CVE List

Id CVE No. Status Description Phase Votes Comments Actions
517  CVE-1999-0520  Candidate  A system-critical NETBIOS/SMB share has inappropriate access control.  Proposed (19990803)  ACCEPT(1) Wall | MODIFY(1) Frech | NOOP(1) Baker | RECAST(1) Northcutt | REJECT(1) LeBlanc | REVIEWING(1) Christey  Northcutt> I think we need to enumerate the shares and or the access control | Christey> One question is, what is "inappropriate"? It"s probably | very dependent on the policy of the enterprise on which | this is found. And should writable shares be different | from readable shares? (Or file systems, mail spools, etc.) | Yes, the impact may be different, but we could have a | large number of entries for each possible type of access. | A content decision (CD:CF-DATA) needs to be reviewed | and accepted by the Editorial Board in order to resolve | this question. | LeBlanc> Unacceptably vague - agree with Christey"s comments. | Frech> associated to: | XF:nt-netbios-everyoneaccess(1) | XF:nt-netbios-guestaccess(2) | XF:nt-netbios-allaccess(3) | XF:nt-netbios-open(15) | XF:nt-netbios-write(19) | XF:nt-netbios-shareguest(20) | XF:nt-writable-netbios(26) | XF:nb-rootshare(393) | XF:decod-smb-password-empty(2358)  View
519  CVE-1999-0522  Candidate  The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.  Proposed (19990803)  ACCEPT(2) Baker, Wall | NOOP(1) Christey | RECAST(1) Northcutt  Northcutt> Why not say world readable, this is what you do further down in the | file (world exportable in CVE-1999-0554) | Christey> ADDREF AUSCERT:AA-96.02  View
524  CVE-1999-0527  Candidate  The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.  Proposed (19990803)  ACCEPT(3) Baker, Northcutt, Wall | MODIFY(1) Frech  Northcutt> That that starts to get specific :) | Frech> ftp-writable-directory(6253) | ftp-write(53) | "writeable" in the description should be "writable."  View
542  CVE-1999-0554  Candidate  NFS exports system-critical data to the world, e.g. / or a password file.  Proposed (19990803)  ACCEPT(2) Northcutt, Wall | NOOP(1) Baker | REVIEWING(1) Christey  Christey> A content decision (CD:CF-DATA) needs to be reviewed | and accepted by the Editorial Board in order to resolve | this question.  View
545  CVE-1999-0559  Candidate  A system-critical Unix file or directory has inappropriate permissions.  Proposed (19990803)  ACCEPT(2) Baker, Wall | RECAST(2) Northcutt, Shostack  Northcutt> Writable other than by root/bin/wheelgroup?  View

Page 398 of 20943, showing 5 records out of 104715 total, starting on record 1986, ending on 1990

Actions