Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-97.05.sendmail |
Description:
|
This advisory addresses a MIME conversion buffer overflow in sendmail versions 8.8.3 and 8.8.4. The advisory includes vendor information, pointers to the latest version of sendmail, a workaround, and general precautions to take when using sendmail.
| | File Size: | 21852 | | Last Modified: | Sep 14 07:49:18 1999 |
| MD5 Checksum: | 56e62f30ecc526f6f4a77a3cdc35fc89 |
|
| /// File Name: |
CA-97.04.talkd |
Description:
|
A vulnerability in talkd(8) program used by talk(1) makes it possible to provide corrupt DNS information to a host and to remotely execute arbitrary commands with root privileges. The advisory includes information on how to solve the general problem as well as the specific one.
| | File Size: | 18571 | | Last Modified: | Sep 14 07:49:17 1999 |
| MD5 Checksum: | 68fba9c8d26263bc31af1ed2639c9629 |
|
| /// File Name: |
CA-97.03.csetup |
Description:
|
A vulnerability in the csetup program under IRIX versions 5.x, 6.0, 6.0.1, 6.1, and 6.2 allows local users to create or overwrite arbitrary files on the system and ultimately gain root privileges. A workaround is provided.
| | File Size: | 6232 | | Last Modified: | Sep 14 07:49:16 1999 |
| MD5 Checksum: | 780bde03fc3ec2e10d7b2e3ec70de97a |
|
| /// File Name: |
CA-97.02.hp_newgrp |
Description:
|
This advisory describes a vulnerability in the newgrp(1) program under HP-UX 9.x and 10.x that may allow users to gain root privileges. A workaround is provided.
| | File Size: | 10088 | | Last Modified: | Sep 14 07:49:15 1999 |
| MD5 Checksum: | 4e9fd81a8b10694c8b297e408aead7cf |
|
| /// File Name: |
CA-97.01.flex_lm |
Description:
|
This advisory describes multi-platform UNIX FLEXlm vulnerabilities. These problems may allow local users to create arbitrary files on the system and execute arbitrary programs using the privileges of the user running the FLEXlm daemons.
| | File Size: | 28451 | | Last Modified: | Sep 14 07:49:14 1999 |
| MD5 Checksum: | 0e933250b36e5cc09a16eda5d7d32aef |
|
| /// File Name: |
CA-96.27.hp_sw_install |
Description:
|
This advisory describes a vulnerability in Hewlett-Packard SD-UX that may allow local users to gain root privileges. A workaround is included.
| | File Size: | 12311 | | Last Modified: | Sep 14 07:49:13 1999 |
| MD5 Checksum: | 1b27c3c2249ae1e5db0efc2d690bd391 |
|
| /// File Name: |
CA-96.26.ping |
Description:
|
This advisory describes a denial-of-service attack using large ICMP datagrams issued via the ping command. Vendor information is included.
| | File Size: | 17445 | | Last Modified: | Sep 14 07:49:12 1999 |
| MD5 Checksum: | 9137b4491befe0c88a9116cd55124621 |
|
| /// File Name: |
CA-96.25.sendmail_groups |
Description:
|
The advisory describes a security problem affecting sendmail version 8 relating to group-writable files. Vendor patches and a workaround are included.
| | File Size: | 20528 | | Last Modified: | Sep 14 07:49:11 1999 |
| MD5 Checksum: | 8102a89180cbfbead6c31780fe9f69e6 |
|
| /// File Name: |
CA-96.24.sendmail.daemon.mode |
Description:
|
It describes a security problem relating to the daemon mode in sendmail 8.7 through 8.8.2. The advisory also includes a note about two vulnerabilities in versions 8.8.0 and 8.8.1; these have been fixed as well.
| | File Size: | 22770 | | Last Modified: | Sep 14 07:49:10 1999 |
| MD5 Checksum: | a3f743b790519cf675a1392e59e9963f |
|
| /// File Name: |
CA-96.23.workman_vul |
Description:
|
This advisory describes a vulnerability in the WorkMan compact disc-playing program that affects UNIX System V Release 4.0 and derivatives and Linux systems.
| | File Size: | 8274 | | Last Modified: | Sep 14 07:49:09 1999 |
| MD5 Checksum: | daf625258a6d66bfa1ce893de5b94451 |
|
| /// File Name: |
CA-96.22.bash_vuls |
Description:
|
This advisory addresses two problems with the GNU Project's Bourne Again SHell (bash): one in yy_string_get() and one in yy_readline_get().
| | File Size: | 10780 | | Last Modified: | Sep 14 07:49:06 1999 |
| MD5 Checksum: | 8faa3d5f2ef45f3d52ac8cc1473ecce1 |
|
| /// File Name: |
CA-96.21.tcp_syn_flooding |
Description:
|
** This advisory supersedes the IP spoofing portion of CA-95:01. ** It describes denial-of-service attacks through TCP SYN flooding and IP spoofing. Advice about filtering is included.
| | File Size: | 23015 | | Last Modified: | Sep 14 07:49:05 1999 |
| MD5 Checksum: | ad36afe8596aa155911012e3784d2dff |
|
| /// File Name: |
CA-96.20.sendmail_vul |
Description:
|
This advisory describes a vulnerability in all versions of sendmail prior to 8.7.6, and includes a workaround and patch information.
