Common Vulnerabilities and Exposures
Get CVEAbout CVENews and EventsEditorial BoardCompatible ProductsRegister

CVE Candidates as of 20030718

Candidates must be reviewed and accepted by the CVE Editorial Board before they can be added to the official CVE list. Therefore, these candidates may be modified or even rejected in the future. They are provided for use by individuals who have a need for an early numbering scheme for items that have not been fully reviewed by the Editorial Board.
CAN-1999-0001

Phase: Modified (20000106-01)
Reference: CERT:CA-98-13-tcp-denial-of-service
Reference: BUGTRAQ:19981223 Re: CERT Advisory CA-98.13 - TCP/IP Denial of Service

Description:
Denial of service in BSD-derived TCP/IP implementations, as described in CERT CA-98-13.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Northcutt
   REVIEWING(1) Christey
Voter Comments:
 Christey> A Bugtraq posting indicates that the bug has to do with
   "short packets with certain options set," so the description
   should be modified accordingly.
   
   But is this the same as CVE-1999-0052?  That one is related
   to nestea (CAN-1999-0257) and probably the one described in
   BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release
   The patch for nestea is in ip_input.c around line 750.
   The patches for CAN-1999-0001 are in lines 388&446.  So, 
   CAN-1999-0001 is different from CAN-1999-0257 and CVE-1999-0052.
   The FreeBSD patch for CVE-1999-0052 is in line 750.
   So, CAN-1999-0257 and CVE-1999-0052 may be the same, though
   CVE-1999-0052 should be RECAST since this bug affects Linux
   and other OSes besides FreeBSD.
 Frech> XF:teardrop(338)
   This assignment was based solely on references to the CERT advisory.


CAN-1999-0004

Phase: Modified (19990621-01)
Reference: CERT:CA-98.10.mime_buffer_overflows
Reference: XF:outlook-long-name
Reference: SUN:00175
Reference: MS:MS98-008
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms98-008.asp

Description:
MIME buffer overflow in email clients, e.g. Solaris mailtool and Outlook.

Votes:

   ACCEPT(8) Baker, Magdych, Wall, Landfield, Cole, Dik, Collins, Northcutt
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Shostack
Voter Comments:
 Frech> Extremely minor, but I believe e-mail is the correct term. (If you reject
   this suggestion, I will not be devastated.) :-)
 Christey> This issue seems to have been rediscovered in
   BUGTRAQ:20000515 Eudora Pro & Outlook Overflow - too long filenames again
   http://marc.theaimsgroup.com/?l=bugtraq&m=95842482413076&w=2
   
   Also see
   BUGTRAQ:19990320 Eudora Attachment Buffer Overflow
   http://marc.theaimsgroup.com/?l=bugtraq&m=92195396912110&w=2
 Christey> 
   CAN-2000-0415 may be a later rediscovery of this problem
   for Outlook.
 Dik> Sun bug 4163471,
 Christey> ADDREF BID:125
 Christey> BUGTRAQ:19980730 Long Filenames & Lotus Products
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526201&w=2


CAN-1999-0015

Phase: Proposed (19990726)
Reference: CERT:CA-97.28.Teardrop_Land
Reference: XF:teardrop

Description:
Teardrop IP denial of service.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF: teardrop-mod
 Christey> Not sure how many separate "instances" of Teardrop there are.
   See: CAN-1999-0015, CAN-1999-0104, CAN-1999-0257, CAN-1999-0258
 Christey> See the SCO advisory at:
   http://www.securityfocus.com/templates/advisory.html?id=1411
   which may further clarify the issue.
 Christey> MSKB:Q154174
   MSKB:Q154174 (CAN-1999-0015) and MSKB:Q179129 (CAN-1999-0104)
   indicate that CAN-1999-0015 was fixed in NT SP3, but
   CAN-1999-0104 was not.  Thus CD:SF-LOC suggests that the
   problems keep separate candidates because one problem appears
   in a different version than the other.
 Christey> BID:124
   http://www.securityfocus.com/bid/124
   Consider MSKB:Q154174
   http://support.microsoft.com/support/kb/articles/q154/1/74.asp
   Consider BUGTRAQ:19971113 Linux IP fragment overlap bug
   http://www.securityfocus.com/archive/1/8014


CAN-1999-0020

Phase: Modified (20000106-01)

Description:
** REJECT ** Duplicate of CVE-1999-0032 ** REJECT ** Buffer overflow in Linux lpr command gives root access.

