Section: .. / advisories / freebsd /
| /// File Name: |
FreeBSD-SA-00:81.ethereal |
Description:
|
FreeBSD Security Advisory - The ethereal port, versions prior to 0.8.14, contains buffer overflows which allow a remote attacker to crash ethereal or execute arbitrary code on the local system as the user running ethereal, typically the root user. These vulnerabilities are identical to those described in advisory 00:61 relating to tcpdump.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3763 | | Last Modified: | Dec 22 00:01:26 2000 |
| MD5 Checksum: | baaa05f7895dc191fdd49d9850329394 |
|
| /// File Name: |
FreeBSD-SA-00:48.xchat |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-00:48 - The xchat IRC client provides the ability to launch URLs displayed in an IRC window in a web browser by right clicking on the URL. However this was handled incorrectly in versions prior to 1.4.3, and prior to 1.5.7 in the 1.5 development series, and allowed a malicious IRC user to embed command strings in a URL which could cause an arbitrary command to be executed as the local user if the URL were to be "launched" in a browser as described above.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3761 | | Last Modified: | Sep 14 00:50:09 2000 |
| MD5 Checksum: | 3ad77f884b1369f7b70ef91411225a9b |
|
| /// File Name: |
FreeBSD-SA-01:38.sudo |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:38.sudo - The sudo port, versions prior to sudo-1.6.3.7, contains a local command-line buffer overflow allowing local users to gain root privileges on the local system.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3757 | | Last Modified: | Apr 25 02:58:21 2001 |
| MD5 Checksum: | 16516985b9f52c388032d3954420c5ff |
|
| /// File Name: |
FreeBSD-SA-00:56.lprng |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-00:56 - The LPRng port, versions prior to 3.6.24, contains a vulnerability in syslog() which allows remote and local root compromise.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3745 | | Last Modified: | Oct 15 20:43:54 2000 |
| MD5 Checksum: | c387831aa8d27504228aab3db76546a5 |
|
| /// File Name: |
FreeBSD-SA-00:40 |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-00:40 - The mopd port contains several remotely exploitable vulnerabilities. An attacker exploiting these can execute arbitrary code on the local machine as root.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3741 | | Last Modified: | Aug 28 23:25:56 2000 |
| MD5 Checksum: | a597170531b61bc224267a66ee679ba6 |
|
| /// File Name: |
FreeBSD-SA-02:17.mod_frontpage |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-02:17 - The mod_frontpage port prior to version mod_portname-1.6.1 contains several remotely exploitable buffer overflows in the fpexec wrapper, which is installed setuid root.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3740 | | Last Modified: | Mar 13 06:02:45 2002 |
| MD5 Checksum: | 8729fe12c9ec1ed3d1f04ea9e7d09932 |
|
| /// File Name: |
FreeBSD-SA-01:32.ipfilter |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:32.ipfilter - When matching a packet fragment, insufficient checks were performed to ensure the fragment is valid. In addition, the fragment cache is checked before any rules are checked. Even if all fragments are blocked with a rule, fragment cache entries can be created by packets that match currently held state information. Because of these discrepancies, certain packets may bypass filtering rules. All versions of FreeBSD prior to the correction date, including FreeBSD 3.5.1 and 4.2, contain this problem.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3740 | | Last Modified: | Apr 24 03:38:38 2001 |
| MD5 Checksum: | 2c3f0fdd3246c06da4aca3af30fb026f |
|
| /// File Name: |
FreeBSD-SA-01:14.micq |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:14 - The micq port, versions prior to 0.4.6.1, contains a remote vulnerability: due to a buffer overflow, a malicious remote user sending specially-crafted packets may be able to execute arbitrary code on the local system with the privileges of the micq process.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3737 | | Last Modified: | Feb 1 01:46:29 2001 |
