and CA-92:12.** A vulnerability is present in SunOS 4.1, 4.1.1, 4.1.2, and 4.1.3 /usr/etc/rpc.mountd. Unauthorized remote hosts will be able to mount the file system. The advisory describes how to obtain a patch for the problem from Sun.
| | File Size: | 4438 | | Last Modified: | Sep 14 07:47:48 1999 |
| MD5 Checksum: | 862a2fbfd61c0d93ab1bd4bbe2e714d7 |
|
| /// File Name: |
CA-94:03.AIX.performance.tools |
Description:
|
Vulnerabilities are present in the bosext1.extcmds.obj performance tools in AIX 3.2.5 and in those AIX 3.2.4 systems with Program Temporary Fixes (PTFs) U420020 or U422510 installed. These problems do not exist in earlier versions of AIX.
| | File Size: | 4211 | | Last Modified: | Sep 14 07:47:49 1999 |
| MD5 Checksum: | 7f60181a7324819de628de8c56a850ab |
|
| /// File Name: |
CA-94:05.MD5.checksums |
Description:
|
This advisory gives the MD5 checksums for a number of SunOS files, along with a tool for checking them.
| | File Size: | 31053 | | Last Modified: | Sep 14 07:47:52 1999 |
| MD5 Checksum: | e08dc59003396e03c0fe06967fb23ce4 |
|
| /// File Name: |
CA-94:06.utmp.vulnerability |
Description:
|
This advisory addresses a vulnerability with /etc/utmp ins SunOS 4.1.X and Solaris 1.1.1 operating systems. Solbourne Computer, Inc. and other Sparc products using SunOS 4.1.X or Solaris 1.1.1 are also affected. Solaris 2.x is not affected by this problem.
| | File Size: | 7029 | | Last Modified: | Sep 14 07:47:53 1999 |
| MD5 Checksum: | 74063161402f72e8645cf34aa177c4c7 |
|
| /// File Name: |
CA-94:07.wuarchive.ftpd.trojan.hors..> |
Description:
|
Warning about intruder-modified source for wuarchive ftpd, which introduced a Trojan horse in versions 2.2, 2.1f, and possibly earlier versions. Recommended solution is to upgrade to version 2.3.
| | File Size: | 6474 | | Last Modified: | Sep 14 07:47:54 1999 |
| MD5 Checksum: | cf5082e1f02dfc21bc0e460cec46b71f |
|
| /// File Name: |
CA-94:08.ftpd.vulnerabilities |
Description:
|
This advisory addresses two vulnerabilities with some releases of fptd and announces new versions and patches to correct these problems. ftpd versions affected are wuarchive ftpd 2.0-2.3, DECWRL ftpd versions prior to 5.93, and BSDI ftpd version 1.1 prior to patch level 5. The vulnerabilities addressed are the SITE EXEC and race condition vulnerabilities.
| | File Size: | 7149 | | Last Modified: | Sep 14 07:47:55 1999 |
| MD5 Checksum: | 33810eadf967db905b4754684b618c37 |
|
| /// File Name: |
CA-94:09.bin.login.vulnerability |
Description:
|
This advisory addresses a vulnerability in /bin/login of all IBM AIX 3 systems, and Linux systems. A workaround and patch information are included in this advisory.
| | File Size: | 12011 | | Last Modified: | Sep 14 07:47:56 1999 |
| MD5 Checksum: | 929e2c044c9fb32eb0e6296e9cc9716c |
|
| /// File Name: |
CA-94:10.IBM.AIX.bsh.vulnerability |
Description:
|
This advisory addresses a vulnerability in the batch queue (bsh) of IBM AIX systems running versions prior to and including AIX 3.2. CERT staff recommends a workaround to disable the bsh feature. IBM provides a patch for systems requiring this functionality.
| | File Size: | 5794 | | Last Modified: | Sep 14 07:47:57 1999 |
| MD5 Checksum: | b6ff572418b9c56de1265d4ff5e6a99c |
|
| /// File Name: |
CA-94:11.majordomo.vulnerabilities |
Description:
|
This advisory addresses two vulnerabilities in Majordomo versions prior to 1.92. CERT staff recommends installing version 1.92, but provides workarounds if this is not possible.
| | File Size: | 6086 | | Last Modified: | Sep 14 07:47:58 1999 |
| MD5 Checksum: | 268f9bdf8ec9232f8693bfe21e53693d |
|
| /// File Name: |
CA-94:13.SGI.IRIX.Help.Vulnerabilit..> |
Description:
|
This advisory addresses a vulnerability in the Silicon Graphics, Inc. IRIX 5.x Help system. SGI recommends installing the patch, but has provided a workaround to disable the Help system if this is not possible.
