Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-92:06.AIX.uucp.vulnerability |
Description:
|
A vulnerability is present in the UUCP software in versions of AIX up to 2007. The advisory describes how to disable UUCP and details how to obtain a patch for the problem from IBM.
| | File Size: | 3407 | | Last Modified: | Sep 14 07:47:02 1999 |
| MD5 Checksum: | 09ca47688a4d9eb08ddd5bbb96a6c363 |
|
| /// File Name: |
CA-92:07.AIX.passwd.vulnerability |
Description:
|
A vulnerability is present in the passwd command in AIX 3.2 and the 2007 update of AIX 3.1. The advisory describes how to disable the /bin/passwd until you obtain and install the patch for the problem from IBM.
| | File Size: | 4128 | | Last Modified: | Sep 14 07:47:03 1999 |
| MD5 Checksum: | 699527f4dfef4f1c7f2da802c4f5ffb5 |
|
| /// File Name: |
CA-92:08.SGI.lp.vulnerability |
Description:
|
A vulnerability is present in the default configuration of the lp software in Silicon Graphics Computer Systems (SGI) IRIX operating systems. This vulnerability is present in all versions of IRIX, prior to IRIX 4.0.5. The advisory describes how to reconfigure the lp software in order to eliminate this vulnerability.
| | File Size: | 3993 | | Last Modified: | Sep 14 07:47:04 1999 |
| MD5 Checksum: | 3055eb9fbbc387504330f7387dac02cc |
|
| /// File Name: |
CA-92:09.AIX.anonymous.ftp.vulnerab..> |
Description:
|
A vulnerability is present in the anonymous FTP configuration in all versions of AIX. The advisory describes how to obtain a patch for the problem from IBM.
| | File Size: | 3648 | | Last Modified: | Sep 14 07:47:04 1999 |
| MD5 Checksum: | c327e23425406aeb8d6ff31645700f69 |
|
| /// File Name: |
CA-92:10.AIX.crontab.vulnerability |
Description:
|
A vulnerability is present in crontab(1) in version 3.2 of AIX. This advisory describes how to implement a workaround for the problem until you obtain the patch for the problem from IBM.
| | File Size: | 4338 | | Last Modified: | Sep 14 07:47:05 1999 |
| MD5 Checksum: | 335bf294534951568df4599aab18d309 |
|
| /// File Name: |
CA-92:11:SunOS.Environment.vulnerab..> |
Description:
|
A vulnerability involving environment variables and setuid/setgid programs exists on all Sun architectures running SunOS 4.0 and higher. The advisory details how to obtain patches for SunOS programs which are known to be impacted by the vulnerability. The advisory contains a workaround to protect vulnerable binaries for which patches are unavailable for your SunOS version, or for local or third party software which may be vulnerable.
| | File Size: | 7412 | | Last Modified: | Sep 14 07:47:06 1999 |
| MD5 Checksum: | 8ea3d36c1521d6b26a062f3a6b92b9fc |
|
| /// File Name: |
CA-92:13.SunOS.NIS.vulnerability |
Description:
|
Vulnerabilities are present in NIS under SunOS 4.1, 4.1.1, and 4.1.2, and may or may not exist in earlier versions of NIS. The advisory describes how to obtain a patch for SunOS 4.1, 4.1.1, and 4.1.2 for the problem from Sun.
| | File Size: | 5652 | | Last Modified: | Sep 14 07:47:08 1999 |
| MD5 Checksum: | 4a92a643f9e6e8b4a863d606fc75d1fd |
|
| /// File Name: |
CA-92:14.Altered.System.Binaries.In..> |
Description:
|
Warning about a significant intrusion incident on the Internet. Urges all system administrators to check their systems for the signs of intrusion detailed in the advisory.
| | File Size: | 7132 | | Last Modified: | Sep 14 07:47:09 1999 |
| MD5 Checksum: | 493a3fa57734698d2d0b91732fd2f87a |
|
| /// File Name: |
CA-92:15.Multiple.SunOS.vulnerabili..> |
Description:
|
** This advisory supersedes CA-91:16. ** The advisory describes how to obtain various patches for SunOS 4.1, 4.1.1, and 4.1.2 for all Sun architectures. As the application of these patches involves rebuilding your system kernel, it is recommended that you apply all patches simultaneously.
| | File Size: | 7284 | | Last Modified: | Sep 14 07:47:10 1999 |
| MD5 Checksum: | 87824e162abc82bf0d9e7cd4db19a60b |
|
| /// File Name: |
CA-92:18.VMS.Monitor.vulnerability...> |
Description:
|
** This advisory supersedes CA-92:16. ** It provides additional information concerning availability of remedial image kits to correct a vulnerability present in the Monitor utility in VMS V5.0 through V5.4-2. The vulnerability has been corrected in V5.4-3 through V5.5-1.
