CVE List

Id CVE No. Status Description Phase Votes Comments Actions
524  CVE-1999-0527  Candidate  The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.  Proposed (19990803)  ACCEPT(3) Baker, Northcutt, Wall | MODIFY(1) Frech  Northcutt> That that starts to get specific :) | Frech> ftp-writable-directory(6253) | ftp-write(53) | "writeable" in the description should be "writable."  View
617  CVE-1999-0635  Candidate  The echo service is running.  Modified (20060122)  ACCEPT(3) Baker, Northcutt, Wall | REVIEWING(1) Christey  Northcutt> The method to my madness is echo is the common denom in the dos attack | Christey> How much of this is an overlap with the echo/chargen flood | problem (CVE-1999-0103)? If this is only an exposure because | of CVE-1999-0103, then maybe this should be REJECTed.  View
778  CVE-1999-0798  Candidate  Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.  Proposed (19991222)  ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(1) Frech | NOOP(1) Christey  Christey> Is CVE-1999-0389 a duplicate of CVE-1999-0798? CVE-1999-0389 | has January 1999 dates associated with it, while CVE-1999-0798 | was reported in late December. | | http://marc.theaimsgroup.com/?l=bugtraq&m=91278867118128&w=2 | | SCO appears to have acknowledged this as well: | ftp://ftp.sco.com/SSE/security_bulletins/SB-99.01a | | The poster also claims that OpenBSD fixed this as well. | Frech> XF:bootp-remote-bo | Christey> Further analysis indicates that this is a duplicate of CVE-1999-0799 | CHANGE> [Christey changed vote from REJECT to NOOP] | Christey> What was I thinking? Brian Caswell pointed out that this is | *not* the same bug as CVE-1999-0799. As reported in the | 1998 Bugtraq post, the bug is in bootpd.c, and is related | to providing an htype value that is used as an index | into an array, and exceeds the intended boundaries of that | array.  View
388  CVE-1999-0389  Candidate  Buffer overflow in the bootp server in the Debian Linux netstd package.  Modified (19991207-01)  ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(1) Frech | REVIEWING(1) Christey  Christey> Is CVE-1999-0389 a duplicate of CVE-1999-0798? CVE-1999-0389 | has January 1999 dates associated with it, while CVE-1999-0798 | was reported in late December. | | Also, is this the same line of code as CVE-1999-0914? Both are in | the netstd package, it could look like a library problem. | | However, deep in the changelog in the | netstd_3.07-7slink.3.diff on Debian, Herbert Xu includes | the following entry: | | +netstd (3.07-7slink.1) frozen; urgency=high | + | + * bootpd: Applied patch from Redhat as well as a fix for the overflow in | + report() (fixes #30675). | + * netkit-ftp: Applied patch from RedHat that fixes some obscure overflow | + bugs. | + | + -- Herbert Xu <herbert@debian.org> Sat, 19 Dec 1998 14:36:48 +1100 | | This tells me that two separate bugs are involved. | | Note that Red Hat posted *some* fix for *some* bootp problem | in June 1998. See: | http://www.redhat.com/support/errata/rh42-errata-general.html#bootp | Frech> XF:debian-netstd-bo | Christey> Further analysis indicates that this is a duplicate of CVE-1999-0799 | CHANGE> [Christey changed vote from REJECT to REVIEWING] | Christey> The fix information for BID:324 suggests that there are two | overflows, one of which is in handle_request (bootpd.c) and is | likely related to a file name; but there is another issue in | report (report.c) which also looks like a straightforward | overflow, which would suggest that this is not a duplicate of | CVE-1999-0798 or CVE-1999-0799. | | Note: see comments for CVE-1999-0798 which explain how that | candidate is not related to CVE-1999-0799.  View
932  CVE-1999-0952  Candidate  Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.  Proposed (19991222)  ACCEPT(3) Baker, Ozancin, Stracener | MODIFY(2) Dik, Frech | REVIEWING(1) Christey  Frech> XF:solaris-lpstat-bo | Christey> It is unclear from Casper Dik"s followup whether this is | exploitable or not. | Dik> Sunbug 4129917 | (other reports in the same thread suggest that the then current patchd id | fix the problem) | Christey> Confirm with Casper Dik that the overflow is in the -c option, | and if so, include it in the description to differentiate | it from the lpstat -n buffer overflow.  View

Page 954 of 20943, showing 5 records out of 104715 total, starting on record 4766, ending on 4770

Actions