Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-2000-10.ie |
Description:
|
CERT Advisory CA-2000-10 - Several flaws exist in Microsoft Internet Explorer that could allow an attacker to masquerade as a legitimate web site if the attacker can compromise the validity of certain DNS information. These problems are different from the problems reported in CERT Advisory CA-2000-05 and CERT Advisory CA-2000-08, but they have a similar impact.
| | Homepage: | http://www.cert.org | | File Size: | 10038 | | Last Modified: | Jun 6 23:30:05 2000 |
| MD5 Checksum: | 998d54720cafa23578e89d1b913a1445 |
|
| /// File Name: |
CA-96.18.fm_fls |
Description:
|
This advisory reports a configuration problem in the floating license server for Adobe FrameMaker (fm_fls). A workaround is provided.
| | File Size: | 9965 | | Last Modified: | Sep 14 07:49:01 1999 |
| MD5 Checksum: | b88e8b0a42f47e99afbdba8f0ed591b0 |
|
| /// File Name: |
CA-98.04.Win32.WebServers |
Description:
|
This advisory reports an exploitation involving long file names on Microsoft Windows-based web servers.
| | File Size: | 9953 | | Last Modified: | Sep 14 07:49:55 1999 |
| MD5 Checksum: | 0aa7dd05cd0ead8602b4bb3bdbe59213 |
|
| /// File Name: |
CA-89:04.decnet.wank.worm |
Description:
|
Warning about the "WANK" worm which attacked DECnet hosts.
| | File Size: | 9931 | | Last Modified: | Sep 14 07:46:22 1999 |
| MD5 Checksum: | 519ff2f53903f7f35624042e69183724 |
|
| /// File Name: |
CA-98.12.mountd |
Description:
|
This advisory reports a Remotely Exploitable Buffer Overflow Vulnerability in mountd.
| | File Size: | 9911 | | Last Modified: | Sep 14 07:50:05 1999 |
| MD5 Checksum: | 2f533783ca44e0e1844b9d113274ebd6 |
|
| /// File Name: |
CA-2003-11.lotus.domino |
Description:
|
CERT Advisory CA-2003-11 - Multiple vulnerabilities have been reported to affect Lotus Notes clients and Domino servers v5.0.12 through 6.0.1 including six exploitable buffer overflows. TCP port 1352 is a likely conduit for attack, however Lotus Notes often listens to Netbios, SPX, or XPC ports.
| | Homepage: | http://www.cert.org | | File Size: | 9867 | | Last Modified: | Mar 27 09:29:44 2003 |
| MD5 Checksum: | faf6d46160e65b496113291bafcb82ee |
|
| /// File Name: |
CA-93:17.xterm.logging.vulnerabilit..> |
Description:
|
This advisory addresses a vulnerability in the logging function of many versions of xterm. It provides information about several solutions.
| | File Size: | 9694 | | Last Modified: | Sep 14 07:47:38 1999 |
| MD5 Checksum: | 226def934ddb93ece550cb6d23c80cde |
|
| /// File Name: |
CA-2002-04.ie-overflow |
Description:
|
CERT Advisory CA-2002-04 - Microsoft Internet Explorer contains a buffer overflow vulnerability in its handling of embedded objects in HTML documents. This vulnerability allows attackers to execute arbitrary code on the victim's system when the victim visits a web page or views an HTML email message. This bug was discussed in MS02-005.
| | Homepage: | http://www.cert.org | | File Size: | 9677 | | Related CVE(s): | CAN-2002-0022 | | Last Modified: | Feb 26 07:41:47 2002 |
| MD5 Checksum: | 86fd6e68bbf8b3c6283cb00313852ed7 |
|
| /// File Name: |
CA-98.06.nisd |
Description:
|
This advisory reports a vulnerability that exists in some implementations of NIS+.
