Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-2003-04.mssql.worm |
Description:
|
CERT Advisory CA-2003-04 - A quickly spreading Microsoft SQL worm exploits two vulnerabilities in Microsoft SQL Server 2000 over udp port 1434.
| | Homepage: | http://www.cert.org | | File Size: | 7874 | | Last Modified: | Jan 26 19:38:07 2003 |
| MD5 Checksum: | 9a3232db2280856d044de3dc8eaac1af |
|
| /// File Name: |
CA-2002-05.php.upload |
Description:
|
CERT Advisory CA-2002-05 - File upload vulnerabilities in php_mime_split allow remote attackers to execute arbitrary code with the privileges of the PHP process in v4.1.1 and below. More information available here. Patch available here.
| | Homepage: | http://www.cert.org | | File Size: | 7777 | | Last Modified: | Feb 28 03:52:42 2002 |
| MD5 Checksum: | 0013da4bfe2284dd9bd31c2fe86d2b62 |
|
| /// File Name: |
CA-97.15.sgi_login |
Description:
|
This advisory describes a vulnerability in the SGI login program when the LOCKOUT parameter is set to a number greater than zero. The vulnerability is present in IRIX 5.3 and 6.2, and perhaps other
| | File Size: | 7746 | | Last Modified: | Sep 14 07:49:29 1999 |
| MD5 Checksum: | 63487ae81515eb2d586277edd64fed61 |
|
| /// File Name: |
CA-2002-24.openssh.trojan |
Description:
|
CERT Advisory CA-2002-24 - OpenSSH was trojaned from July 30 to Aug 1, allowing remote attackers to execute commands over a port 6667 connection. Versions openssh-3.2.2p1.tar.gz, openssh-3.4.tgz, and openssh-3.4p1.tar.gz were replaced. In the future check the GPG signature.
| | Homepage: | http://www.cert.org | | File Size: | 7614 | | Last Modified: | Aug 6 07:11:42 2002 |
| MD5 Checksum: | e84c9dfca68a40aa713fe8ebdcdc6d75 |
|
| /// File Name: |
CA-96.15.Solaris_KCMS_vul |
Description:
|
This advisory describes a vulnerability in the Solaris 2.5 kcms programs and suggests a workaround.
| | File Size: | 7595 | | Last Modified: | Sep 14 07:48:58 1999 |
| MD5 Checksum: | 304756d15566abe3cb98ab1e36a13aa3 |
|
| /// File Name: |
CA-2000-17.rpc.statd |
Description:
|
Cert Advisory CA-2000-17 - There is an input validation vulnerability in rpc.statd where the program passes user-supplied data to the syslog() function as a format string. Exploit allows user to execute arbitrary commands with the priviledges of the rpc.statd process, typically root.
| | Homepage: | http://www.cert.org | | File Size: | 7594 | | Last Modified: | Aug 21 21:44:26 2000 |
| MD5 Checksum: | 1809cac4740e7151a10387d86aaf37e1 |
|
| /// File Name: |
CA-96.05.java_applet_security_mgr |
Description:
|
This advisory describes a vulnerability in the Netscape Navigator 2.0 Java implementation and in Release 1.0 of the Java Developer's Kit from Sun Microsystems, Inc. Workarounds and pointers to a patch are included.
| | File Size: | 7565 | | Last Modified: | Sep 14 07:48:45 1999 |
| MD5 Checksum: | 7e68bb2199001dbc6939c982b95d9253 |
|
| /// File Name: |
CA-94:14.trojan.horse.in.IRC.client..> |
Description:
|
This advisory discusses a Trojan horse that was found in version 2.2.9 or ircII, the source code for the Internet Relay Chat (IRC) client for UNIX systems. For reasons described in the advisory, the CERT staff urges everyone to install ircII version 2.6.
| | File Size: | 7438 | | Last Modified: | Sep 14 07:48:00 1999 |
| MD5 Checksum: | 3ad62e3a6874eb3be1be2d0befdd860e |
|
| /// File Name: |
CA-92:11:SunOS.Environment.vulnerab..> |
Description:
|
A vulnerability involving environment variables and setuid/setgid programs exists on all Sun architectures running SunOS 4.0 and higher. The advisory details how to obtain patches for SunOS programs which are known to be impacted by the vulnerability. The advisory contains a workaround to protect vulnerable binaries for which patches are unavailable for your SunOS version, or for local or third party software which may be vulnerable.
