Section: .. / advisories / iss /
| /// File Name: |
iss.99-08-09.dos_nt |
Description:
|
iss.99-08-09.dos_nt
| | File Size: | 5470 | | Last Modified: | Aug 11 12:20:03 1999 |
| MD5 Checksum: | 7883b8fe5cb73137c51dbf8a7dfd32e2 |
|
| /// File Name: |
iss.98-11-16.snmp_update |
Description:
|
iss.98-11-16.snmp_update
| | File Size: | 5428 | | Last Modified: | Nov 24 19:20:41 1998 |
| MD5 Checksum: | 19bf60170a2defb913eb0ee209c02d77 |
|
| /// File Name: |
iss.01-10-16.citrix |
Description:
|
ISS Security Advisory - A remote denial of service vulnerability has been found in Citrix MetaFrame, an application server that works with Windows Terminal Services. This vulnerability causes a MetaFrame installation to crash or "blue screen" and requires an affected system to be restarted manually.
| | Homepage: | http://xforce.iss.net | | File Size: | 5334 | | Last Modified: | Oct 17 08:50:39 2001 |
| MD5 Checksum: | 34bb43b34fb59d9d774ba6785bc9b360 |
|
| /// File Name: |
iss.01-08-29.bsd-lpr |
Description:
|
ISS Security Advisory - A buffer overflow has been discovered in the line printer daemon of several BSD implementations. (in.lpd or lpd) A remote or local attacker can execute arbitrary code as root. The vulnerability presents itself when an attacker submits a specially crafted print job and then requests a display of the printer queue to trigger the overflow. Affected versions include OpenBSD CURRENT and earlier, FreeBSD 4.3 and earlier, NetBSD 1.5.1 and earlier, and BSD/OS 4.1 and earlier.
| | Homepage: | http://xforce.iss.net | | File Size: | 5297 | | Last Modified: | Aug 30 07:23:03 2001 |
| MD5 Checksum: | ffba09ec65000c193f64aff77c28366b |
|
| /// File Name: |
iss.00-11-01.netmon |
Description:
|
ISS Security Advisory - An exploitable buffer overflow has been found in Microsoft's Network Monitor utility. The vulnerability allows code to be executed on the remote computer with the privilege levels of the administrator. Windows NT, 2000, and SMS 1.2 and 2.0 are affected.
| | Homepage: | http://xforce.iss.net | | File Size: | 5296 | | Last Modified: | Nov 2 10:07:24 2000 |
| MD5 Checksum: | 54baa068b73b12eaea66d04aae2831f8 |
|
| /// File Name: |
iss.00-04-26.aix.frcactrl |
Description:
|
ISS Security Advisory - Insecure file handling in IBM AIX frcactrl program. X-Force has discovered a vulnerability in the AIX frcactrl program. The Fast Response Cache Accelerator (FRCA) is a kernel module that can be used with the IBM HTTP server to improve the performance of a web server. If the FRCA module is loaded, a local attacker could use frcactrl, a program used to manage FRCA configuration, to modify files and/or gain root privileges.
| | Homepage: | http://xforce.iss.net | | File Size: | 5285 | | Last Modified: | Apr 26 23:06:48 2000 |
| MD5 Checksum: | 6566a16424151c35b034e6c7b6e2c165 |
|
| /// File Name: |
iss.smb-dos.txt |
Description:
|
ISS Security Advisory - Windows NT, 2000, and XP can be crashed remotely by sending a malformed packet to port 139, triggering a heap overflow. Exploit available. All affected versions of the Windows operating system are configured with the vulnerable service enabled by default. Includes snort rule. MS security bulletin for this bug is MS02-045.
| | Homepage: | http://www.iss.net/security_center | | File Size: | 5124 | | Related CVE(s): | CAN-2002-0724 | | Last Modified: | Aug 30 20:50:36 2002 |
| MD5 Checksum: | c1a41e51ef34733065164f72ef91735d |
|
| /// File Name: |
iss.99-12-01.fastrack |
Description:
|
ISS as discovered a vulnerability in Netscape Enterprise Server and Netscape FastTrack Server, as well as in the Administration Server supplied with both. There is a buffer overflow in the HTTP Basic Authentication that can be used to execute code on the machine as SYSTEM in Windows NT or as root or nobody in Unix, without requiring authentication. This vulnerability affects all supported platforms of Enterprise and FastTrack web servers. Enterprise 3.5.1 through 3.6sp2 and FastTrack 3.01 were found to be vulnerable.
| | File Size: | 5010 | | Last Modified: | Dec 2 21:40:01 1999 |
| MD5 Checksum: | 544f2f49866b1c58985e30ef3c7852c2 |
|
| /// File Name: |
iss.99-12-12.snoop |
Description:
|
ISS has discovered a remotely exploitable buffer overflow condition in the Solaris Snoop application. Snoop is a network sniffing tool that ships with all Solaris 2.x operating systems. This overflow allows a knowledgeable attacker to seize control of the Snoop application. Solaris 2.4, 2.5, 2.5.1, 2.6, and 2.7 were found to be vulnerable. Patches available here.
| | File Size: | 5006 | | Last Modified: | Dec 14 01:30:54 1999 |
| MD5 Checksum: | fa51995314eee09ba2549218fdb3ebd3 |
|
| /// File Name: |
iss.98-09-01.webcam32 |
Description:
|
iss.98-09-01.webcam32
| | File Size: | 4965 | | Last Modified: | Sep 4 12:01:00 1998 |
| MD5 Checksum: | dcba1ec8058e0b6e47464a0b723caf9e |
|
| /// File Name: |
iss.00-03-14.stick |
Description:
|
The Stick ddos tool overloads IDS systems with false positives, causing them to fail. Paper on stick available here.
