Section: .. / advisories / cert /
|
See the CERT website for more information.
|
| /// File Name: |
CA-93:04a.Amiga.finger.vulnerabilit..> |
Description:
|
A vulnerability is present in the "finger" program of Commodore Business Machine's Amiga UNIX product and affects Commodore Amiga UNIX versions 1.1, 2.03, 2.1, 2.1p1, 2.1p2, and 2.1p2a. This advisory details the availability of a patch for the problem and provides a suggested workaround.
| | File Size: | 4243 | | Last Modified: | Sep 14 07:47:20 1999 |
| MD5 Checksum: | 92996075b41c4871012662f59512a237 |
|
| /// File Name: |
CA-90:05.sunselection.vulnerability |
Description:
|
Vulnerability in SunOS 3.*, 4.0.3, and 4.1 SunView selection_svc facility.
| | File Size: | 4221 | | Last Modified: | Sep 14 07:46:27 1999 |
| MD5 Checksum: | c77f37521a83c42be1426213198c04f7 |
|
| /// File Name: |
CA-94:03.AIX.performance.tools |
Description:
|
Vulnerabilities are present in the bosext1.extcmds.obj performance tools in AIX 3.2.5 and in those AIX 3.2.4 systems with Program Temporary Fixes (PTFs) U420020 or U422510 installed. These problems do not exist in earlier versions of AIX.
| | File Size: | 4211 | | Last Modified: | Sep 14 07:47:49 1999 |
| MD5 Checksum: | 7f60181a7324819de628de8c56a850ab |
|
| /// File Name: |
CA-92:04.ATT.rexecd.vulnerability |
Description:
|
A vulnerability is present in AT&T TCP/IP Release 4.0 running on SVR4 systems for both the 386/486 and 3B2 RISC platforms. The problem is in the remote execution server /usr/etc/rexecd and a new version of rexecd is available from AT&T.
| | File Size: | 4160 | | Last Modified: | Sep 14 07:47:01 1999 |
| MD5 Checksum: | d3ba20fb3622c0b329d3551682a0bfd1 |
|
| /// File Name: |
CA-99-09-arrayd.txt |
Description:
|
A vulnerability has been discovered in the default configuration of the Array Services daemon, arrayd.
| | File Size: | 4128 | | Last Modified: | Sep 14 07:50:13 1999 |
| MD5 Checksum: | cece6b185b6f25f138d0a8f42294ea0f |
|
| /// File Name: |
CA-92:07.AIX.passwd.vulnerability |
Description:
|
A vulnerability is present in the passwd command in AIX 3.2 and the 2007 update of AIX 3.1. The advisory describes how to disable the /bin/passwd until you obtain and install the patch for the problem from IBM.
| | File Size: | 4128 | | Last Modified: | Sep 14 07:47:03 1999 |
| MD5 Checksum: | 699527f4dfef4f1c7f2da802c4f5ffb5 |
|
| /// File Name: |
CA-99-07-IIS-Buffer-Overflow.txt |
Description:
|
A buffer overflow vulnerability in Microsoft Internet Information Server (IIS) 4.0.
| | File Size: | 4092 | | Last Modified: | Sep 14 07:50:12 1999 |
| MD5 Checksum: | ecdd3f781bdc654c5a0b2947e00b641c |
|
| /// File Name: |
CA-90:11.Security.Probes |
Description:
|
Many sites on the Internet received messages on Sunday, December 9. The messages stated that a group of researchers and students were testing for a "common bug" in network hosts.
| | File Size: | 4071 | | Last Modified: | Sep 14 07:46:44 1999 |
| MD5 Checksum: | 48145666c9cca036d27ee5b6d655b788 |
|
| /// File Name: |
CA-92:08.SGI.lp.vulnerability |
Description:
|
A vulnerability is present in the default configuration of the lp software in Silicon Graphics Computer Systems (SGI) IRIX operating systems. This vulnerability is present in all versions of IRIX, prior to IRIX 4.0.5. The advisory describes how to reconfigure the lp software in order to eliminate this vulnerability.
| | File Size: | 3993 | | Last Modified: | Sep 14 07:47:04 1999 |
| MD5 Checksum: | 3055eb9fbbc387504330f7387dac02cc |
|
| /// File Name: |
CA-91:06.NeXTstep.vulnerability |
Description:
|
Addresses three vulnerabilities in NeXT systems running various versions of NeXTstep. Affected are: rexd(8C), /private/etc, username "me".
| | File Size: | 3983 | | Last Modified: | Sep 14 07:46:48 1999 |
| MD5 Checksum: | 79da7369f700994ed8a6de546e62ce42 |
|
| /// File Name: |
CA-91:14.IRIX.mail.vulnerability |
Description:
|
Vulnerability regarding the handling of mail messages on all Silicon Graphics IRIX Systems prior to version 4.0. The problem is fixed in version 4.0. Solution involves changing permissions and ownership of a system command.
| | File Size: | 3964 | | Last Modified: | Sep 14 07:46:54 1999 |
| MD5 Checksum: | 10ddd18e99e6aafb9cacdaaf43db0ab6 |
|
| /// File Name: |
CA-91:11.Ultrix.LAT-Telnet.gateway...> |
Description:
|
Vulnerability in Ultrix LAT/Telnet gateway software on all Ultrix 4.1 and 4.2 systems. Patch available directly from DEC.