| | File Size: | 9618 | | Last Modified: | Sep 14 07:49:57 1999 |
| MD5 Checksum: | a92df3eed98eff13f251d62b7fd38df8 |
|
| /// File Name: |
CA-2003-13.snort |
Description:
|
CERT Advisory CA-2003-13 - Two remote vulnerabilities in the Snort IDS, versions 1.8 through 2.0 RC allow remote execution of code as root. It is not necessary for the attacker to know the IP address of the Snort device they wish to attack; merely sending malicious traffic where it can be observed by an affected Snort sensor is sufficient to exploit these vulnerabilities. Fix available here.
| | Homepage: | http://www.cert.org | | File Size: | 9583 | | Last Modified: | Apr 18 10:06:53 2003 |
| MD5 Checksum: | 30fa60b771ff2e6ee35376d17f2619f4 |
|
| /// File Name: |
CA-2002-16.yahoo |
Description:
|
CERT Advisory CA-2002-16 - Yahoo! Messenger version 5,0,0,1064 and prior for Microsoft Windows contain multiple vulnerabilities which can be exploited to execute arbitrary code with the privileges of the victim user.
| | Homepage: | http://www.cert.org | | File Size: | 9549 | | Last Modified: | Jun 6 05:03:45 2002 |
| MD5 Checksum: | 01b983276b9dab2470d4c32241d73f0d |
|
| /// File Name: |
CA-2000-15.netscape |
Description:
|
CERT Advisory CA-2000-15 - Systems running Netscape Communicator version 4.04 through 4.74 with Java enabled ship with Java classes that allow an unsigned Java applet to access local and remote resources in violation of the security policies for applets.
| | Homepage: | http://www.cert.org | | File Size: | 9477 | | Last Modified: | Aug 11 03:29:12 2000 |
| MD5 Checksum: | a3ff2b199bbc69101c3f98c4bc81dcf7 |
|
| /// File Name: |
CA-2002-02.aol.icq |
Description:
|
There is a remotely exploitable buffer overflow in ICQ v2001A and below. Attackers that are able to exploit the vulnerability can execute arbitrary code with the privileges of the victim user. There are 122 million vulnerable clients. Full details are discussed in VU#570167. An exploit is known to exist. Voice Video & Games plugin installed with AOL Mirabilis ICQ Versions 2001B Beta v5.18 Build #3659 and prior is also vulnerable.
| | Homepage: | http://www.cert.org | | File Size: | 9471 | | Last Modified: | Jan 25 08:27:22 2002 |
| MD5 Checksum: | c8d272590ca4613ec1a4cac1ae2b3505 |
|
| /// File Name: |
CA-2002-28.sendmail |
Description:
|
CERT Advisory CA-2002-28 - Sendmail 8.12.6 was backdoored on September 28, 2002 to include a trojan which executes commands via outbound port 6667 connections.
| | Homepage: | http://www.cert.org | | File Size: | 9461 | | Last Modified: | Oct 10 02:21:03 2002 |
| MD5 Checksum: | f6a94b46de29c16173327843a102489e |
|
| /// File Name: |
CA-2003-12.sendmail |
Description:
|
CERT Advisory CA-2003-12 - A remote stack overflow in Sendmail 8.12.8 and below was discovered by Michal Zalewski which allows remote code execution as root. This bug is in the prescan code and is different than the recent sendmail bug described in CA-2003-07. Patch available here.
| | Homepage: | http://www.cert.org | | File Size: | 9454 | | Related CVE(s): | CAN-2003-0161 | | Last Modified: | Apr 1 07:51:51 2003 |
| MD5 Checksum: | 5f9042c50705af2bf508c8b6bf27dc38 |
|
| /// File Name: |
CA-98.03.ssh-agent |
Description:
|
This advisory details a vulnerability in the SSH cryptographic login program.
| | File Size: | 9443 | | Last Modified: | Sep 14 07:49:54 1999 |
| MD5 Checksum: | 6b3143145ff1041b361970afa096837d |
|
| /// File Name: |
CA-97.24.Count_cgi |
Description:
|
This advisory describes a buffer overrun vulnerability which exists in the Count.cgi cgi-bin program that allows intruders to force Count.cgi to execute arbitrary commands.
| | File Size: | 9427 | | Last Modified: | Sep 14 07:49:46 1999 |
| MD5 Checksum: | 98f244e9627e522b42d605af0ebd921d |
|
| /// File Name: |
CA-97.20.javascript |
Description:
|
This advisory reports a vulnerability in JavaScript that enables remote attackers to monitor a user's Web activities.