Votes:

   MODIFY(1) Frech
   NOOP(4) Shostack, Levy, Wall, Northcutt
   REJECT(2) Baker, Christey
Voter Comments:
 Frech> XF:lpr-bo
 Christey> DUPE CVE-1999-0032, which includes XF:lpr-bo


CAN-1999-0030

Phase: Proposed (19990623)
Reference: CERT:CA-97.21.sgi_buffer_overflow
Reference: AUSCERT:AA-97.24.IRIX.xlock.buffer.overflow.vul
Reference: XF:sgi-xlockbo
Reference: SGI:19970508-02-PX

Description:
root privileges via buffer overflow in xlock command on SGI IRIX systems.

Votes:

   ACCEPT(3) Ozancin, Levy, Prosser
   RECAST(1) Frech
   REJECT(1) Christey
Voter Comments:
 Frech> XF:xlock-bo (also add)
   As per xlock-bo, also appears on AIX, BSDI, DG/UX, FreeBSD, Solaris, and
   several Linii.
   Also, don't you mean to cite SGI:19970502-02-PX? The one you list is
   login/scheme.
 Levy> Notice that this xlock overflow is the same as in
   CA-97.13. CA-97.21 simply is a reminder.
 Christey> As pointed out by Elias, CA-97.21 states: "For more
   information about vulnerabilities in xlock... see CA-97.13"
   CA-97.13 = CVE-1999-0038.
   This may also be a duplicate with CAN-1999-0306.
   
   See exploits at:
   
   http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418394&w=2
   http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418404&w=2
   
   Sun also has this problem, at
   http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/150&type=0&nav=sec.sba


CAN-1999-0033

Phase: Proposed (19990607)
Reference: CERT:CA-97.18.at
Reference: SUN:00160
Reference: XF:sun-atbo

Description:
Command execution in Sun systems via buffer overflow in the at program

Votes:

   ACCEPT(8) Baker, Shostack, Wall, Cole, Dik, Collins, Hill, Northcutt
   NOOP(1) Christey
   RECAST(1) Frech
Voter Comments:
 Frech> This vulnerability also manifests itself for the following 
   platforms: AIX, HPUX, IRIX, Solaris, SCO, NCR MP-RAS. In this light,
   please add the following:
   Reference: XF:at-bo
 Dik> Sun bug 1265200, 4063161
 Christey> ADDREF SGI:19971102-01-PX
   ftp://patches.sgi.com/support/free/security/advisories/19971102-01-PX
   SCO:SB.97:01
   ftp://ftp.sco.com/SSE/security_bulletins/SB.97:01a
 Christey> CIAC:F-15
   http://ciac.llnl.gov/ciac/bulletins/f-15.shtml
   HP:HPSBUX9502-023
 Christey> Add period to the end of the description.


CAN-1999-0061

Phase: Proposed (19990630)
Reference: NAI:NAI-20
Reference: XF:bsd-lpd

Description:
File creation and deletion, and remote execution, in the BSD line printer daemon (lpd).

Votes:

   ACCEPT(3) Frech, Hill, Northcutt
   RECAST(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Christey> This should be split into three separate problems based on
   the SNI advisory.  But there's newer information to further
   complicate things.
   
   What do we do about this one?  in 1997 or so, SNI did an
   advisory on this problem.  In early 2000, it was still
   discovered to be present in some Linux systems.  So an 
   SF-DISCOVERY content decision might say that this is a
   long enough time between the two, so this should be recorded
   separately.  But they're the same codebase... so if we keep
   them in the same entry, how do we make sure that this entry
   reflects that some new information has been discovered?
   
   The use of dot notation may help in this regard, to use one
   dot for the original problem as discovered in 1997, and
   another dot for the resurgence of the problem in 2000.
 Baker> We should merge these.


CAN-1999-0076

Phase: Modified (19990925-01)
Reference: XF:ftp-args

Description:
Buffer overflow in wu-ftp from PASV command causes a core dump.

Votes:

   ACCEPT(3) Baker, Frech, Ozancin
   NOOP(1) Balinsky
   REVIEWING(1) Christey
Voter Comments:
 Balinsky> Don't know what this is.  Is this the LIST Core dump vulnerability?
 Christey> Need to add more references and details.


