CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
556 | CVE-1999-0572 | Candidate | .reg files are associated with the Windows NT registry editor (regedit), making the registry susceptible to Trojan Horse attacks. | Modified (20041017) | ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | NOOP(2) Christey, Northcutt | Northcutt> I don"t quite get what this means, sorry | Frech> XF:nt-regfile(178) | Christey> MISC:http://security-archive.merton.ox.ac.uk/nt-security-199902/0087.html | View |
557 | CVE-1999-0575 | Candidate | A Windows NT system"s user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking. | Proposed (19990721) | ACCEPT(4) Christey, Ozancin, Shostack, Wall | MODIFY(1) Frech | RECAST(2) Baker, Northcutt | Northcutt> It isn"t a great truth that you should enable all or the above, if you | do you potentially introduce a vulnerbility of filling up the file | system with stuff you will never look at. | Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Christey> The list of event types is very useful for lookup. | Frech> XF:nt-system-audit | XF:nt-logon-audit | XF:nt-object-audit | XF:nt-privil-audit | XF:nt-process-audit | XF:nt-policy-audit | XF:nt-account-audit | CHANGE> [Baker changed vote from REVIEWING to RECAST] | View |
558 | CVE-1999-0576 | Candidate | A Windows NT system"s file audit policy does not log an event success or failure for security-critical files or directories. | Proposed (19990721) | ACCEPT(3) Baker, Shostack, Wall | MODIFY(2) Frech, Ozancin | REJECT(1) Northcutt | Northcutt> 1.) Too general are we ready to state what the security-critical files | and directories are | 2.) Does Ataris, Windows CE, PalmOS, Linux have such a capability | Ozancin> Some files and directories are clearly understood to be critical. Others are | unclear. We need to clarify that critical is. | Frech> XF:nt-object-audit | View |
559 | CVE-1999-0577 | Candidate | A Windows NT system"s file audit policy does not log an event success or failure for non-critical files or directories. | Proposed (19990721) | ACCEPT(2) Shostack, Wall | MODIFY(3) Baker, Frech, Ozancin | REJECT(1) Northcutt | Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Perhaps only failure should be logged. | Frech> XF:nt-object-audit | CHANGE> [Baker changed vote from REVIEWING to MODIFY] | Baker> Failure on non-critical files is what should be monitored. | View |
560 | CVE-1999-0578 | Candidate | A Windows NT system"s registry audit policy does not log an event success or failure for security-critical registry keys. | Proposed (19990721) | ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) Northcutt | Ozancin> with reservation | Again what is defined as critical | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228) | View |
Page 112 of 20943, showing 5 records out of 104715 total, starting on record 556, ending on 560