CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
4961 | CVE-2002-0570 | Candidate | The encrypted loop device in Linux kernel 2.4.10 and earlier does not authenticate the entity that is encrypting data, which allows local users to modify encrypted data without knowing the key. | Proposed (20020611) | ACCEPT(3) Alderson, Cole, Frech | MODIFY(1) Foat | NOOP(2) Cox, Wall | Foat> A local user can not modify the data. The user needs to root the box | first or at least get UNIX permission to write to the encrypted file system. | This is different than being a local user. | CHANGE> [Cox changed vote from REVIEWING to NOOP] | View |
1895 | CVE-2000-0317 | Candidate | Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option. | Proposed (20000518) | ACCEPT(3) Baker, Cole, Levy | MODIFY(1) Frech | NOOP(3) Christey, LeBlanc, Wall | RECAST(1) Dik | Dik> there"s a lot of confusion in this one. | These point to buffer overflows: | Reference: BUGTRAQ:20000424 Solaris 7 x86 lpset exploit. | Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0192.html | Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0236.html | But these point to dlopen() in libprint that doesnt" check pathnames: | Reference: BUGTRAQ:20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !) | Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95729763119559&w=2 | Reference: SUNBUG:4334568 | And this is a bufferoverflow again: | Reference: BID:1138 | Reference: URL:http://www.securityfocus.com/bid/1138 | Frech> XF:solaris-lpset-bo | Christey> ADDREF SUN:00195? Need to check with Casper. | View |
3880 | CVE-2001-1076 | Candidate | Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable. | Modified (20061101) | ACCEPT(2) Frech, Green | MODIFY(1) Dik | NOOP(3) Armstrong, Cole, Foat | REVIEWING(1) Wall | Dik> Sun bug: 4477380 | Description errors: CFIME -> CFTIME | Don"t understand "SOR" environment variable. This must | presumably be TZ | View |
3287 | CVE-2001-0470 | Candidate | Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name. | Proposed (20010524) | ACCEPT(2) Dik, Frech | NOOP(4) Cole, Oliver, Wall, Ziese | Dik> sun bug: 4425460 | View |
3219 | CVE-2001-0401 | Candidate | Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable. | Modified (20090716) | ACCEPT(2) Dik, Frech | NOOP(3) Cole, Wall, Ziese | Dik> sun bug: 4330475 | View |
Page 248 of 20943, showing 5 records out of 104715 total, starting on record 1236, ending on 1240