CVE List

Id CVE No. Status Description Phase Votes Comments Actions
966  CVE-1999-0986  Entry  The ping command in Linux 2.0.3x allows local users to cause a denial of service by sending large packets with the -R (record route) option.        View
967  CVE-1999-0987  Entry  Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.        View
968  CVE-1999-0988  Candidate  UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.  Modified (20000121-01)  ACCEPT(3) Baker, Blake, Cole | MODIFY(1) Frech | RECAST(1) Stracener | REVIEWING(1) Christey  Stracener> The pkg* programs pkgtrans, pkginfo, pkgcat, pkginstall, and pkgparam | can be used to mount etc/shadow printing attacks as a result of the | "dacread" permission (cf. /etc/security/tcb/privs). The procedural | differences between the individual exploits for each of these utilities | are therefore inconsequential. CVE-1999-0988 should be merged with | CVE-1999-0828. From the standpoint of maintaining consistency of the | level of abstraction used in CVE, the co-existence of CANS | 1999-0988/1999-0828 present two choices: either merge 0988 with 0828, or | split 0828 into 4 distinct candidates, keeping 0988 intact. Due to the | very small differences (in principle) between the exploits subsumed by | 0828 and 0988 and the shared dacread permissions of the pkg* suite, I | suggest a merge. Below is a summary of the data upon which my decision | was based. | utility exploit | -------- ---------------------------------- | pkgtrans --> symlink + dacread permission prob | pkginfo --> truss (debugging utility) in conjunction with pkginfio -d | etc/shadow. In this case, it captures the interaction between | pkginfo the shadow file. Once again: dacread. | pkgcat --> buffer overflow + dacread permission prob | pkginstall -> buffer overflow + dacread permission prob | pkgparam --> -f etc/shadow (works because of dacread). | Christey> This is a tough one. While there are few procedural | differences, one could view "assignment of an improper | permission" as a "class" of problems along the lines of | buffer overflows and the like. Just like some programs | were fine until they got turned into CGI scripts, this | could be an emerging pattern which should be given | consideration. Consider the Eyedog and scriptlet.typelib | ActiveX utilities being marked as safe for scripting | (CVE-1999-0668 and 0669). | | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a loosely | alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:unixware-pkgtrans-symlink  View
969  CVE-1999-0989  Entry  Buffer overflow in Internet Explorer 5 directshow filter (MSDXM.OCX) allows remote attackers to execute commands via the vnd.ms.radio protocol.        View
970  CVE-1999-0990  Candidate  Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.  Interim (19991229)  ACCEPT(3) Blake, Cole, Stracener | MODIFY(1) Frech | NOOP(1) Baker  Frech> XF:verbose-auth-identify-user(3804)  View

Page 194 of 20943, showing 5 records out of 104715 total, starting on record 966, ending on 970

Actions