| | File Size: | 9149 | | Last Modified: | Sep 14 07:47:11 1999 |
| MD5 Checksum: | d080ba518701f588a86ecb778a05f11a |
|
| /// File Name: |
CA-92:19.Keystroke.Logging.Banner.N..> |
Description:
|
This advisory provides information from the United States Department of Justice, General Litigation and Legal Advice Section, Criminal Division, regarding keystroke monitoring by computer systems administrators, as a method of protecting computer systems from unauthorized access. The CERT staff strongly suggests adding a notice banner such as the one included in the advisory to all systems. Sites not covered by U.S. law should consult their legal counsel.
| | File Size: | 6042 | | Last Modified: | Sep 14 07:47:12 1999 |
| MD5 Checksum: | c2dd95072b105375eb41f2a6cec4aafb |
|
| /// File Name: |
CA-92:20.Cisco.Access.List.vulnerab..> |
Description:
|
This advisory provides information concerning a vulnerability in Cisco router access lists when the "established" keyword is used. This vulnerability is present in Cisco software releases 8.2, 8.3, 9.0 and 9.1. The advisory describes workarounds and provides information on how to obtain a patch for the problem from Cisco.
| | File Size: | 5581 | | Last Modified: | Sep 14 07:47:12 1999 |
| MD5 Checksum: | d4f10508dc3b7768d21abbfa6410adfe |
|
| /// File Name: |
CA-92:21.ConvexOS.vulnerabilities |
Description:
|
This advisory provides information concerning several vulnerabilities in ConvexOS/Secure, CONVEX CXbatch, CONVEX Storage Manager (CSM), and ConvexOS EMACS. These vulnerabilities can affect ConvexOS versions V6.2 - V10.2 and ConvexOS/Secure versions V9.5 and V10.0 on all supported architectures. The advisory describes a workaround for one of the vulnerabilities and provides information on how to obtain a patches for the other problems from CONVEX Computer Corporation.
| | File Size: | 5938 | | Last Modified: | Sep 14 07:47:13 1999 |
| MD5 Checksum: | 3e71d8b4d58199d91749e14bb9b92467 |
|
| /// File Name: |
CA-93:01.REVISED.HP.NIS.ypbind.vuln..> |
Description:
|
** This advisory supersedes CA-92:17. ** A vulnerability is present in Hewlett-Packard's HP/UX Operating System for series 300, 700, and 800 computers, which allows remote NIS servers unauthorized access to local NIS hosts. Patches from HP are available for all of the HP/UX level 8 releases (8.0, 8.02, 8.06, and 8.07). The problem is fixed in HP/UX 9.0.
| | File Size: | 5744 | | Last Modified: | Sep 14 07:47:14 1999 |
| MD5 Checksum: | 669ba4a4e2a9c619765eb859e29edda0 |
|
| /// File Name: |
CA-93:02a.NeXT.NetInfo._writers.vul..> |
Description:
|
This advisory provides information concerning vulnerabilities in the distributed printing facility ("_writers" properties) of NeXT computers running all releases of NeXTSTEP software through NeXTSTEP Release 3.0. The advisory details the availability of a patch for the problems and provides suggested workarounds.
| | File Size: | 6233 | | Last Modified: | Sep 14 07:47:16 1999 |
| MD5 Checksum: | a972cdc1519587485675a866751363c8 |
|
| /// File Name: |
CA-93:03.SunOS.Permissions.vulnerab..> |
Description:
|
This advisory describes a patch that is available to correct the ownerships and permissions for a number of system files in SunOS 4.1, 4.1.1, 4.1.2, and 4.1.3. These have been fixed in SunOS 5.0. CERT staff has seen an increasing number of attackers exploit these problems on systems and we encourage sites to consider installing this patch.
| | File Size: | 6118 | | Last Modified: | Sep 14 07:47:19 1999 |
| MD5 Checksum: | 6292c19f3aa42c4bccf5f57f7add2059 |
|
| /// File Name: |
CA-93:04a.Amiga.finger.vulnerabilit..> |
Description:
|
A vulnerability is present in the "finger" program of Commodore Business Machine's Amiga UNIX product and affects Commodore Amiga UNIX versions 1.1, 2.03, 2.1, 2.1p1, 2.1p2, and 2.1p2a. This advisory details the availability of a patch for the problem and provides a suggested workaround.