| | File Size: | 9372 | | Last Modified: | Sep 14 07:49:39 1999 |
| MD5 Checksum: | aa7121d26f48211407ecd0cafd2547b9 |
|
| /// File Name: |
CA-2000-11.kerberos |
Description:
|
CERT Advisory CA-2000-11 - MIT Kerberos vulnerable to denial-of-service attacks. Several new buffer overflow vulnerabilities were found in Kerberos 4, Kerberos 5 with v4 support, KerbNet, and Cygnus Kerberos. Due to the use of static buffers, these vulnerabilities do not allow remote execution of arbitrary code.
| | Homepage: | http://www.cert.org | | File Size: | 9355 | | Last Modified: | Jun 12 18:07:45 2000 |
| MD5 Checksum: | 1e504f377be057c78ce8d432d3fced78 |
|
| /// File Name: |
CA-96.17.Solaris_vold_vul |
Description:
|
This advisory describes a vulnerability in the Solaris volume management daemon (vold) and gives a workaround.
| | File Size: | 9354 | | Last Modified: | Sep 14 07:49:00 1999 |
| MD5 Checksum: | 9867aa2570e793509ee624c76443b7cd |
|
| /// File Name: |
CA-2000-01.distributed |
Description:
|
CERT Advisory CA-2000-01 - Denial-of-Service Developments. A distributed denial-of-service tool called "Stacheldraht" has been discovered on multiple compromised hosts at several organizations. X-Force released a paper on trin00 and TFN. CERT DoS homepage here.
| | File Size: | 9319 | | Last Modified: | Jan 4 09:19:35 2000 |
| MD5 Checksum: | da7ed5f5bf820da50da365eabdaecace |
|
| /// File Name: |
CA-96.07.java_bytecode_verifier |
Description:
|
This advisory describes a vulnerability in the Java bytecode verifier portion of Sun Microsystems' Java Development Kit (JDK) 1.0 and 1.0.1. Workarounds are provided for this product and Netscape Navigator 2.0 and 2.01, which have the JDK built in.
| | File Size: | 9300 | | Last Modified: | Sep 14 07:48:47 1999 |
| MD5 Checksum: | 605c3f42617f758bbfadf017b380aa54 |
|
| /// File Name: |
CA-2002-17.apache |
Description:
|
CERT Advisory CA-2002-17 - Apache v1.3.24 and 2.0.36 and below contains a remotely exploitable vulnerability in chunk encoded data support that is present by default. Remote code execution is possible on some platforms, denial of service attacks are possible against others. Fix available here.
| | Homepage: | http://www.cert.org | | File Size: | 9259 | | Last Modified: | Jun 19 07:49:30 2002 |
| MD5 Checksum: | 33aac8d5526df98677412567f1f82ac3 |
|
| /// File Name: |
CA-2000-22.lprng |
Description:
|
CERT Advisory CA-2000-22 - Input Validation Problems in LPRng. A popular replacement software package to the BSD lpd printing service called LPRng contains at least one format string vulnerability in the syslog() function, which allows remote users with access to TCP port 515 to execute arbitrary code on vulnerable systems as root. Fix available here.
| | Homepage: | http://www.cert.org | | File Size: | 9251 | | Last Modified: | Dec 15 04:09:32 2000 |
| MD5 Checksum: | f66eaa57326f7eec805db9c183469a6f |
|
| /// File Name: |
CA-2002-12-ISC-DHCP |
Description:
|
CERT Advisory CA-2002-12 - A format string vulnerability in ISC DHCP 3 to 3.0.1rc8 can be used to remotely execute code through this application. Because ISC DHCP runs with root privileges, exploitation of this vulnerability can lead to a root compromise.
| | Homepage: | http://www.cert.org | | File Size: | 9193 | | Last Modified: | May 10 07:44:11 2002 |
| MD5 Checksum: | 95cc636e9bbdd703e6ba5a6658603d96 |
|
|
|
|
|