CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
105 | CVE-1999-0105 | Candidate | finger allows recursive searches by using a long string of @ symbols. | Proposed (19990726) | MODIFY(3) Baker, Frech, Shostack | NOOP(1) Christey | REJECT(1) Northcutt | Shostack> fingerD | Frech> XF:finger-bomb | Christey> aka redirection or forwarding requests? (but then might | overlap CVE-1999-0106) | Baker> should change description to indicate the recursive searching can consume enough system resources to cause a DoS. | View |
106 | CVE-1999-0106 | Candidate | Finger redirection allows finger bombs. | Proposed (19990726) | ACCEPT(1) Northcutt | MODIFY(2) Frech, Shostack | RECAST(1) Baker | REVIEWING(1) Christey | Shostack> fingerd allows redirection | This is a larger modification, since there are two applications of the | vulnerability, one that I can finger anonymously, and the other that I | can finger bomb anonymously. | Frech> XF:finger-bomb | Christey> need more refs | Baker> This should be merged with 1999-0105 | View |
380 | CVE-1999-0381 | Candidate | super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. | Proposed (19990726) | ACCEPT(7) Baker, Blake, Cole, Frech, Landfield, Levy, Ozancin | MODIFY(1) Bishop | NOOP(2) Armstrong, Wall | REVIEWING(1) Christey | Christey> Is this the same as CVE-1999-0373? They both have the same | X-Force reference. | | BID:342 suggests that there are two. | | http://www.debian.org/security/1999/19990215a suggests | that there are two. However, CVE-1999-0373 is written up in | a fashion that is too general; and both XF:linux-super-bo and | XF:linux-super-logging-bo refer to CVE-1999-0373. | CVE-1999-0373 may need to be split. | | Frech> From what I can surmise, ISS released the original advisory (attached to | linux-super-bo), and Sekure SDI expanded on it by releasing another related | overflow in syslog (which is linux-super-logging-bo). | | When I was originally assigning these issues, I placed both XF references | and the ISS advisory on the -0373 candidate, since there was nothing else | available. Based on the information above, I"d request that | XF:linux-super-logging-bo be removed from CVE-1999-0373. | Christey> Given Andre"s feedback, these are different issues. | CVE-1999-0373 does not need to be split because the ISS | reference is sufficient to distinguish that CVE from this | candidate; however, the CVE-1999-0373 description should | probably be modified slightly. | Bishop> (as indicated by Christey) | CHANGE> [Cole changed vote from NOOP to ACCEPT] | CHANGE> [Christey changed vote from NOOP to REVIEWING] | Christey> There are 2 bugs, as confirmed by the super author at: | BUGTRAQ:19990226 Buffer Overflow in Super (new) | http://www.securityfocus.com/archive/1/12713 | BID:397 also seems to cover this one, and it may cover | CVE-1999-0373 as well. | View |
410 | CVE-1999-0411 | Candidate | Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access. | Proposed (19990726) | MODIFY(2) Baker, Frech | NOOP(2) Christey, Wall | Frech> Neither XFDB nor the BugTraq article (incidentally, shows up as 7 March, not | 19 February) does not mention gaining root access... it says a local user | could | "delete or overwrite arbitrary files on the system." | Baker> By overwriting arbitrary files, one could then gain root access. I agree with a minor description change to reflect this. | Christey> Normalize Bugtraq reference to: | BUGTRAQ:19990307 Little exploit for startup scripts (SCO 5.0.4p). | http://marc.theaimsgroup.com/?l=bugtraq&m=92087765014242&w=2 | Also, SCO:SB-99.17 | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.17c | View |
450 | CVE-1999-0451 | Candidate | Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port. | Proposed (19990726) | ACCEPT(2) Baker, Ozancin | MODIFY(1) Frech | NOOP(1) Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:linux-ports-dos(8364) | View |
Page 20532 of 20943, showing 5 records out of 104715 total, starting on record 102656, ending on 102660