Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CS-2002-02 |
Description:
|
Unavailable.
| | File Size: | 9187 | | Last Modified: | May 29 08:32:14 2002 |
| MD5 Checksum: | a4128a42b18994cc6abd8c451be8bde4 |
|
| /// File Name: |
CA-98.08.qpopper_vul |
Description:
|
This advisory reports buffer overflow vulnerabilities in some Post Office Protocol (POP) servers.
| | File Size: | 9175 | | Last Modified: | Sep 14 07:50:01 1999 |
| MD5 Checksum: | 1fbfae4c74045aa4ce89a054e8cd96a8 |
|
| /// File Name: |
CA-92:18.VMS.Monitor.vulnerability...> |
Description:
|
** This advisory supersedes CA-92:16. ** It provides additional information concerning availability of remedial image kits to correct a vulnerability present in the Monitor utility in VMS V5.0 through V5.4-2. The vulnerability has been corrected in V5.4-3 through V5.5-1.
| | File Size: | 9149 | | Last Modified: | Sep 14 07:47:11 1999 |
| MD5 Checksum: | d080ba518701f588a86ecb778a05f11a |
|
| /// File Name: |
CA-95:04.NCSA.http.daemon.for.unix...> |
Description:
|
This advisory provides a patch for a vulnerability in the NCSA HTTP daemon version 1.3 for UNIX.
| | File Size: | 9115 | | Last Modified: | Sep 14 07:48:11 1999 |
| MD5 Checksum: | 6cd59d212c56dc98952a95b2ac8c8836 |
|
| /// File Name: |
CA-2001-11.iisworm |
Description:
|
Cert Advisory CA-2001-11 - A worm which uses the sadmind overflow and the IIS unicode bug is propagating on the internet. Solaris systems compromised by this worm are being used to scan and compromise other Solaris and IIS systems. IIS systems compromised by this worm can suffer modified web content.
| | Homepage: | http://www.cert.org | | File Size: | 9061 | | Last Modified: | May 9 01:02:16 2001 |
| MD5 Checksum: | e570ec4ca2764bfc26430d8e5f738e9f |
|
| /// File Name: |
CA-93:15.SunOS.and.Solaris.vulnerab..> |
Description:
|
This advisory describes several vulnerabilities in Sun operating systems: /usr/lib/sendmail (SunOS 4.1.x, Solaris 2.x), /bin/tar (Solaris 2.x), and dev/audio (SunOS 4.1.x, Solaris 2.x). The advisory includes patch and workaround information for these problems. * The sendmail portion of this advisory is superseded by CA-96.20, CA-96.24, and CA-96.25. *
| | File Size: | 8990 | | Last Modified: | Sep 14 07:47:37 1999 |
| MD5 Checksum: | 6667c72dc7c76eaaa77efd3bc25a45cb |
|
| /// File Name: |
CA-2001-07.ftp.glob |
Description:
|
CERT Advisory CA-2001-07 - Many FTP servers have remote vulnerabilities in filename expansion due to the glob() function which allow arbitrary code execution. Vulnerable FTP servers include OpenBSD, NetBSD, FreeBSD, Irix, HPUX 11, and Solaris 8.
| | Homepage: | http://www.cert.org | | File Size: | 8975 | | Last Modified: | Apr 10 22:25:35 2001 |
| MD5 Checksum: | affce6442bd731ae8d4c7a694b8c8c00 |
|
| /// File Name: |
CA-2001-06.mime.execute |
Description:
|
CERT Advisory CA-2001-06 - All versions of Microsoft Internet Explorer 5.5 SP1 or earlier and any software which utilizes vulnerable versions of Internet Explorer to render HTML allows an intruder to construct malicious content that, when viewed in Internet Explorer (or any program that uses the IE HTML rendering engine), can execute arbitrary code.
