CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
558 | CVE-1999-0576 | Candidate | A Windows NT system"s file audit policy does not log an event success or failure for security-critical files or directories. | Proposed (19990721) | ACCEPT(3) Baker, Shostack, Wall | MODIFY(2) Frech, Ozancin | REJECT(1) Northcutt | Northcutt> 1.) Too general are we ready to state what the security-critical files | and directories are | 2.) Does Ataris, Windows CE, PalmOS, Linux have such a capability | Ozancin> Some files and directories are clearly understood to be critical. Others are | unclear. We need to clarify that critical is. | Frech> XF:nt-object-audit | View |
559 | CVE-1999-0577 | Candidate | A Windows NT system"s file audit policy does not log an event success or failure for non-critical files or directories. | Proposed (19990721) | ACCEPT(2) Shostack, Wall | MODIFY(3) Baker, Frech, Ozancin | REJECT(1) Northcutt | Ozancin> It is far less interesting what a user does successfully that what they | attempt and fail at. | Perhaps only failure should be logged. | Frech> XF:nt-object-audit | CHANGE> [Baker changed vote from REVIEWING to MODIFY] | Baker> Failure on non-critical files is what should be monitored. | View |
560 | CVE-1999-0578 | Candidate | A Windows NT system"s registry audit policy does not log an event success or failure for security-critical registry keys. | Proposed (19990721) | ACCEPT(4) Baker, Ozancin, Shostack, Wall | MODIFY(1) Frech | REJECT(1) Northcutt | Ozancin> with reservation | Again what is defined as critical | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228) | View |
561 | CVE-1999-0579 | Candidate | A Windows NT system"s registry audit policy does not log an event success or failure for non-critical registry keys. | Proposed (19990721) | ACCEPT(3) Baker, Shostack, Wall | MODIFY(2) Frech, Ozancin | REJECT(1) Northcutt | Ozancin> Again only failure may be of interest. It would be impractical to wad | through the incredibly large amount of logging that this would generate. It | could overwhelm log entries that you might find interesting. | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:nt-object-audit(228) | View |
564 | CVE-1999-0582 | Candidate | A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc. | Proposed (19990721) | ACCEPT(3) Ozancin, Shostack, Wall | MODIFY(2) Baker, Frech | REJECT(1) Northcutt | Northcutt> The definition is? | Baker> Maybe a rewording of this one too. I think most people would agree on | some "minimum" policies like 3-5 bad attempts lockout for an hour or | until the administrator unlocks the account. | Suggested rewrite - | A Windows NT account policy does not enforce reasonable minimum | security-critical settings for lockouts, e.g. lockout duration, | lockout after bad logon attempts, etc. | Ozancin> with reservations | What is appropriate? | Frech> XF:nt-thres-lockout | XF:nt-lock-duration | XF:nt-lock-window | XF:nt-perm-lockout | XF:lockout-disabled | View |
Page 20526 of 20943, showing 5 records out of 104715 total, starting on record 102626, ending on 102630