|
CA-97.01 |
Vulnerabilities in UNIX FLEXlm
This advisory describes multi-platform UNIX FLEXlm vulnerabilities. These problems
may allow local users to create arbitrary files on the system and execute arbitrary programs
using the privileges of the user running the FLEXlm daemons.
|
|
CA-97.02 |
Vulnerability in newgrp(1) program
This advisory describes a vulnerability in the newgrp(1) program under HP-UX 9.x and
10.x that may allow users to gain root privileges. A workaround is provided.
|
|
CA-97.03 |
Vulnerability in csetup program
A vulnerability in the csetup program under IRIX versions 5.x, 6.0, 6.0.1, 6.1, and 6.2
allows local users to create or overwrite arbitrary files on the system and ultimately gain
root privileges. A workaround is provided.
|
|
CA-97.04 |
Vulnerability in talkd(8) program
A vulnerability in talkd(8) program used by talk(1) makes it possible to provide corrupt
DNS information to a host and to remotely execute arbitrary commands with root
privileges. This advisory includes information on how to solve the general problem as well
as the specific one.
|
|
CA-97.05 |
MIME conversion buffer overflow in sendmail versions in 8.8.3 and 8.8.4
This advisory addresses a MIME conversion buffer overflow in sendmail versions in 8.8.3
and 8.8.4. This advisory includes information, pointers to the latest version of sendmail, a
workaround, and general precautions to take when using sendmail.
|
|
CA-97.06 |
Vulnerability in rlogin program
This advisory reports a vulnerability in many implementations of the rlogin program,
including eklogin and klogin. Vendor information and a workaround are included.
|
|
CA-97.07 |
Vulnerability in the nph-test-cgi script
This advisory points out a vulnerability in the nph-test-cgi script included with some http
daemons. Readers are urged to disable the script. Vendor information is included.
|
|
CA-97.08 |
Vulnerabilities in INN
This advisory describes two vulnerabilities in the InterNetNews server (INN). One affects
versions 1.5 and earlier; the other affects 1.5.1 and earlier. This advisory includes pointers
to version 1.5.1 and earlier. Updated information on the second vulnerability was added as
"Topic 2." Pointers to all relevant patches are included, along with information from
vendors.
|
|
CA-97.09 |
Vulnerability in IMAP and POP
This advisory reports a vulnerability in some versions of the Internet Message Access
Protocol (IMAP) and Post Office Protocol (POP) implementations (imapd, ipop2d, and
ipop3d). Vendor and upgrade information are included.
|
|
CA-97.10 |
Buffer overflow in libraries using Natural Language Service (NLS)
This advisory reports a buffer overflow condition that affects some libraries using the
Natural Language Service (NLS). Vendor vulnerability and patch information are
included.
|
|
CA-97.11 |
Buffer overflow vulnerability in Xt library
This advisory reports a buffer overflow vulnerability in the Xt library of the X Windowing
System. Vendor vulnerability and patch information are included.
|
|
CA-97.12 |
Vulnerability in webdist.cgi-bin program
This advisory reports a vulnerability in the webdist.cgi-bin program, part of the IRIX
Mindshare Out Box package, available with IRIX 5.x and 6.x. By exploiting this
vulnerability, both local and remote users may be able to execute arbitrary commands with
the privileges of the httpd daemon. A workaround is included.
|
|
CA-97.13 |
Buffer overflow problem in xlock
This advisory reports a buffer overflow problem in some versions of xlock. This problem
makes it possible for local users to execute arbitrary programs as a privileged user. Patch
information and a workaround are included.
|
|
CA-97.14 |
Vulnerability in metamail
This advisory reports a vulnerability in metamail, a package that implements MIME. All
versions of metamail through 2.7 are vulnerable.
|
|
CA-97.15 |
Vulnerability in SGI login program
This advisory describes a vulnerability in the SGI login program when the LOCKOUT
parameter is set to a number greater than zero. The vulnerability is present in IRIS 5.3 and
6.2, and perhaps other versions.
|
|
CA-97.16 |
Vulnerability in ftpd
This advisory describes a vulnerability in some versions of ftpd distributed and installed
under various UNIX platforms. Includes vendor information.
|
|
CA-97.17 |
Buffer overflow in suidperl
This advisory addresses a buffer overflow condition in suidperl (sperl) built from Perl 4.n
and Perl 5.n distributions on UNIX systems. It suggests several solutions and includes
vendor information and a patch for Perl version 5.003.
|
|
CA-97.18 |
Buffer overflow in at(1) program
This advisory addresses a buffer overflow condition in some versions of the
at(1) program.