| | Homepage: | http://www.cert.org | | File Size: | 8873 | | Last Modified: | Apr 10 04:24:56 2001 |
| MD5 Checksum: | 401206084c421cb5b0974756de5668d2 |
|
| /// File Name: |
CA-2002-30.trojan |
Description:
|
CERT Advisory CA-2002-30 - Released source code distributions of the libpcap and tcpdump packages were modified by an intruder and contain a trojan horse which, upon compile time, remote grabs a file from a fixed IP address which it then compiles and runs. The binary then goes to a fixed IP address and gets a one character response which enables the remote machine to trigger the spawning of a shell to the remote machine. The backdoor also explicitly ignores all traffic on port 1963.
| | Homepage: | http://www.cert.org/ | | File Size: | 8715 | | Last Modified: | Nov 15 09:02:19 2002 |
| MD5 Checksum: | e54c4be958885a0de93635a5937a757f |
|
| /// File Name: |
CA-90:02.intruder.warning |
Description:
|
Warning about a series of attacks on Internet systems. Includes a list of 14 points to check on Unix and VMS systems. The points cover possible signs of a break-in as well as possible system configuration vulnerabilities.
| | File Size: | 8691 | | Last Modified: | Sep 14 07:46:25 1999 |
| MD5 Checksum: | ba4bd611e6e3473307178c2fa9f05030 |
|
| /// File Name: |
CA-96.01.UDP_service_denial |
Description:
|
This advisory describes UDP port denial-of-service attacks, for which an exploitation script has been publicly posted. The advisory includes a workaround.
| | File Size: | 8660 | | Last Modified: | Sep 14 07:48:42 1999 |
| MD5 Checksum: | 84d727d432dec2f3eea22b7cd940b707 |
|
| /// File Name: |
CA-2003-05.oracle |
Description:
|
CERT Advisory CA-2003-05 - Systems running Oracle8 Database v 8.0.6, 8.1.7, Oracle9i Database (Release 1 and 2), and Oracle9i Application Server (Release 9.0.2 and 9.0.3) contain multiple remote vulnerabilities which can lead to the execution of arbitrary code, allow users to modify database records, or cause a denial of service, breaking the database.
| | Homepage: | http://www.cert.org | | File Size: | 8514 | | Last Modified: | Feb 20 10:20:39 2003 |
| MD5 Checksum: | 22a4447df0df965497ab612a64c1a15a |
|
| /// File Name: |
CA-90:06a.NeXT.vulnerability |
Description:
|
Describes several vulnerabilities in NeXT system software. The advisory was originally issued as 90:06; 90:06a includes several corrections.
| | File Size: | 8481 | | Last Modified: | Sep 14 07:46:40 1999 |
| MD5 Checksum: | 49bd246bb2fdaf35822775d30d1fd897 |
|
| /// File Name: |
CA-2001.interbase |
Description:
|
CERT Advisory CA-2001-01 - Interbase is an open source database package that had previously been distributed in a closed source fashion by Borland/Inprise. Both the open and closed source versions of the Interbase server contain a compiled-in back door account with a known password which allows any local or remote user able to access port 3050/tcp [gds_db] to manipulate any database object and run arbitrary code on the system.
| | Homepage: | http://www.cert.org | | File Size: | 8473 | | Last Modified: | Jan 13 01:29:09 2001 |
| MD5 Checksum: | 4ccfa403993e47c8ebf067e978169831 |
|
| /// File Name: |
CA-98-13-tcp-denial-of-service |
Description:
|
This advisory describes a vulnerability that could allow an intruder crash certain systems based on BSD-derived TCP/IP stacks.
| | File Size: | 8411 | | Last Modified: | Sep 14 07:49:51 1999 |
| MD5 Checksum: | cfd604eed1244fff7b603309a4ef690e |
|
| /// File Name: |
CS-2002-03 |
Description:
|
Unavailable.
| | File Size: | 8327 | | Last Modified: | Sep 1 00:51:08 2002 |
| MD5 Checksum: | cdd88fe75408ba5c8faaa0769102f8bc |
|
| /// File Name: |
CA-94:13.SGI.IRIX.Help.Vulnerabilit..> |
Description:
|
This advisory addresses a vulnerability in the Silicon Graphics, Inc. IRIX 5.x Help system. SGI recommends installing the patch, but has provided a workaround to disable the Help system if this is not possible.