| | File Size: | 7412 | | Last Modified: | Sep 14 07:47:06 1999 |
| MD5 Checksum: | 8ea3d36c1521d6b26a062f3a6b92b9fc |
|
| /// File Name: |
CA-2002-33.MDAC |
Description:
|
CERT Advisory CA-2002-33 - Heap Overflow Vulnerability in Microsoft Data. A routine in the RDS component, specifically the RDS Data Stub function, contains an unchecked buffer. The RDS Data Stub function's purpose is to parse incoming HTTP requests and generate RDS commands. This unchecked buffer could be exploited to cause a heap overflow.
| | Homepage: | http://www.cert.org | | File Size: | 7392 | | Last Modified: | Nov 24 02:18:56 2002 |
| MD5 Checksum: | b5c22892f43bdc3b7483e26eba6523ce |
|
| /// File Name: |
CA-95:12.sun.loadmodule.vul |
Description:
|
The advisory describes a problem with the loadmodule(8) program in Sun OS 4.1.X and provides patch information.
| | File Size: | 7355 | | Last Modified: | Sep 14 07:48:35 1999 |
| MD5 Checksum: | 79afb161722955323b933949d7614a4c |
|
| /// File Name: |
CA-2002-34.xfs |
Description:
|
CERT Advisory CA-2002-34 - The Solaris X Window Font Service (XFS) daemon (fs.auto) on Solaris 2.5.1 - 9 contains a remotely exploitable user nobody buffer overflow on Sparc and X86. More information available here.
| | Homepage: | http://www.cert.org | | File Size: | 7331 | | Related CVE(s): | CAN-2002-1317 | | Last Modified: | Nov 30 12:08:28 2002 |
| MD5 Checksum: | e6268b7f2e6e9e048615738ffeb05c49 |
|
| /// File Name: |
CA-92:15.Multiple.SunOS.vulnerabili..> |
Description:
|
** This advisory supersedes CA-91:16. ** The advisory describes how to obtain various patches for SunOS 4.1, 4.1.1, and 4.1.2 for all Sun architectures. As the application of these patches involves rebuilding your system kernel, it is recommended that you apply all patches simultaneously.
| | File Size: | 7284 | | Last Modified: | Sep 14 07:47:10 1999 |
| MD5 Checksum: | 87824e162abc82bf0d9e7cd4db19a60b |
|
| /// File Name: |
CA-94:15.NFS.Vulnerabilities |
Description:
|
This advisory describes security measures to guard against several vulnerabilities in the Network File System (NFS). The advisory was prompted by an increase in root compromises by intruders using tools to exploit the vulnerabilities.
| | File Size: | 7193 | | Last Modified: | Sep 14 07:48:03 1999 |
| MD5 Checksum: | 33d07304d57dcf3bc7c2dca5ee4cc7d3 |
|
| /// File Name: |
CA-94:08.ftpd.vulnerabilities |
Description:
|
This advisory addresses two vulnerabilities with some releases of fptd and announces new versions and patches to correct these problems. ftpd versions affected are wuarchive ftpd 2.0-2.3, DECWRL ftpd versions prior to 5.93, and BSDI ftpd version 1.1 prior to patch level 5. The vulnerabilities addressed are the SITE EXEC and race condition vulnerabilities.
| | File Size: | 7149 | | Last Modified: | Sep 14 07:47:55 1999 |
| MD5 Checksum: | 33810eadf967db905b4754684b618c37 |
|
| /// File Name: |
CA-92:14.Altered.System.Binaries.In..> |
Description:
|
Warning about a significant intrusion incident on the Internet. Urges all system administrators to check their systems for the signs of intrusion detailed in the advisory.
| | File Size: | 7132 | | Last Modified: | Sep 14 07:47:09 1999 |
| MD5 Checksum: | 493a3fa57734698d2d0b91732fd2f87a |
|
| /// File Name: |
CA-2003-09.iis-webdav |
Description:
|
CERT Advisory CA-2003-09 - A buffer overflow vulnerability exists in Microsoft IIS 5.0 running on Microsoft Windows 2000. An overflow in ntdll.dll of WebDAV allows remote users to execute code in the local system context. See also ms03-007.
