CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
186 | CVE-1999-0186 | Candidate | In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters. | Modified (20071119) | ACCEPT(2) Baker, Dik | MODIFY(1) Frech | NOOP(1) Wall | REVIEWING(1) Christey | Frech> Change XF:snmp-backdoor-access to XF:sol-hidden-commstr | Add ISS:Hidden Community String in SNMP Implementation | Christey> What is the proper level of abstraction to use here? Should | we have a separate entry for each different default community | string? See: | http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and | http://cve.mitre.org/Board_Sponsors/archives/msg00250.html | http://cve.mitre.org/Board_Sponsors/archives/msg00251.html | | Until the associated content decisions have been approved | by the Editorial Board, this candidate cannot be accepted | for inclusion in CVE. | Christey> ADDREF BID:177 | Christey> ISS:19981102 Hidden community string in SNMP implementation | http://xforce.iss.net/alerts/advise11.php | | Change description to include "hidden" | Christey> XF:snmp-backdoor-access is missing. | View |
187 | CVE-1999-0187 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-1999-0022. Reason: This candidate is a duplicate of CVE-1999-0022. Notes: All CVE users should reference CVE-1999-0022 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Modified (20050204) | ACCEPT(2) Hill, Northcutt | RECAST(3) Baker, Frech, Prosser | REJECT(1) Dik | REVIEWING(1) Christey | Prosser> The Sun Patches in Ref roll-up fixes for an earlier BO in | rdist lookup( )(ref CERT 96.14)as well as the BO in rdist function expstr() | (ref CERT 97-23) and various vendor bulletins. However both of these rdist | BO"s affect many more OSs than just Sun, i.e., BSD/OS 2.1, DEC OSF"s, AIX, | FreeBSD, SCO, SGI, etc. Believe this falls into the SF-codebase content | decision | Frech> XF:rdist-bo (error msg formation) | XF:rdist-bo2 (execute code) | XF:rdist-bo3 (execute user-created code) | XF:rdist-sept97 (root from local) | Christey> Duplicate of CVE-1999-0022 (SUN:00179 is referenced in | CERT:CA-97.23.rdist), but as Mike and Andre noted, there | are multiple flaws here, so a RECAST may be necessary. | Dik> As currently phrasedm thissa duplicate of CVE-1999-0022 | Baker> Based on our new philosophy, this should be recast/merged or re-described. | View |
188 | CVE-1999-0188 | Entry | The passwd command in Solaris can be subjected to a denial of service. | View | |||
189 | CVE-1999-0189 | Entry | Solaris rpcbind listens on a high numbered UDP port, which may not be filtered since the standard port number is 111. | View | |||
190 | CVE-1999-0190 | Entry | Solaris rpcbind can be exploited to overwrite arbitrary files and gain root access. | View |
Page 38 of 20943, showing 5 records out of 104715 total, starting on record 186, ending on 190