| | File Size: | 8291 | | Last Modified: | Sep 14 07:47:59 1999 |
| MD5 Checksum: | 75bcdf7781e63e31396705ab8db1b2cc |
|
| /// File Name: |
CA-96.23.workman_vul |
Description:
|
This advisory describes a vulnerability in the WorkMan compact disc-playing program that affects UNIX System V Release 4.0 and derivatives and Linux systems.
| | File Size: | 8274 | | Last Modified: | Sep 14 07:49:09 1999 |
| MD5 Checksum: | daf625258a6d66bfa1ce893de5b94451 |
|
| /// File Name: |
CA-2003-03.windows.locator |
Description:
|
CERT Advisory CA-2003-03 - Windows NT, 2000, and XP contains a buffer overflow in the Windows Locator service that allows remote attackers to execute arbitrary code via the netbios ports. More information available here and in ms03-001.
| | Homepage: | http://www.cert.org | | File Size: | 8111 | | Last Modified: | Jan 24 08:07:05 2003 |
| MD5 Checksum: | e25389d4f4430a44f678578aad102a83 |
|
| /// File Name: |
cert.press.release.dec88 |
Description:
|
The DARPA press release issued on December 6, 1988 announcing the formation of the original team, which evolved into the CERT Coordination Center.
| | File Size: | 8035 | | Last Modified: | Sep 14 07:50:17 1999 |
| MD5 Checksum: | 6bb319f5777ed0d81d4f5db42d24b98e |
|
| /// File Name: |
CA-90:12.SunOS.TIOCCONS.vulnerabili..> |
Description:
|
This Advisory was a rebroadcast of a Sun Microsystems, Inc. Security Bulletin announcing the availability of a patch that corrects a problem with TIOCCONS. Problem Description: TIOCCONS can be used to re-direct console output/input away from "console"
| | File Size: | 8011 | | Last Modified: | Sep 14 07:46:44 1999 |
| MD5 Checksum: | fe8d2de38dd6e78f68ba2e0c6c052f73 |
|
| /// File Name: |
CA-99-12-amd.txt |
Description:
|
There is a buffer overflow vulnerability in the logging facility of the amd daemon.
| | File Size: | 7989 | | Last Modified: | Sep 16 20:42:09 1999 |
| MD5 Checksum: | e093f357b230d861a5ee88bfd67261ed |
|
| /// File Name: |
CA-2002-13.MSN.Chat.control.txt |
Description:
|
CERT Advisory CA-2002-13 - A buffer overflow in the MSN Chat control allows remote attackers to run arbitrary code if a user runs MSN Messenger or Exchange Instant Messenger. It is also possible to exploit this vulnerability via a web site or HTML email. Additional information can be found in the Microsoft bulletin MS02-22.
| | Homepage: | http://www.cert.org | | File Size: | 7931 | | Last Modified: | May 13 03:23:39 2002 |
| MD5 Checksum: | 7f908068e4f7db69361f9a16ecbf85d9 |
|
| /// File Name: |
CA-96.16.Solaris_admintool_vul |
Description:
|
This advisory describes a vulnerability in the Solaris admintool and gives a workaround.
| | File Size: | 7923 | | Last Modified: | Sep 14 07:48:59 1999 |
| MD5 Checksum: | e41b47dc54c897ecaec484803242b278 |
|
| /// File Name: |
CA-2000-03.dns |
Description:
|
CERT Advisory CA-2000-03 - Continuing Compromises of DNS servers. Many systems are vulnerable to remote root bind bugs which are increasingly being exploited. A significant number of delegates DNS servers in the in-addr.arpa tree are running outdated version of DNS software as well. CERT
| | Homepage: | http://www.cert.org | | File Size: | 7898 | | Last Modified: | Apr 27 03:01:29 2000 |
| MD5 Checksum: | 32549c6a877570f9948d9f777077df64 |
|
|
|
|
|