CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
808 | CVE-1999-0828 | Candidate | UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission. | Modified (20000121-01) | ACCEPT(3) Armstrong, Baker, Stracener | MODIFY(2) Cole, Frech | REVIEWING(2) Christey, Prosser | Cole> This is BID 850. | Christey> See comments on CVE-1999-0988. Perhaps these two should be | merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a | loosely alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:sco-pkg-dacread-fileread | View |
968 | CVE-1999-0988 | Candidate | UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack. | Modified (20000121-01) | ACCEPT(3) Baker, Blake, Cole | MODIFY(1) Frech | RECAST(1) Stracener | REVIEWING(1) Christey | Stracener> The pkg* programs pkgtrans, pkginfo, pkgcat, pkginstall, and pkgparam | can be used to mount etc/shadow printing attacks as a result of the | "dacread" permission (cf. /etc/security/tcb/privs). The procedural | differences between the individual exploits for each of these utilities | are therefore inconsequential. CVE-1999-0988 should be merged with | CVE-1999-0828. From the standpoint of maintaining consistency of the | level of abstraction used in CVE, the co-existence of CANS | 1999-0988/1999-0828 present two choices: either merge 0988 with 0828, or | split 0828 into 4 distinct candidates, keeping 0988 intact. Due to the | very small differences (in principle) between the exploits subsumed by | 0828 and 0988 and the shared dacread permissions of the pkg* suite, I | suggest a merge. Below is a summary of the data upon which my decision | was based. | utility exploit | -------- ---------------------------------- | pkgtrans --> symlink + dacread permission prob | pkginfo --> truss (debugging utility) in conjunction with pkginfio -d | etc/shadow. In this case, it captures the interaction between | pkginfo the shadow file. Once again: dacread. | pkgcat --> buffer overflow + dacread permission prob | pkginstall -> buffer overflow + dacread permission prob | pkgparam --> -f etc/shadow (works because of dacread). | Christey> This is a tough one. While there are few procedural | differences, one could view "assignment of an improper | permission" as a "class" of problems along the lines of | buffer overflows and the like. Just like some programs | were fine until they got turned into CGI scripts, this | could be an emerging pattern which should be given | consideration. Consider the Eyedog and scriptlet.typelib | ActiveX utilities being marked as safe for scripting | (CVE-1999-0668 and 0669). | | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a loosely | alludes to this problem; the README for patch SSE053 | effectively confirms it. | Frech> XF:unixware-pkgtrans-symlink | View |
1625 | CVE-2000-0047 | Candidate | Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message. | Modified (20000202-01) | ACCEPT(2) Baker, Frech | NOOP(1) Williams | View | |
1624 | CVE-2000-0046 | Candidate | Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message. | Modified (20000204-01) | ACCEPT(2) Baker, Williams | MODIFY(1) Frech | Frech> ADDREF XF:icq-url-bo | View |
796 | CVE-1999-0816 | Candidate | The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024. | Modified (20000313-01) | ACCEPT(3) Baker, Cole, Stracener | MODIFY(1) Frech | NOOP(2) Christey, LeBlanc | Christey> This candidate is unconfirmed by the vendor. | Frech> XF:motorola-cable-default-pass | View |
Page 20377 of 20943, showing 5 records out of 104715 total, starting on record 101881, ending on 101885