CAN-1999-0078

Phase: Modified (19990621-01)
Reference: CERT:CA-96.08.pcnfsd
Reference: XF:rpc-pcnfsd

Description:
pcnfsd (aka rpc.pcnfsd) allows local users to change file permissions, or execute arbitrary commands through arguments in the RPC call.

Votes:

   ACCEPT(5) Frech, Shostack, Landfield, Collins, Northcutt
   RECAST(1) Christey
Voter Comments:
 Christey> This candidate should be SPLIT, since there are two separate
   software flaws.  One is a symlink race and the other is a
   shell metacharacter problem.
 Christey> The permissions part of this vulnerability appears to
   overlap with CVE-1999-0353
 Christey> SGI:20020802-01-I


CAN-1999-0086

Phase: Interim (19990630)
Reference: ERS:ERS-SVA-E01-1998:001.1
Reference: XF:ibm-routed

Description:
AIX routed allows remote users to modify sensitive files.

Votes:

   ACCEPT(2) Shostack, Northcutt
   MODIFY(2) Frech, Prosser
   NOOP(1) Baker
   REJECT(1) Christey
Voter Comments:
 Frech> Reference: XF:ibm-routed
 Prosser> This vulnerability allows debug mode to be turned on which is
   the problem.  Should this be more specific in the description? This
   one also affects SGI OSes, ref SGI Security Advisory 19981004-PX which
   is in the SGI cluster, shouldn't these be cross-referenced as the same
   vuln affects multiple OSes.
 Christey> This appears to be subsumed by CVE-1999-0215


CAN-1999-0088

Phase: Proposed (19990617)
Reference: ERS:ERS-SVA-E01-1998:004.1
Reference: URL:http://www-1.ibm.com/services/brs/brspwhub.nsf/advisories/852567CC004F9038852566BF007B6393/$file/ERS-SVA-E01-1998_004_1.txt

Description:
IRIX and AIX automountd services (autofsd) allow remote users to execute root commands.

Votes:

   ACCEPT(2) Shostack, Northcutt
   MODIFY(2) Frech, Prosser
   RECAST(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Frech> ERS (and other references, BTW) explicitly stipulate 'local and
   remote'.
   Reference: XF:irix-autofsd
 Prosser> Include the SGI Alert as well since it is mentioned in the
   description.
   SGI Security Advisory 19981005-01-PX
 Christey> DUPE CAN-1999-0210?
 Christey> ADDREF CIAC:J-014
 Baker> It does look very similar to 1999-0210.  Perhaps they should be a single entry


CAN-1999-0089

Phase: Interim (19990630)
Reference: ERS:ERS-SVA-E01-1997:005.1
Reference: XF:ibm-libDtSvc

Description:
Buffer overflow in AIX libDtSvc library can allow local users to gain root access.

Votes:

   ACCEPT(2) Shostack, Northcutt
   MODIFY(2) Frech, Prosser
   RECAST(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Frech> Reference: XF:ibm-libDtSvc
 Prosser> The overflow is in the dtaction utility.  Also affects
   dtaction in the CDE on versions of SunOS (SUN 164). Probably should be
   specific.
 Christey> Same Codebase as CAN-1999-0121, so the two entries should be
   merged.


CAN-1999-0092

Phase: Proposed (19990623)
Reference: ERS:ERS-SVA-E01-1997:006.1

Description:
Various vulnerabilities in the AIX portmir command allows local users to obtain root access.

Votes:

   ACCEPT(1) Bollinger
   MODIFY(1) Frech
   NOOP(1) Ozancin
Voter Comments:
 Frech> XF:ibm-portmir


CAN-1999-0098

Phase: Proposed (19990726)
Reference: XF:smtp-helo-bo

Description:
Buffer overflow in SMTP HELO command in Sendmail allows a remote attacker to hide activities.

