Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-98.01.smurf |
Description:
|
This advisory describes the "smurf" IP Denial-of-Service attacks.
| | File Size: | 20994 | | Last Modified: | Sep 14 07:49:52 1999 |
| MD5 Checksum: | 82dc851afe15546c81d35881dbda7839 |
|
| /// File Name: |
CA-98-13-tcp-denial-of-service |
Description:
|
This advisory describes a vulnerability that could allow an intruder crash certain systems based on BSD-derived TCP/IP stacks.
| | File Size: | 8411 | | Last Modified: | Sep 14 07:49:51 1999 |
| MD5 Checksum: | cfd604eed1244fff7b603309a4ef690e |
|
| /// File Name: |
CA-97.28.Teardrop_Land |
Description:
|
This advisory reports on two IP Denial-of-Service attacks.
| | File Size: | 13938 | | Last Modified: | Sep 14 07:49:50 1999 |
| MD5 Checksum: | 83b0888f397aad90538de341288fbd25 |
|
| /// File Name: |
CA-97.27.FTP_bounce |
Description:
|
This advisory discusses the use of the PORT command in the FTP protocol.
| | File Size: | 20831 | | Last Modified: | Sep 14 07:49:49 1999 |
| MD5 Checksum: | 77c719c1b5fb9d32dd994bddd1a4f4b1 |
|
| /// File Name: |
CA-97.26.statd |
Description:
|
This advisory reports a vulnerability that exists in the statd(1M) program, available on a variety of Unix platforms.
| | File Size: | 12745 | | Last Modified: | Sep 14 07:49:48 1999 |
| MD5 Checksum: | 97a8497ec33b2a69a3d4a842a74a45d7 |
|
| /// File Name: |
CA-97.25.CGI_metachar |
Description:
|
This advisory reports a vulnerability that some CGI scripts have a problem that allows an attacker to execute arbitrary commands on a WWW server under the effective user-id of the server process.
| | File Size: | 6304 | | Last Modified: | Sep 14 07:49:47 1999 |
| MD5 Checksum: | b96a7e7a763ec5a4aacce291710b0754 |
|
| /// File Name: |
CA-97.24.Count_cgi |
Description:
|
This advisory describes a buffer overrun vulnerability which exists in the Count.cgi cgi-bin program that allows intruders to force Count.cgi to execute arbitrary commands.
| | File Size: | 9427 | | Last Modified: | Sep 14 07:49:46 1999 |
| MD5 Checksum: | 98f244e9627e522b42d605af0ebd921d |
|
| /// File Name: |
CA-97.23.rdist |
Description:
|
This advisory discusses a buffer overflow problem in rdist. It is a different vulnerability from the one described in CA-96.14.
| | File Size: | 17551 | | Last Modified: | Sep 14 07:49:45 1999 |
| MD5 Checksum: | ea6da4998c1eb28dbce2f119ce602ccb |
|
| /// File Name: |
CA-97.22.bind |
Description:
|
** This advisory supersedes CA-96.02 ** It describes a vulnerability in all versions of BIND before release 4.9.6, suggests several solutions, and provides pointers to the current version of bind.
| | File Size: | 15425 | | Last Modified: | Sep 14 07:49:42 1999 |
| MD5 Checksum: | e5aa2f1ac093fd0fffd1967d02c28331 |
|
| /// File Name: |
CA-97.21.sgi_buffer_overflow |
Description:
|
In this advisory, we describe 6 buffer overflow problems in SGI IRIX systems. Problems affect the df, pset, eject, login/scheme, ordist, and xlock programs. Workarounds and a pointer to a wrapper are provided.
| | File Size: | 22013 | | Last Modified: | Sep 14 07:49:40 1999 |
| MD5 Checksum: | 7a764383c709e75dfc3670d806662769 |
|
| /// File Name: |
CA-97.20.javascript |
Description:
|
This advisory reports a vulnerability in JavaScript that enables remote attackers to monitor a user's Web activities.
| | File Size: | 9372 | | Last Modified: | Sep 14 07:49:39 1999 |
| MD5 Checksum: | aa7121d26f48211407ecd0cafd2547b9 |
|
| /// File Name: |
CA-97.19.bsdlp |
Description:
|
This advisory describes a vulnerability in BSD-based lpr printing software. Vendor information and a pointer to a wrapper are included.
| | File Size: | 10640 | | Last Modified: | Sep 14 07:49:38 1999 |
| MD5 Checksum: | 404732293e68bd9b18964f1e1cd8e95a |
|
| /// File Name: |
CA-97.18.at |
Description:
|
This advisory addresses a buffer overflow condition in some versions of the at(1) program. Patch information and a workaround are provided.
| | File Size: | 13543 | | Last Modified: | Sep 14 07:49:34 1999 |
| MD5 Checksum: | 073629019b6c17c0178bc309d7b0af0d |
|
| /// File Name: |
CA-97.17.sperl |
Description:
|
This advisory addresses a buffer overflow condition in suidperl (sperl) built from Perl 4.n and Perl 5.n distributions on UNIX systems. It suggests several solutions and includes vendor information and a patch for Perl version 5.003.