Patch information and a workaround are provided.
|
|
CA-97.19 |
Vulnerability in BSD-based lpr printing software
This advisory describes a vulnerability in BSD-based lpr printing software. Vendor
information and a pointer to a wrapper are included.
|
|
CA-97.20 |
Vulnerability in JavaScript
This advisory reports a vulnerability in JavaScript that enables remote attackers to monitor
a user's Web activities.
|
|
CA-97.21 |
Buffer overflow problems in SGI IRIS systems
In this advisory, we describe 6 buffer overflow problems in SGI IRIS systems. Problems
affect the df, pset, eject, login/scheme, ordist, and xlock programs. Workarounds and a
pointer to a wrapper are provided.
|
|
CA-97.22 |
Vulnerability in BIND
This advisory supersedes CA-96.02. It describes a vulnerability in all versions of BIND
before release 4.9.6, suggests several solutions, and provides pointers to the current version
of bind.
|
|
CA-97.23 |
Buffer overflow problem in rdist
This advisory discusses a buffer overflow problem in rdist. It is a different
vulnerability
from the one described in CA-96.14.
|
|
CA-97.24 |
Vulnerability in Count cgi
This advisory describes a buffer overrun vulnerability which exists in the Count.cgi cgi-bin
program that allows intruders to force Count.cgi to execute arbitrary commands.
|
|
CA-97.25 |
Vulnerability in CGI metachar
This advisory reports a vulnerability in some CGI scripts. This problem allows an attacker
to execute arbitrary commands on a WWW server under the effective user-id of the server
process.
|
|
CA-97.26 |
Vulnerability in statd (1M) program
This advisory reports a vulnerability that exists in the statd (1M) program, available on a
variety of Unix platforms.
|
|
CA-97.27 |
FTP Bounce
This advisory discusses the use of the PORT command in the FTP protocol.
|
|
CA-97.28 |
IP Denial-of-Service Attacks
This advisory reports on two IP denial-of-service attacks
|
|
VB-97.01 |
Division of Privilege (DoP) - Potential Security Vulnerability
Information from Digital concerning the discovery a potential vulnerability with the
Division of Privilege (DoP), "/usr/sbin/dop" for DIGITAL UNIX V4.0, V4.0A, and V4.0B,
where under certain circumstances, an unauthorized user many gain unauthorized
privileges. A workaround is provided.
|
|
VB-97.02 |
Security Hole in Guestbook Script for Web Servers Using SSI
Information from Selena Sol about a vulnerability in all versions of Selena Sol's
Guestbook.
|
|
VB-97.03 |
Vulnerability in rpcbind
Information from Sun Microsystems, Inc. about a vulnerability in the rpcbind program,
which can aid an attacker to gain unauthorized access if exploited. Patches are provided.
|
|
VB-97.04 |
Security Vulnerability in chfn executable
Information from Hewlett-Packard concerning a vulnerability with the chfn command. A
patch is provided.
|
|
VB-97.05 |
Vulnerability in Lynx Temporary Files
Information about a vulnerability in Lynx 2.7.1. Patches are provided.
|
|
VB-97.06 |
Vulnerability in Lynx Downloading
Information about a vulnerability in versions of Lynx up to and including version 2.7.1 on
Unix or Unix-like operating systems. A patch is provided.
|
|
VB-97.07 |
IRIX webdist.cgi, handler and wrap programs
Information from Silicon Graphics Inc. about a vulnerability with cgi-bin programs
webdist.cgi, handler and wrap available for IRIX 5.x and 6.x. A patch is provided.
|
|
VB-97.08 |
Vulnerability in Transarc DCE Integrated login for sites running both AFS and DCE
Information from Transarc Corp concerning a vulnerability in Transarc DCE Integrated
login for sites running both AFS and DCE. Patches are provided.
|
|
VB-97.09 |
Vulnerabilities in Cisco CHAP Authentication
Information from Cisco Systems about a vulnerability that exists in PPP CHAP
authentication in all "classic" Cisco IOS software versions starting with the introduction of
CHAP support in release 9.1(1) and a vulnerability that exists in Cisco IOS/700 software.
Workarounds are provided.
|
|
VB-97.10 |
Security bugfix for Samba
Information from the Samba Team about a security hole in all versions of Samba. A new
release of Samba is provided.
|
|
VB-97.11 |
Vulnerability in "nosuid" mount option
Information from NEC Corporation concerning a vulnerability in the "nosuid" mount
option. Patches are provided.
|
|
VB-97.12 |
Potential denial-of-service attack in the OSF/DCE security server
Information from The Open Group about a potential problem in the security serve that
could allow for a denial-of-service attack. A fix is provided.
|
|
VB-97.13 |
Vulnerability in GlimpseHTTP and WebGlimpse CGI scripts
Information from Project FUSE, University of Arizona concerning vulnerabilities in both
GlimpseHTTP and WebGlimpse. An upgrade is available.
|
|
VB-97.14 |
Vulnerability in /usr/bin/X11/scoterm
Information from Santa Cruz Operation, Inc. about a vulnerability in the implementation of
scoterm. Patches are provided.
|
|
VB-97.15 |
Vulnerability in nix_cachemgr
Information from Sun Microsystems, Inc. about a vulnerability in nix_cachemgr. Patches
are provided.
|
|
VB-97.16 |
CrackLib
A bug in CrackLib v2.5 may be exploitable to obtain root privileges when logged on
machines where CrackLib is installed as part of a SUID program, such as "/bin/passwd". A
upgrade or patch is available.
|
*CERT is registered in the U.S. Patent and Trademark Office
Copyright 1998 Carnegie Mellon University. Conditions for use, disclaimers,
and sponsorship information can be found in http://www.cert.org/legal_stuff.html.
If you do not have web access, send mail to cert@cert.org
with "copyright" in the subject line.