Votes:

   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> (Accept XF reference.)
   Our references do not mention hiding activities. This issue can crash the
   SMTP server or execute arbitrary byte-code. Is there another reference
   available?
 Christey> Should this be merged with CAN-1999-0284, which is Sendmail
   with SMTP HELO?
 Christey> BUGTRAQ:19980522 about sendmail 8.8.8 HELO hole
   http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925991&w=2
   BUGTRAQ:19980527 about sendmail 8.8.8 HELO hole
   http://marc.theaimsgroup.com/?l=bugtraq&m=90221101926003&w=2


CAN-1999-0104

Phase: Proposed (19990726)
Reference: CERT:CA-97.28.Teardrop_Land
Reference: XF:teardrop-mod

Description:
A later variation on the Teardrop IP denial of service attack, a.k.a. Teardrop-2

Votes:

   ACCEPT(2) Frech, Wall
   REVIEWING(1) Christey
Voter Comments:
 Wall> Another reference is Microsoft Knowledge Base Q179129.
 Christey> Not sure how many separate "instances" of Teardrop there are.
   See: CAN-1999-0015, CAN-1999-0104, CAN-1999-0257, CAN-1999-0258
 Christey> See the SCO advisory at:
   http://www.securityfocus.com/templates/advisory.html?id=1411
   which may further clarify the issue.
 Christey> MSKB:Q179129
   http://support.microsoft.com/support/kb/articles/q179/1/29.asp
 Christey> MSKB:Q179129
   http://support.microsoft.com/support/kb/articles/q179/1/29.asp
   Note that the hotfix name is teardrop2, but the keywords
   included in the KB article specifically name bonk
   (CAN-1999-0258) and boink.
   Since teardrop2 was fixed in a slightly different version
   (at least in a separate patch) than Teardrop, CD:SF-LOC
   suggests keeping them separate.
 Christey> Add period to the end of the description.


CAN-1999-0105

Phase: Proposed (19990726)

Description:
finger allows recursive searches by using a long string of @ symbols.

Votes:

   MODIFY(2) Frech, Shostack
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Shostack> fingerD
 Frech> XF:finger-bomb
 Christey> aka redirection or forwarding requests? (but then might
   overlap CAN-1999-0106)


CAN-1999-0106

Phase: Proposed (19990726)

Description:
Finger redirection allows finger bombs.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(2) Frech, Shostack
   REVIEWING(1) Christey
Voter Comments:
 Shostack> fingerd allows redirection
   This is a larger modification, since there are two applications of the 
   vulnerability, one that I can finger anonymously, and the other that I 
   can finger bomb anonymously.
 Frech> XF:finger-bomb
 Christey> need more refs


CAN-1999-0107

Phase: Modified (19991223-01)
Reference: XF:apache-dos
Reference: BUGTRAQ:19971230 Apache DoS attack?

Description:
Buffer overflow in Apache 1.2.5 and earlier allows a remote attacker to cause a denial of service with a large number of GET requests containing a large number of / characters.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Shostack, Wall, Northcutt
   REVIEWING(1) Levy
   REVOTE(1) Christey
Voter Comments:
 Wall> - Although this is probably the phf hack.
 Frech> XF:apache-dos
 Christey> This sounds like the incident reported in:
   NTBUGTRAQ:20000810 Apache Distributed Denial of Service
 Levy> I belive this is the problem where sending lot of HTTP headers to apache resulted on a denial of service.
   BUGTRAQ: http://www.securityfocus.com/archive/1/10228
   BUGTRAQ: http://www.securityfocus.com/archive/1/10516


CAN-1999-0110

Phase: Interim (19990810)

Description:
** REJECT ** Duplicate of CVE-1999-0315 (this has a typo) ** REJECT ** Buffer overflow in fbformat command in Solaris.

Votes:

   MODIFY(1) Frech
   NOOP(4) Shostack, Levy, Wall, Northcutt
   REJECT(3) Baker, Dik, Christey
Voter Comments:
 Frech> XF:fdformat-bo
 Christey> Duplicate of CAN-1999-0315
 Dik> dup


CAN-1999-0114

Phase: Modified (20000106-01)
Reference: BUGTRAQ:19990912 elm filter program
Reference: BUGTRAQ:19951226 filter (elm package) security hole
Reference: XF:elm-filter2

Description:
Local users can execute commands as other users, and read other users' files, through the filter command in the Elm elm-2.4 mail package using a symlink attack.