| MD5 Checksum: | 80b14bb792b0f28d7de89dbd80818eb1 |
|
| /// File Name: |
sa96-19 |
Description:
|
Buffer overflow in modstat
| | File Size: | 3733 | | Last Modified: | Sep 23 05:52:22 1999 |
| MD5 Checksum: | 7004204773d0e5bf88c94771a60f705c |
|
| /// File Name: |
FreeBSD-SA-00:38.zope |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-00:38 - The issue involves an inadequately protected method in one of the base classes in the DocumentTemplate package that could allow the contents of DTMLDocuments or DTMLMethods to be changed remotely or through DTML code without forcing proper user authorization.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3731 | | Last Modified: | Aug 15 05:29:19 2000 |
| MD5 Checksum: | 632b3e9319db03059f8ddd19d0a5711b |
|
| /// File Name: |
freebsd.sa-99.02.exec_calls |
Description:
|
Profiling Across Exec Calls
| | File Size: | 3697 | | Last Modified: | Sep 23 05:52:22 1999 |
| MD5 Checksum: | b6e2c2bad6625d53d805c7809cc90e24 |
|
| /// File Name: |
FreeBSD-SA-00:29.wu-ftpd |
Description:
|
FreeBSD-SA-00:29 - The wu-ftpd port, versions 2.6.0 and below, contains a vulnerability which allows remote anonymous FTP users to execute arbitrary code as root on the local machine, by inserting string-formatting operators into command input, which are incorrectly parsed by the FTP server.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3659 | | Last Modified: | Jul 13 00:50:28 2000 |
| MD5 Checksum: | 6ae2d585b83ab90f805bebe5987ce7ff |
|
| /// File Name: |
FreeBSD-SA-01:26.interbase |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:26 - The interbase port has a hard coded backdoor which has full read and write access to databases stored on the server, and also gives the ability to write to arbitrary files on the server as the user running the interbase server (usually user root). Remote attackers may connect to the database on TCP port 3050.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3658 | | Last Modified: | Mar 16 02:36:41 2001 |
| MD5 Checksum: | 1757f4c716432f5a102856a2e81db743 |
|
| /// File Name: |
sa97-02 |
Description:
|
Buffer overflow in lpd
| | File Size: | 3653 | | Last Modified: | Sep 23 05:52:22 1999 |
| MD5 Checksum: | 7fb53540203503a7c09f11e334f5a4f7 |
|
| /// File Name: |
FreeBSD-SA-00:11.ircii |
Description:
|
FreeBSD Security Advisory - ircII port contains a remote overflow. ircII version 4.4 distributed with freebsd contained a remotely-exploitable buffer overflow in the /DCC CHAT command which allows remote users to execute arbitrary code as the client user.
| | Homepage: | http://www.freebsd.org | | File Size: | 3653 | | Last Modified: | Apr 12 01:29:55 2000 |
| MD5 Checksum: | 4a910a22b02cf1eda7375d8b9143969b |
|
| /// File Name: |
FreeBSD-SA-00:72.curl |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-00:73 - The curl port, versions prior to 7.4.1, allows a client-side exploit through a buffer overflow in the error handling code. A malicious ftp server operator can cause arbitrary code to be executed by the user running the curl client.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3651 | | Last Modified: | Nov 26 04:10:46 2000 |
| MD5 Checksum: | ee47649ba1e8173863061b29692ee15c |
|
| /// File Name: |
FreeBSD-SA-00:49.eject |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-00:49 - The eject port is installed setuid root, and contains several exploitable buffers which can be overflowed by local users, yielding root privileges.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3650 | | Last Modified: | Sep 14 00:51:50 2000 |
| MD5 Checksum: | 96b6dae72ab2fe3a285d136a511a5265 |
|
| /// File Name: |
FreeBSD-SA-01:28.timed |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:28 - Malformed packets sent to the timed daemon on UDP port 525 could cause it to crash, thereby denying service to clients.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3647 | | Last Modified: | Mar 16 02:41:44 2001 |
