Section: .. / advisories / iss /
| /// File Name: |
iss.01-05-09.irix.espd |
Description:
|
ISS Security Advisory - A buffer overflow has been discovered in IRIX rpc.espd, which is installed by default on all current SGI IRIX installations. Remote attackers without accounts can execute commands as root. Patch available here.
| | Homepage: | http://xforce.iss.net | | File Size: | 5533 | | Last Modified: | May 17 21:49:21 2001 |
| MD5 Checksum: | 7409d9d244ce290b32c9c3efd7962913 |
|
| /// File Name: |
iss.01-05-15.iis.url.decode |
Description:
|
ISS Security Alert - A flaw exists in Microsoft Internet Information Server (IIS) that may allow remote attackers to view directory structures, view and delete files, execute arbitrary commands, and deny service to the server. It is possible for attackers to craft URLs that take advantage of a flaw in IIS URL decoding routines. Security mechanisms within these routines can be bypassed. All recent versions of IIS are affected by this vulnerability.
| | Homepage: | http://xforce.iss.net | | File Size: | 7176 | | Last Modified: | May 17 22:57:56 2001 |
| MD5 Checksum: | 501e29ead39aba3b7ed1aa3339dda9e0 |
|
| /// File Name: |
iss.01-07-05.radius |
Description:
|
ISS Security Advisory - X-Force has discovered buffer overflow vulnerabilities in two popular Remote Authentication Dial-In User Server (RADIUS) implementations. The vulnerabilities in this advisory allow attackers to launch Denial of Service (DoS) attacks against critical network components, bypass 802.11 WLAN access control, and compromise and control protected network resources. Affected versions include Merit 3.6b RADIUS and Lucent 2.1-2 RADIUS. Prior releases are also vulnerable.
| | Homepage: | http://xforce.iss.net | | File Size: | 5909 | | Last Modified: | Jul 12 14:42:53 2001 |
| MD5 Checksum: | 5b49d5a5bf26d13e0f3c41583fb17e54 |
|
| /// File Name: |
iss.01-08-27.hp.lpr |
Description:
|
ISS Security Advisory - A buffer overflow has been discovered in the HP-UX line printer daemon (rlpdaemon) which allows a remote or local attacker to execute arbitrary code with superuser privilege. Affected versions include HP-UX 10.01, 10.10, 10.20, 11.00, and 11.11. Rlpdaemon is configured to run by default even if it is not being used.
| | Homepage: | http://xforce.iss.net | | File Size: | 4684 | | Last Modified: | Aug 28 08:55:03 2001 |
| MD5 Checksum: | 225386c3d3c624544ff8d532276ffa41 |
|
| /// File Name: |
iss.01-08-29.bsd-lpr |
Description:
|
ISS Security Advisory - A buffer overflow has been discovered in the line printer daemon of several BSD implementations. (in.lpd or lpd) A remote or local attacker can execute arbitrary code as root. The vulnerability presents itself when an attacker submits a specially crafted print job and then requests a display of the printer queue to trigger the overflow. Affected versions include OpenBSD CURRENT and earlier, FreeBSD 4.3 and earlier, NetBSD 1.5.1 and earlier, and BSD/OS 4.1 and earlier.
| | Homepage: | http://xforce.iss.net | | File Size: | 5297 | | Last Modified: | Aug 30 07:23:03 2001 |
| MD5 Checksum: | ffba09ec65000c193f64aff77c28366b |
|
| /// File Name: |
iss.01-10-02.ttdbserverd |
Description:
|
ISS Security Advisory - A format string vulnerability has been found in the tooltalk service (rpc.ttdbserverd) on multiple versions of HP-UX, IBM AIX, IRIX, DG-UX, and Solaris. ToolTalk contains a "syslog()" call that will interpret user-supplied formatting arguments. This call is insecure and allows remote attackers to control formatting and manipulate data at arbitrary locations in the memory of the running executable.
| | Homepage: | http://xforce.iss.net | | File Size: | 7609 | | Last Modified: | Oct 4 08:38:32 2001 |
| MD5 Checksum: | fc846f2aab901cd94774643b4e146f2d |
|
| /// File Name: |
iss.01-10-16.citrix |
Description:
|
ISS Security Advisory - A remote denial of service vulnerability has been found in Citrix MetaFrame, an application server that works with Windows Terminal Services. This vulnerability causes a MetaFrame installation to crash or "blue screen" and requires an affected system to be restarted manually.
| | Homepage: | http://xforce.iss.net | | File Size: | 5334 | | Last Modified: | Oct 17 08:50:39 2001 |
| MD5 Checksum: | 34bb43b34fb59d9d774ba6785bc9b360 |
|
| /// File Name: |
iss.01-11-12.dtspcd |
Description:
|
ISS discovered a buffer overflow vulnerability in the Subprocess Control Server (dtspcd) in all Unix variants running CDE (Common Desktop Environment) system. The vulnerability in the dtspcd daemon allows remote attackers to execute arbitrary commands on a target system as root. Many unix flavors are affected.
| | Homepage: | http://xforce.iss.net | | File Size: | 6851 | | Last Modified: | Nov 13 00:31:54 2001 |
| MD5 Checksum: | beea66f63139c599a9961d27013d248f |
|
| /// File Name: |
iss.01-11-20.rlpdaemon |
Description:
|
ISS Security Advisory - ISS X-Force has discovered a vulnerability in the HP-UX line printer daemon (rlpdaemon) that allows a remote or local user to execute arbitrary code with root privileges. Affected versions include HP-UX 10.01, 10.10, 10.20, 11.00, and 11.11.