| | File Size: | 3929 | | Last Modified: | Sep 14 07:46:53 1999 |
| MD5 Checksum: | a809e64a1d29d98d4b7917e572aa885b |
|
| /// File Name: |
CA-91:17.DECnet-Internet.Gateway.vu..> |
Description:
|
Vulnerability in Ultrix DECnet to Internet gateway software. This advisory details a workaround. The vulnerability affects Ultrix versions 4.0, 4.1, and 4.2.
| | File Size: | 3905 | | Last Modified: | Sep 14 07:46:55 1999 |
| MD5 Checksum: | 5a12a141a9d10c63766a1bd28197ba08 |
|
| /// File Name: |
CA-90:03.unisys.warning |
Description:
|
Warning about Unisys U5000 systems. Some of the logins supplied when the system was shipped did not have passwords, and intruders were taking advantage of this vulnerability.
| | File Size: | 3869 | | Last Modified: | Sep 14 07:46:26 1999 |
| MD5 Checksum: | 8d00333dfd6ff45c9e356a33baadda34 |
|
| /// File Name: |
CA-89:05.ultrix3.0.hole |
Description:
|
Warning about attacks on DEC/Ultrix 3.0 machines. Advises users to check for Trojan horses, insecure tftp, simple passwords.
| | File Size: | 3830 | | Last Modified: | Sep 14 07:46:23 1999 |
| MD5 Checksum: | 875a123062dfaadaed19342c540fc114 |
|
| /// File Name: |
rdist-patch-status |
Description:
|
rdist-patch-status
| | File Size: | 3739 | | Last Modified: | Sep 14 07:50:19 1999 |
| MD5 Checksum: | c1c6e4b281e0345d83173b045d338b06 |
|
| /// File Name: |
CA-92:05.AIX.REXD.Daemon.vulnerabil..> |
Description:
|
The rexd daemon may be enabled by default in versions 3.1 and 3.2 of AIX for IBM RS/6000 machines. The advisory describes a fix for the problem and details how to obtain a patch for the problem from IBM.
| | File Size: | 3734 | | Last Modified: | Sep 14 07:47:02 1999 |
| MD5 Checksum: | 12755620942eeeceebec51a51a8de967 |
|
| /// File Name: |
CA-89:02.sun.restore.hole |
Description:
|
Vulnerability in SunOS 4.0.* restore(8) command.
| | File Size: | 3678 | | Last Modified: | Sep 14 07:46:21 1999 |
| MD5 Checksum: | cc9fa31c90d14c28431acbd58b135dca |
|
| /// File Name: |
CA-91:12.Trusted.Hosts.Configuratio..> |
Description:
|
Vulnerability in MANY Unix systems regarding the use of a minus sign ("-") as the first character in any hosts.equiv hosts.lpd, and/or .rhosts files. Workaround is to re-arrange the lines in these files such that the "-" is not the first character in the file.
| | File Size: | 3668 | | Last Modified: | Sep 14 07:46:53 1999 |
| MD5 Checksum: | ccb7cd77efe8fdde74a8ec822a9cafd2 |
|
| /// File Name: |
CA-92:09.AIX.anonymous.ftp.vulnerab..> |
Description:
|
A vulnerability is present in the anonymous FTP configuration in all versions of AIX. The advisory describes how to obtain a patch for the problem from IBM.
| | File Size: | 3648 | | Last Modified: | Sep 14 07:47:04 1999 |
| MD5 Checksum: | c327e23425406aeb8d6ff31645700f69 |
|
| /// File Name: |
CA-93:19.Solaris.Startup.vulnerabil..> |
Description:
|
Information about a vulnerability in the system startup scripts on Solaris 2.x and Solaris x86 systems.
| | File Size: | 3637 | | Last Modified: | Sep 14 07:47:39 1999 |
| MD5 Checksum: | 981b2e945dac996d775ce8c2bd61066f |
|
| /// File Name: |
CA-91:08.systemV.login.vulnerabilit..> |
Description:
|
Addresses a vulnerability in all System V Release 4 versions of /bin/login. Patch provided by AT&T.
| | File Size: | 3600 | | Last Modified: | Sep 14 07:46:49 1999 |
| MD5 Checksum: | 265a1e6a9d41917c2673bd365d5c9d5d |
|
| /// File Name: |
CA-92:01.NeXTstep.configuration.vul..> |
Description:
|
A vulnerability is present in the default configuration in release 2 of NeXTstep's NetInfo. The advisory indicates where a description of how to configure NetInfo correctly can be obtained.
| | File Size: | 3414 | | Last Modified: | Sep 14 07:46:59 1999 |
| MD5 Checksum: | 24df072134fc112a28ee5f133caebabe |
|
| /// File Name: |
CA-92:06.AIX.uucp.vulnerability |
Description:
|
A vulnerability is present in the UUCP software in versions of AIX up to 2007. The advisory describes how to disable UUCP and details how to obtain a patch for the problem from IBM.
| | File Size: | 3407 | | Last Modified: | Sep 14 07:47:02 1999 |
| MD5 Checksum: | 09ca47688a4d9eb08ddd5bbb96a6c363 |
|
| /// File Name: |
CA-91:05.Ultrix.chroot.vulnerabilit..> |
Description:
|
Corrects improper installation of /usr/bin/chroot for Ultrix versions 4.0 and 4.1.
| | File Size: | 2963 | | Last Modified: | Sep 14 07:46:48 1999 |
| MD5 Checksum: | e3ef49c71cce529ec4f264d0c1970705 |
|
|
|
|
|