| | File Size: | 4243 | | Last Modified: | Sep 14 07:47:20 1999 |
| MD5 Checksum: | 92996075b41c4871012662f59512a237 |
|
| /// File Name: |
CA-93:05.OpenVMS.AXP.vulnerability |
Description:
|
A vulnerability is present with Digital Equipment Corporation's OpenVMS and OpenVMS AXP. This vulnerability is present in OpenVMS V5.0 through V5.5-2 and OpenVMS AXP V1.0 but has been corrected in OpenVMS V6.0 and OpenVMS AXP V1.5. This advisory provides details from Digital on the severity of the vulnerability and patch availability for the problem.
| | File Size: | 6919 | | Last Modified: | Sep 14 07:47:21 1999 |
| MD5 Checksum: | aeff2469420c9db0f51a688439203c81 |
|
| /// File Name: |
CA-93:06.wuarchive.ftpd.vulnerabili..> |
Description:
|
A vulnerability is present in versions of wuarchive ftpd available before April 8, 1993. This vulnerability is present in wuarchive ftpd versions which were available from wuarchive.wustl.edu and many other anonymous FTP sites. This advisory provides details on the severity of the vulnerability and (1) the availability of a new version of wuarchive ftpd and (2) availability of a patch for the problem.
| | File Size: | 4430 | | Last Modified: | Sep 14 07:47:21 1999 |
| MD5 Checksum: | 037496a1ac713b392c527e78787846e7 |
|
| /// File Name: |
CA-93:07.Cisco.Router.Packet.Handli..> |
Description:
|
A vulnerability exists in Cisco routers such that a router which is configured to suppress source routed packets with the following command: "no ip source-route" may allow traffic which should be suppressed. This vulnerability applies to all models of Cisco routers, and occurs with the following releases of software: 8.2, 8.3, 9.0, 9.1, and 9.17. This advisory details information about releases available to correct this problem.
| | File Size: | 4430 | | Last Modified: | Sep 14 07:47:22 1999 |
| MD5 Checksum: | 34adfbfb33336421040cfc0ed0b2b814 |
|
| /// File Name: |
CA-93:08.SCO.passwd.vulnerability |
Description:
|
A vulnerability exists in several releases of SCO's Operating Systems. This vulnerability has the potential to deny legitimate users the ability to log onto the system. This advisory details information about releases available to correct this problem.
| | File Size: | 11301 | | Last Modified: | Sep 14 07:47:27 1999 |
| MD5 Checksum: | b8632fa408d40ffd51ccb32ca25fe724 |
|
| /// File Name: |
CA-93:10.anonymous.FTP.activity |
Description:
|
This advisory provides an updated version of the anonymous FTP configuration guidelines that is available from the CERT Coordination Center.
| | File Size: | 12841 | | Last Modified: | Sep 14 07:47:31 1999 |
| MD5 Checksum: | 85dbc64f1d9066e3a74b14338e0460dc |
|
| /// File Name: |
CA-93:11.UMN.UNIX.gopher.vulnerabil..> |
Description:
|
Vulnerabilities exist in versions of the UMN UNIX gopher and gopher+ server and client available before August 6, 1993. These vulnerabilities are present in UMN UNIX gopher and gopher+ versions which were available from boombox.micro.umn.edu and many other anonymous FTP sites. This advisory provides details on the severity of the vulnerabilities and the availability of new versions of UMN UNIX gopher and gopher+.
| | File Size: | 4968 | | Last Modified: | Sep 14 07:47:32 1999 |
| MD5 Checksum: | de837c5e744243377d2284cd6037edf4 |
|
| /// File Name: |
CA-93:12.Novell.LOGIN.EXE.vulnerabi..> |
Description:
|
A vulnerability exists in Novell's NetWare 4.x login program (LOGIN.EXE). This advisory provides details on the availability of a security-enhance version of the Novell Netware 4.x login program.
| | File Size: | 5228 | | Last Modified: | Sep 14 07:47:34 1999 |
| MD5 Checksum: | 329a3141bf0cb2f33a796442f923dc2e |
|
| /// File Name: |
CA-93:13.SCO.Home.Directory.Vulnera..> |
Description:
|
A vulnerability relating to the "dos" and "asg" accounts exists in numerous SCO Operating Systems releases. This advisory provides instructions for repairing the vulnerability.
| | File Size: | 6365 | | Last Modified: | Sep 14 07:47:35 1999 |
| MD5 Checksum: | 030689f3cf2839ebd9977cb3030957a2 |
|
|
|
|
|