Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-95:09.Solaris.ps.vul |
Description:
|
This advisory describes a vulnerability in Solaris that can be exploited if the permissions on the /tmp and /var/tmp directories are set incorrectly.
| | File Size: | 13835 | | Last Modified: | Sep 14 07:48:28 1999 |
| MD5 Checksum: | 65b36a02be742c26067752c254b2f4ba |
|
| /// File Name: |
CA-95:10.ghostscript |
Description:
|
This advisory describes a vulnerability involving the -dSAFER option in ghostscript versions 2.6 through 3.22 beta. The advisory includes instructions for fixing the problem and pointers to version 3.33 of ghostscript.
| | File Size: | 15940 | | Last Modified: | Sep 14 07:48:34 1999 |
| MD5 Checksum: | fd4023068d8fe25142b6ca2995ddba00 |
|
| /// File Name: |
CA-95:12.sun.loadmodule.vul |
Description:
|
The advisory describes a problem with the loadmodule(8) program in Sun OS 4.1.X and provides patch information.
| | File Size: | 7355 | | Last Modified: | Sep 14 07:48:35 1999 |
| MD5 Checksum: | 79afb161722955323b933949d7614a4c |
|
| /// File Name: |
CA-95:13.syslog.vul |
Description:
|
This advisory describes a general problem with syslog, lists vendor information about patches, and provides a workaround for solving the syslog problem in sendmail in particular.
| | File Size: | 22867 | | Last Modified: | Sep 14 07:48:36 1999 |
| MD5 Checksum: | e39dfff9daefd95c7120a4e998abb18f |
|
| /// File Name: |
CA-95:14.Telnetd_Environment_Vulner..> |
Description:
|
This advisory describes a vulnerability with some telnet daemons and includes patch information from vendors, along with a workaround.
| | File Size: | 26674 | | Last Modified: | Sep 14 07:48:37 1999 |
| MD5 Checksum: | 06ab579e8768524b339184aca88c75eb |
|
| /// File Name: |
CA-95:15.SGI.lp.vul |
Description:
|
This advisory points out accounts that are distributed without passwords and urges SGI customers to create passwords for those accounts.
| | File Size: | 10923 | | Last Modified: | Sep 14 07:48:38 1999 |
| MD5 Checksum: | d71b2dbd6f3758ceb50ca382bd593960 |
|
| /// File Name: |
CA-95:16.wu-ftpd.vul |
Description:
|
This advisory describes a vulnerability in the wu-fptd SITE EXEC command and provides solutions for both Linux users and others.
| | File Size: | 13838 | | Last Modified: | Sep 14 07:48:39 1999 |
| MD5 Checksum: | 75e31876631fbf4054469904a5686ed3 |
|
| /// File Name: |
CA-95:17.rpc.ypupdated.vul |
Description:
|
This advisory describes a vulnerability in the rpc.ypupdated program, for which an exploitation program has been posted to several newsgroups. The advisory includes vendor information and a workaround.
| | File Size: | 13439 | | Last Modified: | Sep 14 07:48:40 1999 |
| MD5 Checksum: | 5aa3b22aefdb2606fbc498669eed6b6a |
|
| /// File Name: |
CA-95:18.widespread.attacks |
Description:
|
This advisory warns readers of attacks on hundreds of Internet sites in which intruders exploit known vulnerabilities, all of which have been addressed in previous CERT advisories. These advisories are listed.
| | File Size: | 19834 | | Last Modified: | Sep 14 07:48:41 1999 |
| MD5 Checksum: | 5137a730a6a4957f38a847de0e2c1efa |
|
| /// File Name: |
CA-96.01.UDP_service_denial |
Description:
|
This advisory describes UDP port denial-of-service attacks, for which an exploitation script has been publicly posted. The advisory includes a workaround.
| | File Size: | 8660 | | Last Modified: | Sep 14 07:48:42 1999 |
| MD5 Checksum: | 84d727d432dec2f3eea22b7cd940b707 |
|
| /// File Name: |
CA-96.03.kerberos_4_key_server |
Description:
|
This advisory describes a problem with the Kerberos 4 key server, points to patches, and provides vendor information.
| | File Size: | 10840 | | Last Modified: | Sep 14 07:48:43 1999 |
| MD5 Checksum: | 2d2b8d87bd0cf809d613af6612b08bad |
|
| /// File Name: |
CA-96.04.corrupt_info_from_servers |
Description:
|
This advisory describes a vulnerability in network servers that can lead to corrupt information. The advisory includes information on subroutines for validating host names and IP addresses, patches for sendmail, and the status of vendor activity relating to the problem.
| | File Size: | 21012 | | Last Modified: | Sep 14 07:48:44 1999 |
| MD5 Checksum: | a48de544f6e0dd0dd81a0351bb9f1aea |
|
| /// File Name: |
CA-96.05.java_applet_security_mgr |
Description:
|
This advisory describes a vulnerability in the Netscape Navigator 2.0 Java implementation and in Release 1.0 of the Java Developer's Kit from Sun Microsystems, Inc. Workarounds and pointers to a patch are included.