| | File Size: | 8291 | | Last Modified: | Sep 14 07:47:59 1999 |
| MD5 Checksum: | 75bcdf7781e63e31396705ab8db1b2cc |
|
| /// File Name: |
CA-94:14.trojan.horse.in.IRC.client..> |
Description:
|
This advisory discusses a Trojan horse that was found in version 2.2.9 or ircII, the source code for the Internet Relay Chat (IRC) client for UNIX systems. For reasons described in the advisory, the CERT staff urges everyone to install ircII version 2.6.
| | File Size: | 7438 | | Last Modified: | Sep 14 07:48:00 1999 |
| MD5 Checksum: | 3ad62e3a6874eb3be1be2d0befdd860e |
|
| /// File Name: |
CA-94:15.NFS.Vulnerabilities |
Description:
|
This advisory describes security measures to guard against several vulnerabilities in the Network File System (NFS). The advisory was prompted by an increase in root compromises by intruders using tools to exploit the vulnerabilities.
| | File Size: | 7193 | | Last Modified: | Sep 14 07:48:03 1999 |
| MD5 Checksum: | 33d07304d57dcf3bc7c2dca5ee4cc7d3 |
|
| /// File Name: |
CA-95:01.IP.spoofing.attacks.and.hi..> |
Description:
|
The IP spoofing portion of this advisory has been superseded by CA-96.21. The description of the intruder activity of hijacking terminals is still current.
| | File Size: | 26137 | | Last Modified: | Sep 14 07:48:07 1999 |
| MD5 Checksum: | 3a95cb7ae1968a12be491dad55d5ed35 |
|
| /// File Name: |
CA-95:02.binmail.vulnerabilities |
Description:
|
** This advisory supersedes CA-91:01a and CA-91:13. ** It addresses vulnerabilities in some versions of /bin/mail based on BSD 4.3 UNIX. It includes a list of vendor patches and source code for mail.local.c, an alternative to /bin/mail.
| | File Size: | 10040 | | Last Modified: | Sep 14 07:48:08 1999 |
| MD5 Checksum: | 43436de334513164d7545cf804ca6a7d |
|
| /// File Name: |
CA-95:03a.telnet.encryption.vulnera..> |
Description:
|
** This advisory supersedes CA-95:03. ** Description and patch information for a security problem in the Berkeley Telnet clients that support encryption and Kerberos V4 authentication. It provides additional information.
| | File Size: | 14466 | | Last Modified: | Sep 14 07:48:09 1999 |
| MD5 Checksum: | ac934c64565e33ccc82a2d351435ebbf |
|
| /// File Name: |
CA-95:04.NCSA.http.daemon.for.unix...> |
Description:
|
This advisory provides a patch for a vulnerability in the NCSA HTTP daemon version 1.3 for UNIX.
| | File Size: | 9115 | | Last Modified: | Sep 14 07:48:11 1999 |
| MD5 Checksum: | 6cd59d212c56dc98952a95b2ac8c8836 |
|
| /// File Name: |
CA-95:06.satan |
Description:
|
An overview of the Security Administrator Tool for Analyzing Networks (SATAN) based on the CERT staff's review of beta version 0.51. Includes list of vulnerabilities probed and advice on securing systems.
| | File Size: | 16156 | | Last Modified: | Sep 14 07:48:12 1999 |
| MD5 Checksum: | 1bb58a38e81fa46cce5931a7388bfd6f |
|
| /// File Name: |
CA-95:07a.REVISED.satan.vul |
Description:
|
** This advisory replaces CA-95:07.** It is a revision that provides new information the problem described in CA-95:07, and includes precautions to take when running SATAN. A tutorial by the SATAN authors, "SATAN Password Disclosure" is appended to the advisory.
| | File Size: | 14979 | | Last Modified: | Sep 14 07:48:13 1999 |
| MD5 Checksum: | c3b643701b8842ae4102585860474562 |
|
| /// File Name: |
CA-95:08.sendmail.v.5.vulnerability |
Description:
|
This advisory describes a vulnerability in sendmail v.5, which is still in use and which includes IDA sendmail. Many vendors have previously fixed the problem, others recently developed patches.
| | File Size: | 22747 | | Last Modified: | Sep 14 07:48:27 1999 |
| MD5 Checksum: | eee46950dd25557fa0dcd27fa9da33da |
|
|
|
|
|