| | File Size: | 29974 | | Last Modified: | Sep 14 07:49:33 1999 |
| MD5 Checksum: | 3732a2047f3dffef5d118958863c225c |
|
| /// File Name: |
CA-97.16.ftpd |
Description:
|
This advisory describes a vulnerability in some versions of ftpd distributed and installed under various Unix platforms. Includes vendor information.
| | File Size: | 19089 | | Last Modified: | Sep 14 07:49:32 1999 |
| MD5 Checksum: | 0f8dc8f73fd8a2c28042f5d0d722ad93 |
|
| /// File Name: |
CA-97.15.sgi_login |
Description:
|
This advisory describes a vulnerability in the SGI login program when the LOCKOUT parameter is set to a number greater than zero. The vulnerability is present in IRIX 5.3 and 6.2, and perhaps other
| | File Size: | 7746 | | Last Modified: | Sep 14 07:49:29 1999 |
| MD5 Checksum: | 63487ae81515eb2d586277edd64fed61 |
|
| /// File Name: |
CA-97.14.metamail |
Description:
|
This advisory reports a vulnerability in metamail, a package that implements MIME. All versions of metamail through 2.7 are vulnerable.
| | File Size: | 16489 | | Last Modified: | Sep 14 07:49:27 1999 |
| MD5 Checksum: | 5c1d19788a50977d4215a1bdb7660951 |
|
| /// File Name: |
CA-97.13.xlock |
Description:
|
This advisory reports a buffer overflow problem in some versions of xlock. This problem makes it possible for local users to execute arbitrary programs as a privileged user. Patch information and a workaround are included.
| | File Size: | 11188 | | Last Modified: | Sep 14 07:49:26 1999 |
| MD5 Checksum: | 0f0ae0fdc12663da8b6527d6e842aa6e |
|
| /// File Name: |
CA-97.12.webdist |
Description:
|
This advisory reports a vulnerability in the webdist.cgi-bin program, part of the IRIX Mindshare Out Box package, available with IRIX 5.x and 6.x. When exploiting this vulnerability, both local and remote users may be able to execute arbitrary commands with the privileges of the httpd daemon. A workaround is included.
| | File Size: | 10050 | | Last Modified: | Sep 14 07:49:25 1999 |
| MD5 Checksum: | b49eca1d205428b04a7c6e84a8823a02 |
|
| /// File Name: |
CA-97.11.libXt |
Description:
|
This advisory reports a buffer overflow vulnerability in the Xt library of the X Windowing System. Vendor vulnerability and patch information are included.
| | File Size: | 17094 | | Last Modified: | Sep 14 07:49:24 1999 |
| MD5 Checksum: | 3a4279e4f162c827e93903e696e012d1 |
|
| /// File Name: |
CA-97.10.nls |
Description:
|
This advisory reports a buffer overflow condition that affects some libraries using the Natural Language Service (NLS). Vendor vulnerability and patch information are included.
| | File Size: | 11589 | | Last Modified: | Sep 14 07:49:23 1999 |
| MD5 Checksum: | b4a1f10dd458571eabd0262f7ec267f6 |
|
| /// File Name: |
CA-97.09.imap_pop |
Description:
|
This advisory reports a vulnerability in some versions of the Internet Message Access Protocol (IMAP) and Post Office Protocol (POP) implementations (imapd, ipop2d, and ipop3d). Vendor and upgrade information are included.
| | File Size: | 17809 | | Last Modified: | Sep 14 07:49:22 1999 |
| MD5 Checksum: | c1825eb50e5bb3da0be50e9cd69e2e67 |
|
| /// File Name: |
CA-97.08.innd |
Description:
|
Originally issued Topic 2 issued This advisory describes two vulnerabilities in INN (the InterNetNews server). One affects versions 1.5 and earlier; the other affects 1.5.1 and earlier. The advisory includes pointers to version 1.5.1 and earlier. Updated information on the second vulnerability was added as "Topic 2." Pointers to all relevant patches are included, along with information from vendors.
| | File Size: | 18493 | | Last Modified: | Sep 14 07:49:21 1999 |
| MD5 Checksum: | ff117c5bcf14949b0a7b05813a43daee |
|
| /// File Name: |
CA-97.07.nph-test-cgi_script |
Description:
|
This advisory points out a vulnerability in the nph-test-cgi script included with some http daemons. Readers are urged to disable the script. Vendor information is included.
| | File Size: | 10822 | | Last Modified: | Sep 14 07:49:20 1999 |
| MD5 Checksum: | 0c25a7d99a5d9e71a2ee5425339b407f |
|
| /// File Name: |
CA-97.06.rlogin-term |
Description:
|
This advisory reports a vulnerability in many implementations of the rlogin program, including eklogin and klogin. Vendor information and a workaround are included.
| | File Size: | 18465 | | Last Modified: | Sep 14 07:49:19 1999 |
| MD5 Checksum: | 78fd56082966061112a5ce4576d73a43 |
|
|
|
|
|