| | File Size: | 27176 | | Last Modified: | Sep 14 07:49:04 1999 |
| MD5 Checksum: | 4b21d5c259b9eeabe666aa2e03de41d6 |
|
| /// File Name: |
CA-96.19.expreserve |
Description:
|
** This advisory supersedes CA-93:09 and CA-93:09a. ** It provides information about a vulnerability in the expreserve utility. A workaround and vendor information are included.
| | File Size: | 13398 | | Last Modified: | Sep 14 07:49:03 1999 |
| MD5 Checksum: | 8d3886d64c9be44bbdb359769b9e509d |
|
| /// File Name: |
CA-96.18.fm_fls |
Description:
|
This advisory reports a configuration problem in the floating license server for Adobe FrameMaker (fm_fls). A workaround is provided.
| | File Size: | 9965 | | Last Modified: | Sep 14 07:49:01 1999 |
| MD5 Checksum: | b88e8b0a42f47e99afbdba8f0ed591b0 |
|
| /// File Name: |
CA-96.17.Solaris_vold_vul |
Description:
|
This advisory describes a vulnerability in the Solaris volume management daemon (vold) and gives a workaround.
| | File Size: | 9354 | | Last Modified: | Sep 14 07:49:00 1999 |
| MD5 Checksum: | 9867aa2570e793509ee624c76443b7cd |
|
| /// File Name: |
CA-96.16.Solaris_admintool_vul |
Description:
|
This advisory describes a vulnerability in the Solaris admintool and gives a workaround.
| | File Size: | 7923 | | Last Modified: | Sep 14 07:48:59 1999 |
| MD5 Checksum: | e41b47dc54c897ecaec484803242b278 |
|
| /// File Name: |
CA-96.15.Solaris_KCMS_vul |
Description:
|
This advisory describes a vulnerability in the Solaris 2.5 kcms programs and suggests a workaround.
| | File Size: | 7595 | | Last Modified: | Sep 14 07:48:58 1999 |
| MD5 Checksum: | 304756d15566abe3cb98ab1e36a13aa3 |
|
| /// File Name: |
CA-96.14.rdist_vul |
Description:
|
** This advisory supersedes CA-91:20 and CA-94:04. ** It describes a vulnerability in the lookup subroutine of rdist, for which an exploitation script is available. Vendor information and a pointer to a new version of rdist are included.
| | File Size: | 20215 | | Last Modified: | Sep 14 07:48:57 1999 |
| MD5 Checksum: | 2b428acbb9d7a24d412c24781d2b94c4 |
|
| /// File Name: |
CA-96.13.dip_vul |
Description:
|
This advisory describes a vulnerability in the dip program, which is shipped with most Linux systems. Other UNIX systems may also use it. Pointers to dip 3.3.7 are included.
| | File Size: | 6250 | | Last Modified: | Sep 14 07:48:56 1999 |
| MD5 Checksum: | 39dc2d085f5af3ec2049671e138e2c37 |
|
| /// File Name: |
CA-96.12.suidperl_vul |
Description:
|
This advisory describes a vulnerability in systems that contain the suidperl program and that support saved set-user-ID and saved set-group-ID. Patch information is included.
| | File Size: | 18082 | | Last Modified: | Sep 14 07:48:56 1999 |
| MD5 Checksum: | 9af14e27a03e76ff8d997d958d3404c1 |
|
| /// File Name: |
CA-96.11.interpreters_in_cgi_bin_di..> |
Description:
|
This advisory warns users not to put interpreters in a Web server's CGI bin directory and to evaluate all programs in that directory.
| | File Size: | 6693 | | Last Modified: | Sep 14 07:48:52 1999 |
| MD5 Checksum: | 981fa741bc747f79e3dee296c420a561 |
|
| /// File Name: |
CA-96.10.nis+_configuration |
Description:
|
This advisory was originally released as AUSCERT advisory AA-96.02a. It describes a vulnerability and workarounds for versions of NIS+ in which the access rights on the NIS+ passwd table are left in an unsecure state.
| | File Size: | 14851 | | Last Modified: | Sep 14 07:48:51 1999 |
| MD5 Checksum: | fd10eb63eb797fe3f5352e55ef3c65d5 |
|
| /// File Name: |
CA-96.09.rpc.statd |
Description:
|
This advisory describes a vulnerability in the rpc.statd (or statd) program that allows authorized users to remove or create any file that a root user can. Vendor information is included.
| | File Size: | 23289 | | Last Modified: | Sep 14 07:48:50 1999 |
| MD5 Checksum: | 9ff682c9fdf12c351153e421ee58982b |
|
| /// File Name: |
CA-96.08.pcnfsd |
Description:
|
This advisory describes a vulnerability in the pcnfsd program (also known as rpc.pcnfsd). A patch is included.
| | File Size: | 23804 | | Last Modified: | Sep 14 07:48:48 1999 |
| MD5 Checksum: | bcd858cf4118cb86cea659236576662e |
|
|
|
|
|