| | File Size: | 7565 | | Last Modified: | Sep 14 07:48:45 1999 |
| MD5 Checksum: | 7e68bb2199001dbc6939c982b95d9253 |
|
| /// File Name: |
CA-96.06.cgi_example_code |
Description:
|
This advisory describes a problem with example CGI code, as found in
| | File Size: | 13572 | | Last Modified: | Sep 14 07:48:46 1999 |
| MD5 Checksum: | 958b610082eec2ac8a1f42656fa7df54 |
|
| /// File Name: |
CA-96.07.java_bytecode_verifier |
Description:
|
This advisory describes a vulnerability in the Java bytecode verifier portion of Sun Microsystems' Java Development Kit (JDK) 1.0 and 1.0.1. Workarounds are provided for this product and Netscape Navigator 2.0 and 2.01, which have the JDK built in.
| | File Size: | 9300 | | Last Modified: | Sep 14 07:48:47 1999 |
| MD5 Checksum: | 605c3f42617f758bbfadf017b380aa54 |
|
| /// File Name: |
CA-96.08.pcnfsd |
Description:
|
This advisory describes a vulnerability in the pcnfsd program (also known as rpc.pcnfsd). A patch is included.
| | File Size: | 23804 | | Last Modified: | Sep 14 07:48:48 1999 |
| MD5 Checksum: | bcd858cf4118cb86cea659236576662e |
|
| /// File Name: |
CA-96.09.rpc.statd |
Description:
|
This advisory describes a vulnerability in the rpc.statd (or statd) program that allows authorized users to remove or create any file that a root user can. Vendor information is included.
| | File Size: | 23289 | | Last Modified: | Sep 14 07:48:50 1999 |
| MD5 Checksum: | 9ff682c9fdf12c351153e421ee58982b |
|
| /// File Name: |
CA-96.10.nis+_configuration |
Description:
|
This advisory was originally released as AUSCERT advisory AA-96.02a. It describes a vulnerability and workarounds for versions of NIS+ in which the access rights on the NIS+ passwd table are left in an unsecure state.
| | File Size: | 14851 | | Last Modified: | Sep 14 07:48:51 1999 |
| MD5 Checksum: | fd10eb63eb797fe3f5352e55ef3c65d5 |
|
| /// File Name: |
CA-96.11.interpreters_in_cgi_bin_di..> |
Description:
|
This advisory warns users not to put interpreters in a Web server's CGI bin directory and to evaluate all programs in that directory.
| | File Size: | 6693 | | Last Modified: | Sep 14 07:48:52 1999 |
| MD5 Checksum: | 981fa741bc747f79e3dee296c420a561 |
|
| /// File Name: |
CA-96.12.suidperl_vul |
Description:
|
This advisory describes a vulnerability in systems that contain the suidperl program and that support saved set-user-ID and saved set-group-ID. Patch information is included.
| | File Size: | 18082 | | Last Modified: | Sep 14 07:48:56 1999 |
| MD5 Checksum: | 9af14e27a03e76ff8d997d958d3404c1 |
|
| /// File Name: |
CA-96.13.dip_vul |
Description:
|
This advisory describes a vulnerability in the dip program, which is shipped with most Linux systems. Other UNIX systems may also use it. Pointers to dip 3.3.7 are included.
| | File Size: | 6250 | | Last Modified: | Sep 14 07:48:56 1999 |
| MD5 Checksum: | 39dc2d085f5af3ec2049671e138e2c37 |
|
| /// File Name: |
CA-96.14.rdist_vul |
Description:
|
** This advisory supersedes CA-91:20 and CA-94:04. ** It describes a vulnerability in the lookup subroutine of rdist, for which an exploitation script is available. Vendor information and a pointer to a new version of rdist are included.
| | File Size: | 20215 | | Last Modified: | Sep 14 07:48:57 1999 |
| MD5 Checksum: | 2b428acbb9d7a24d412c24781d2b94c4 |
|
| /// File Name: |
CA-96.15.Solaris_KCMS_vul |
Description:
|
This advisory describes a vulnerability in the Solaris 2.5 kcms programs and suggests a workaround.
| | File Size: | 7595 | | Last Modified: | Sep 14 07:48:58 1999 |
| MD5 Checksum: | 304756d15566abe3cb98ab1e36a13aa3 |
|
| /// File Name: |
CA-96.16.Solaris_admintool_vul |
Description:
|
This advisory describes a vulnerability in the Solaris admintool and gives a workaround.
| | File Size: | 7923 | | Last Modified: | Sep 14 07:48:59 1999 |
| MD5 Checksum: | e41b47dc54c897ecaec484803242b278 |
|
| /// File Name: |
CA-96.17.Solaris_vold_vul |
Description:
|
This advisory describes a vulnerability in the Solaris volume management daemon (vold) and gives a workaround.
| | File Size: | 9354 | | Last Modified: | Sep 14 07:49:00 1999 |
| MD5 Checksum: | 9867aa2570e793509ee624c76443b7cd |
|
|
|
|
|