CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1075  CVE-1999-1095  Candidate  sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.  Proposed (20010912)  MODIFY(1) Frech | NOOP(3) Christey, Cole, Foat  Frech> XF:sort-tmp-file-symlink(7182) | Christey> This issue clearly has a long history. | CALDERA:CSSA-2002-SCO.21 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0018.html | CALDERA:CSSA-2002-SCO.2 | URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q1/0002.html | (There are 2 Caldera advisories because one is for Open UNIX | and UnixWare, and the other is for OpenServer) | | XF:openserver-sort-symlink(9218) | URL:http://www.iss.net/security_center/static/9218.php  View
1647  CVE-2000-0069  Candidate  The recover program in Solstice Backup allows local users to restore sensitive files.  Proposed (20000125)  MODIFY(1) Frech  Frech> XF:solstice-backup-restore-files(3904)  View
1351  CVE-1999-1371  Candidate  Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.  Modified (20040723)  ACCEPT(2) Cole, Dik | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall  Frech> XF:solaris-write-bo(7546) | Christey> This appears to be a rediscovery of the problem for Solaris | 2.8: | BUGTRAQ:20011114 /usr/bin/write (solaris2.x) Segmentation Fault | URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100588255815773&w=2 | Dik> sun bug: 4218941  View
1138  CVE-1999-1158  Candidate  Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.  Proposed (20010912)  ACCEPT(4) Cole, Dik, Foat, Stracener | MODIFY(1) Frech | RECAST(1) Christey  Frech> XF:solaris-pam-bo(7432) | Dik> sun bug: 4018347 | Christey> These issues should be SPLIT per CD:SF-EXEC because the PAM | problem appears in different Solaris versions than | unix_scheme.  View
932  CVE-1999-0952  Candidate  Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.  Proposed (19991222)  ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(2) Dik, Frech | REVIEWING(1) Christey  Frech> XF:solaris-lpstat-bo | Christey> It is unclear from Casper Dik"s followup whether this is | exploitable or not. | Dik> Sunbug 4129917 | (other reports in the same thread suggest that the then current patchd id | fix the problem) | Christey> Confirm with Casper Dik that the overflow is in the -c option, | and if so, include it in the description to differentiate | it from the lpstat -n buffer overflow.  View

Page 80 of 20943, showing 5 records out of 104715 total, starting on record 396, ending on 400

Actions