| MD5 Checksum: | 966eb434860dcea9e93ca3134e57b93f |
|
| /// File Name: |
FreeBSD-SA-01:15.tinyproxy |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:15 - The tinyproxy port, versions prior to 1.3.3a, contains remote vulnerabilities: due to a heap overflow, malicious remote users can cause arbitrary code to be executed as the user running tinyproxy.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3633 | | Last Modified: | Feb 1 01:47:36 2001 |
| MD5 Checksum: | 77b21498d6a7813c74b86046e787d2cf |
|
| /// File Name: |
FreeBSD-SA-01:06.zope |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:06.zope - The zope port, versions prior to 2.2.4, contains a vulnerability due to the computation of local roles not climbing the correct hierarchy of folders, sometimes granting local roles inappropriately. This may allow users with privileges in one folder to gain the same privileges in another folder.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3625 | | Last Modified: | Jan 17 07:54:33 2001 |
| MD5 Checksum: | 35e7c60c1c8026dfa91e332c100feec3 |
|
| /// File Name: |
FreeBSD-SA-01_47.xinetd |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-01:47 - The xinetd port, versions prior to xinetd-2.3.0, contains a potentially exploitable buffer overflow in the logging routines. If xinetd is configured to log the userid of remote clients obtained via the RFC1413 ident service, a remote user may be able to cause xinetd to crash by returning a specially-crafted ident response. This may also potentially execute arbitrary code as the user running xinetd, normally root.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3613 | | Last Modified: | Aug 11 10:53:19 2001 |
| MD5 Checksum: | bd04640e39c1ed7270b7729a372acbec |
|
| /// File Name: |
FreeBSD-SA-00:79:oops |
Description:
|
FreeBSD Security Advisory - The oops port, versions prior to 1.5.2, contains remote vulnerabilities through buffer and stack overflows in the HTML parsing code. These vulnerabilities may allow remote users to execute arbitrary code as the user running oops.
| | Homepage: | http://www.freebsd.org/security | | File Size: | 3592 | | Last Modified: | Dec 21 23:21:47 2000 |
| MD5 Checksum: | 556a1885b27dd4771d50fa80bac785db |
|
| /// File Name: |
freebsd.sa-00.05.golddig |
Description:
|
FreeBSD Security Advisory - golddig, from the ports collection, erroneously installs a level-creation utility setuid root, which allows users to overwrite the contents of arbitrary local files. It is not believed that any elevation of privileges is possible with this vulnerability because the contents of the file are a textual representation of a golddig game level which is highly constrained.
| | Homepage: | http://www.freebsd.org | | File Size: | 3549 | | Last Modified: | May 9 23:13:32 2000 |
| MD5 Checksum: | e80dfab428f54601385c02d8c9ecb031 |
|
| /// File Name: |
freebsd.sa-00.06.htdig |
Description:
|
FreeBSD Security Advisory - There is a security hole in the htsearch cgi-bin program for versions of htdig prior to 3.1.5, which allows remote users to read any file on the local system that is accessible to the user ID running htsearch.
| | Homepage: | http://www.freebsd.org | | File Size: | 3523 | | Last Modified: | Mar 1 22:12:07 2000 |
| MD5 Checksum: | 9a0bf489d75c650bc8f4efdedbff2ac1 |
|
| /// File Name: |
freebsd.sa-00.05.mysql322-server |
Description:
|
FreeBSD Security Advisory - The MySQL database server (versions prior to 3.22.32) has a flaw in the password authentication mechanism which allows anyone who can connect to the server to access databases without requiring a password, given a valid username on the database - in other words, the normal password authentication mechanism can be completely bypassed.
| | Homepage: | http://www.freebsd.org | | File Size: | 3498 | | Last Modified: | Feb 29 09:16:48 2000 |
| MD5 Checksum: | cb6b34a2a03fdcf9ea2e562583b4c132 |
|
|
|
|
|