| | Homepage: | http://www.iss.net/xforce | | File Size: | 4862 | | Last Modified: | Nov 21 00:19:37 2001 |
| MD5 Checksum: | 43096382e2e5ba6caf7ba296e2418260 |
|
| /// File Name: |
iss.05-02-01.iis5 |
Description:
|
ISS Security Advisory - Windows 2000 running IIS 5.0 has a serious remote vulnerability in the ISAPI printer extension. More information available here.
| | Homepage: | http://xforce.iss.net | | File Size: | 5816 | | Last Modified: | May 3 04:07:09 2001 |
| MD5 Checksum: | ee2197a7cf116fb15f36e2d4b9e5e7c3 |
|
| /// File Name: |
iss.09-05-00.trinity |
Description:
|
ISS Security Alert - A new Distributed Denial of Service tool, "Trinity v3", has been reported. Each client joins an undernet IRC channel to take commands. A bindshell is usually installed on TCP port 33270.
| | Homepage: | http://xforce.iss.net | | File Size: | 8488 | | Last Modified: | Sep 6 05:50:06 2000 |
| MD5 Checksum: | bf31b109e8c23a901996de22d6471e8d |
|
| /// File Name: |
iss.97-10-21.scheduler_winlogin_key..> |
Description:
|
iss.97-10-21.scheduler_winlogin_keys
| | File Size: | 4801 | | Last Modified: | Oct 23 19:41:56 1997 |
| MD5 Checksum: | 24b7fd453e9fa2d26d4bacf80e898758 |
|
| /// File Name: |
iss.98-06-10.rpc.nisd |
Description:
|
iss.98-06-10.rpc.nisd
| | File Size: | 3471 | | Last Modified: | Jun 11 02:49:43 1998 |
| MD5 Checksum: | a6ce08753e4852bdcfdf3a5eaa1b98f4 |
|
| /// File Name: |
iss.98-06-29.nis_dos |
Description:
|
iss.98-06-29.nis_dos
| | File Size: | 11537 | | Last Modified: | Jul 15 11:02:00 1999 |
| MD5 Checksum: | 5b9c336b5cda14647e89d837bc499717 |
|
| /// File Name: |
iss.98-07-24.exchange_dos |
Description:
|
iss.98-07-24.exchange_dos
| | File Size: | 6977 | | Last Modified: | Jul 15 11:00:55 1999 |
| MD5 Checksum: | 9c00194a3a5cba62f66079e62d9d3b27 |
|
| /// File Name: |
iss.98-08-06.cdc_back_orifice |
Description:
|
iss.98-08-06.cdc_back_orifice
| | File Size: | 6151 | | Last Modified: | Aug 9 22:48:21 1998 |
| MD5 Checksum: | fc55bb97989a81f04e3b7c0cb2f821b3 |
|
| /// File Name: |
iss.98-08-31.exec_dirs_iis |
Description:
|
iss.98-08-31.exec_dirs_iis
| | File Size: | 4198 | | Last Modified: | Sep 4 12:00:59 1998 |
| MD5 Checksum: | 413ccead4ac8a0f5f1b155a637191d95 |
|
| /// File Name: |
iss.98-09-01.webcam32 |
Description:
|
iss.98-09-01.webcam32
| | File Size: | 4965 | | Last Modified: | Sep 4 12:01:00 1998 |
| MD5 Checksum: | dcba1ec8058e0b6e47464a0b723caf9e |
|
| /// File Name: |
iss.98-09-10.backdoors_update |
Description:
|
iss.98-09-10.backdoors_update
| | File Size: | 11183 | | Last Modified: | Sep 11 22:15:23 1998 |
| MD5 Checksum: | e3d0f05c115c1e740f5d11db2e2289e1 |
|
| /// File Name: |
iss.98-09-29.snork |
Description:
|
iss.98-09-29.snork
| | File Size: | 5596 | | Last Modified: | Oct 2 05:10:26 1998 |
| MD5 Checksum: | ac1155e34b9747ecafe55ce0d1870a23 |
|
| /// File Name: |
iss.98-11-02.bmc_patrol |
Description:
|
iss.98-11-02.bmc_patrol
| | File Size: | 3909 | | Last Modified: | Nov 24 19:20:42 1998 |
| MD5 Checksum: | f955dc4127ccb11498beeccf99fc91d6 |
|
| /// File Name: |
iss.98-11-02.hp_snmp |
Description:
|
iss.98-11-02.hp_snmp
| | File Size: | 3229 | | Last Modified: | Nov 24 19:20:50 1998 |
| MD5 Checksum: | 9a6b555ba1fa4519d0cd250bbad4b914 |
|
| /// File Name: |
iss.98-11-02.sun_snmp |
Description:
|
iss.98-11-02.sun_snmp
| | File Size: | 3469 | | Last Modified: | Nov 24 19:20:43 1998 |
| MD5 Checksum: | cec586006427d61d3761af190770dc82 |
|
| /// File Name: |
iss.98-11-16.snmp_update |
Description:
|
iss.98-11-16.snmp_update
| | File Size: | 5428 | | Last Modified: | Nov 24 19:20:41 1998 |
| MD5 Checksum: | 19bf60170a2defb913eb0ee209c02d77 |
|
| /// File Name: |
iss.98-12-10.icmp_redirect |
Description:
|
iss.98-12-10.icmp_redirect
| | File Size: | 5582 | | Last Modified: | Feb 1 02:23:53 1999 |
| MD5 Checksum: | 5c6400e37f6d5c5d0b8545fb9be9c861 |
|
|
|
|
|