| | Homepage: | http://xforce.iss.net | | File Size: | 4919 | | Last Modified: | Mar 16 23:42:14 2001 |
| MD5 Checksum: | 8288054dff36679726c41d2a59603aa4 |
|
| /// File Name: |
iss.01-11-20.rlpdaemon |
Description:
|
ISS Security Advisory - ISS X-Force has discovered a vulnerability in the HP-UX line printer daemon (rlpdaemon) that allows a remote or local user to execute arbitrary code with root privileges. Affected versions include HP-UX 10.01, 10.10, 10.20, 11.00, and 11.11.
| | Homepage: | http://www.iss.net/xforce | | File Size: | 4862 | | Last Modified: | Nov 21 00:19:37 2001 |
| MD5 Checksum: | 43096382e2e5ba6caf7ba296e2418260 |
|
| /// File Name: |
iss.99-03-24.dos.cisco |
Description:
|
iss.99-03-24.dos.cisco
| | File Size: | 4837 | | Last Modified: | Mar 25 08:35:56 1999 |
| MD5 Checksum: | dabe6cacfedf2e60cb4ae5369bf512e4 |
|
| /// File Name: |
iss.97-10-21.scheduler_winlogin_key..> |
Description:
|
iss.97-10-21.scheduler_winlogin_keys
| | File Size: | 4801 | | Last Modified: | Oct 23 19:41:56 1997 |
| MD5 Checksum: | 24b7fd453e9fa2d26d4bacf80e898758 |
|
| /// File Name: |
iss.99-03-31.webramp |
Description:
|
iss.99-03-31.webramp
| | File Size: | 4752 | | Last Modified: | Apr 2 10:44:37 1999 |
| MD5 Checksum: | e0c0519e1b2b0593ca0b490688507ac1 |
|
| /// File Name: |
iss.99-03-15.ldap |
Description:
|
iss.99-03-15.ldap
| | File Size: | 4698 | | Last Modified: | Mar 17 01:22:29 1999 |
| MD5 Checksum: | 0f3605eb09be68933872f6d62a61bdfe |
|
| /// File Name: |
iss.01-08-27.hp.lpr |
Description:
|
ISS Security Advisory - A buffer overflow has been discovered in the HP-UX line printer daemon (rlpdaemon) which allows a remote or local attacker to execute arbitrary code with superuser privilege. Affected versions include HP-UX 10.01, 10.10, 10.20, 11.00, and 11.11. Rlpdaemon is configured to run by default even if it is not being used.
| | Homepage: | http://xforce.iss.net | | File Size: | 4684 | | Last Modified: | Aug 28 08:55:03 2001 |
| MD5 Checksum: | 225386c3d3c624544ff8d532276ffa41 |
|
| /// File Name: |
iss.99-06-17.iis_htr |
Description:
|
iss.99-06-17.iis_htr
| | File Size: | 4676 | | Last Modified: | Jun 18 11:22:40 1999 |
| MD5 Checksum: | bdbbb3bd3b777f6cf3ebd1a19c9127b0 |
|
| /// File Name: |
iss.99-01-18.backweb.protocol |
Description:
|
iss.99-01-18.backweb.protocol
| | File Size: | 4647 | | Last Modified: | Feb 1 02:23:56 1999 |
| MD5 Checksum: | 2ded6a9597ed1f65e18851320932c16d |
|
| /// File Name: |
iss.00-06-20.aix-cdmount |
Description:
|
Internet Security Systems Security Advisory - The AIX cdmount program is a SUID to root wrapper of the mount command. Insecure handling of the arguments to cdmount may allow a local regular user to execute commands as root. AIX systems with the LPP UMS.objects 2.3.0.0 and below installed are vulnerable.
| | Homepage: | http://xforce.iss.net | | File Size: | 4633 | | Last Modified: | Jun 21 21:31:22 2000 |
| MD5 Checksum: | 5f97a08dbf0dfbe2e6e33491d8528ab0 |
|
| /// File Name: |
iss.00-10-25.oracle |
Description:
|
ISS Security Advisory - Oracle listener program releases 7.3.4, 8.0.6, and 8.1.6 on all platforms contains remote vulnerabilities which allow an attacker to gain access to an operating system account. Fix available here.
| | Author: | Ben Layer and Aaron Newman | | Homepage: | http://xforce.iss.net | | File Size: | 4629 | | Last Modified: | Oct 27 09:22:56 2000 |
| MD5 Checksum: | d68a5327986ff62710b677cf2379e499 |
|
| /// File Name: |
iss.99-06-09.k-mail |
Description:
|
iss.99-06-09.k-mail
| | File Size: | 4505 | | Last Modified: | Jun 10 12:57:35 1999 |
| MD5 Checksum: | e63860221b430512e05d7dabc2d61642 |
|
| /// File Name: |
iss.99-08-25.netscape |
Description:
|
iss.99-08-25.netscape
| | File Size: | 4395 | | Last Modified: | Sep 1 03:52:19 1999 |
| MD5 Checksum: | b7e5b70a03a39b07a9bb969278b88138 |
|
| /// File Name: |
iss.98-08-31.exec_dirs_iis |
Description:
|
iss.98-08-31.exec_dirs_iis
| | File Size: | 4198 | | Last Modified: | Sep 4 12:00:59 1998 |
| MD5 Checksum: | 413ccead4ac8a0f5f1b155a637191d95 |
|
| /// File Name: |
iss.99-08-23.lotus_dos |
Description:
|
iss.99-08-23.lotus_dos
| | File Size: | 4064 | | Last Modified: | Aug 23 19:26:19 1999 |
| MD5 Checksum: | a5a311167f7bae5b555d992e2df64d64 |
|
|
|
|
|