| | Homepage: | http://www.cert.org | | File Size: | 7125 | | Related CVE(s): | CAN-2003-0109 | | Last Modified: | Mar 18 14:39:13 2003 |
| MD5 Checksum: | ffa2899810162a68e9c91d8cae8f7803 |
|
| /// File Name: |
CA-2002-11.cachefsd |
Description:
|
CERT Advisory CA-2002-11 - Sun's NFS/RPC file system cachefs daemon (cachefsd) installed by default with Sun Solaris 2.5.1, 2.6, 7, and 8, contains a remotely exploitable heap overflow which allows attackers to execute code as root.
| | Homepage: | http://www.cert.org | | File Size: | 7079 | | Last Modified: | May 7 09:36:50 2002 |
| MD5 Checksum: | 842f0179954995b6d4c0f25e885ed5d3 |
|
| /// File Name: |
CA-2003-14.mswin.txt |
Description:
|
CERT Advisory CA-2003-14 - A buffer overflow vulnerability exists in a shared HTML conversion library included in Microsoft Windows. An attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service.
| | Homepage: | http://www.cert.org | | File Size: | 7062 | | Last Modified: | Jul 18 01:54:32 2003 |
| MD5 Checksum: | 8c5b5e631a493151fcc60504744b1dc0 |
|
| /// File Name: |
CA-99-08-cmsd.txt |
Description:
|
A buffer overflow vulnerability has been discovered in the Calendar Manager Service daemon, rpc.cmsd.
| | File Size: | 7036 | | Last Modified: | Sep 14 07:50:13 1999 |
| MD5 Checksum: | 9af137a220c48af4b42f6212d48562e4 |
|
| /// File Name: |
CA-94:06.utmp.vulnerability |
Description:
|
This advisory addresses a vulnerability with /etc/utmp ins SunOS 4.1.X and Solaris 1.1.1 operating systems. Solbourne Computer, Inc. and other Sparc products using SunOS 4.1.X or Solaris 1.1.1 are also affected. Solaris 2.x is not affected by this problem.
| | File Size: | 7029 | | Last Modified: | Sep 14 07:47:53 1999 |
| MD5 Checksum: | 74063161402f72e8645cf34aa177c4c7 |
|
| /// File Name: |
CA-93:05.OpenVMS.AXP.vulnerability |
Description:
|
A vulnerability is present with Digital Equipment Corporation's OpenVMS and OpenVMS AXP. This vulnerability is present in OpenVMS V5.0 through V5.5-2 and OpenVMS AXP V1.0 but has been corrected in OpenVMS V6.0 and OpenVMS AXP V1.5. This advisory provides details from Digital on the severity of the vulnerability and patch availability for the problem.
| | File Size: | 6919 | | Last Modified: | Sep 14 07:47:21 1999 |
| MD5 Checksum: | aeff2469420c9db0f51a688439203c81 |
|
| /// File Name: |
CA-96.11.interpreters_in_cgi_bin_di..> |
Description:
|
This advisory warns users not to put interpreters in a Web server's CGI bin directory and to evaluate all programs in that directory.
| | File Size: | 6693 | | Last Modified: | Sep 14 07:48:52 1999 |
| MD5 Checksum: | 981fa741bc747f79e3dee296c420a561 |
|
| /// File Name: |
CA-2002-35.raq4 |
Description:
|
CERT Advisory CA-2002-35 - Cobalt Raq4 systems with the Security Hardening Package installed allow remote attackers to execute code as root because overflow.cgi does not adequately filter input destined for the email variable.
| | Homepage: | http://www.cert.org | | File Size: | 6638 | | Last Modified: | Dec 12 16:49:28 2002 |
| MD5 Checksum: | 026cbf3d80a30a687e152121d00ddeb6 |
|
| /// File Name: |
CA-2002-10.rpc.walld |
Description:
|
CERT Advisory CA-2002-10 - Solaris v2.5.1, 2.6, 2.7, and 2.8 rpc.walld contains a remotely exploitable format string overflow.
| | Homepage: | http://www.cert.org | | File Size: | 6526 | | Last Modified: | May 7 09:33:11 2002 |
| MD5 Checksum: | 4653bcc808b8d76746723c186ffc665c |
|
|
|
|
|