CVE List

Id CVE No. Status Description Phase Votes Comments Actions
921  CVE-1999-0941  Candidate  Mutt mail client allows a remote attacker to execute commands via shell metacharacters.  Proposed (19991222)  ACCEPT(1) Stracener | NOOP(2) Baker, Christey | REJECT(1) Frech | REVIEWING(1) Levy  Frech> References are vague, but seem to be identical to CVE-1999-0940 | (XF:mutt-text-enriched-mime-bo). According to the references, the malformed | messages consist of metacharacters. In addition, -0941"s reference and | -0940"s SuSE reference both refer to fixes in 1.0pre3 release. Will | reconsider vote if other clearer references are forthcoming. | Christey> Modify to mention that the metachar"s are in the Content-Type header. | http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526154&w=2  View
924  CVE-1999-0944  Candidate  IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.  Proposed (19991222)  ACCEPT(2) Baker, Stracener | MODIFY(1) Frech | NOOP(2) Bollinger, Christey | REVIEWING(1) Levy  Frech> XF:websphere-database-pwd-accessible | Christey> ADDREF BID:1763 | URL:http://www.securityfocus.com/bid/1763  View
928  CVE-1999-0948  Candidate  Buffer overflow in uum program for Canna input system allows local users to gain root privileges.  Proposed (19991222)  ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Christey  Christey> CVE-1999-0948 and CVE-1999-0949 are extremely similar. | uum (0948) is exploitable through a different set of options | than canuum (0949). If it"s the same generic option parsing | routine used by both programs, then CD:SF-CODEBASE says to | merge them. But if it"s not, then CD:SF-LOC and CD:SF-EXEC | says to split them. However, this is a prime example of | how SF-EXEC might be modified - uum and canuum are clearly | part of the same package, so in the absence of clear | information, maybe we should merge them. | Frech> XF:canna-uum-bo  View
929  CVE-1999-0949  Candidate  Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.  Proposed (19991222)  ACCEPT(2) Levy, Stracener | MODIFY(1) Frech | NOOP(2) Baker, Christey  Christey> CVE-1999-0948 and CVE-1999-0949 are extremely similar. | uum (0948) is exploitable through a different set of options | than canuum (0949). If it"s the same generic option parsing | routine used by both programs, then CD:SF-CODEBASE says to | merge them. But if it"s not, then CD:SF-LOC and CD:SF-EXEC | says to split them. However, this is a prime example of | how SF-EXEC might be modified - uum and canuum are clearly | part of the same package, so in the absence of clear | information, maybe we should merge them. | | Also review BID:758 and BID:757 - may need to change the BID | here. | Frech> XF:canna-uum-bo | Christey> CHANGEREF BID:757 BID:758 | Christey> The following page says that canuum is a "Japanese input tty | frontend for Canna using uum," which suggests that it is, at | the least, a different package, so perhaps this should stay SPLIT. | | http://wuarchive.wustl.edu/mirrors/NetBSD/NetBSD-current/pkgsrc/inputmethod/canuum/README.html  View
932  CVE-1999-0952  Candidate  Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.  Proposed (19991222)  ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(2) Dik, Frech | REVIEWING(1) Christey  Frech> XF:solaris-lpstat-bo | Christey> It is unclear from Casper Dik"s followup whether this is | exploitable or not. | Dik> Sunbug 4129917 | (other reports in the same thread suggest that the then current patchd id | fix the problem) | Christey> Confirm with Casper Dik that the overflow is in the -c option, | and if so, include it in the description to differentiate | it from the lpstat -n buffer overflow.  View

Page 20557 of 20943, showing 5 records out of 104715 total, starting on record 102781, ending on 102785

Actions