Votes:

   ACCEPT(7) Shostack, Bishop, Wall, Landfield, Cole, Armstrong, Blake
   MODIFY(2) Baker, Frech
   NOOP(3) Ozancin, Christey, Northcutt
   REVIEWING(1) Levy
Voter Comments:
 Frech> XF:elm-filter2
 CHANGE> [Wall changed vote from NOOP to ACCEPT]
 Landfield> with Frech modifications
 Baker> ADD REF http://www.cert.org/ftp/cert_bulletins/VB-95:10a.elm	Official Advisory
 Christey> The correct URL is http://www.cert.org/vendor_bulletins/VB-95:10a.elm
   Need to make sure that this CERT advisory describes the right
   problem, especially since the CERT advisory is dated December
   18, 1995 and the original Bugtraq post was December 26, 1995.
 Christey> BID:1802
   URL:http://www.securityfocus.com/bid/1802
   BID:1802 doesn't include the 1999 posting - does Security
   Focus think that the 1999 post describes a different
   vulnerability?
 Christey> XF:elm-filter2 isn't on the X-Force web site.  How about XF:elm-filter(402) ?
   Its references point to the December 26, 1995 BUgtraq post.
   
   Also consider CIAC:G-36 and CERT:VB-95:10
 Frech> DELREF:XF:elm-filter2(711)
   ADDREF:XF:elm-filter(402)


CAN-1999-0119

Phase: Proposed (19990728)

Description:
Windows NT 4.0 beta allows users to read and delete shares.

Votes:

   MODIFY(1) Frech
   NOOP(1) Northcutt
   REJECT(1) Wall
Voter Comments:
 Wall> Reject based on beta copy.
 Frech> XF:nt-beta(11)
   Reconsider reject, because this beta was in widespread use.


CAN-1999-0121

Phase: Proposed (19990617)
Reference: SUN:00164
Reference: ERS:ERS-SVA-E01-1997:005.1

Description:
Buffer overflow in dtaction command gives root access.

Votes:

   ACCEPT(2) Dik, Northcutt
   MODIFY(3) Baker, Frech, Prosser
   REVIEWING(1) Christey
Voter Comments:
 Frech> Reference: XF:dtaction-bo
   Reference: XF:sun-dtaction
 Prosser> Buffer overflow also affects /usr/dt/bin/dtaction in libDtSvc.a
   library in AIX 4.x, but reference for this Sun vulnerability should
   only reflect the Sun Bulletin or the CIAC I-032 version of the Sun
   Bulletin
 Christey> This is the Same Codebase as CAN-1999-0089, so the two entries
   should be merged.
 Frech> Replace sun-dtaction(732) with dtaction-bo(879)
 Baker> Merge with 1999-0089


CAN-1999-0123

Phase: Modified (20000105-01)
Reference: XF:linux-mailx
Reference: BUGTRAQ:19951222 mailx-5.5 (slackware /bin/mail) security hole

Description:
Race condition in Linux mailx command allows local users to read user files.

Votes:

   ACCEPT(3) Baker, Frech, Ozancin
   NOOP(1) Wall

CAN-1999-0127

Phase: Proposed (19990623)
Reference: CERT:CA-96.27.hp_sw_install
Reference: AUSCERT:AA-96.04
Reference: XF:hpux-swinstall

Description:
swinstall and swmodify commands in SD-UX package in HP-UX systems allow local users to create or overwrite arbitrary files to gain root access.

Votes:

   ACCEPT(1) Prosser
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> (keep current XF: reference, and add)
   XF:hpux-sqwmodify
 Christey> Perhaps this should be split, per SF-LOC.
 Christey> CIAC:H-81
   http://ciac.llnl.gov/ciac/bulletins/h-81.shtml
   HP:HPSBUX9707-064  references CERT:CA-96.27
   http://ciac.llnl.gov/ciac/bulletins/h-81.shtml
   
   The original AUSCERT advisory says that the programs "create
   files in an insecure manner" and "Exploit details involving
   this vulnerability have been made publicly available." which
   leads one to assume that the following original Bugtraq post
   provides the details for a standard symlink problem:
   
   BUGTRAQ:19961005 swinst,bug
   http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419941&w=2


CAN-1999-0140

Phase: Proposed (19990630)

Description:
Denial of service in RAS/PPTP on NT systems.

Votes:

   ACCEPT(1) Hill
   MODIFY(2) Frech, Meunier
   NOOP(1) Baker
   REJECT(1) Christey
Voter Comments:
 Meunier> Add "pptp invalid packet length in header" to distinguish from other
   vulnerabilities in RAS/PPTP on NT systems resulting in DOS, that might be
   discovered in the future.
 Frech> XF:nt-ras-bo
   ONLY IF reference is to MS:MS99-016
 Christey> According to my mappings, this is not the MS:MS99-016 problem
   referred to by Andre.  However, I have yet to dig up a
   source.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 CHANGE> [Christey changed vote from REVIEWING to REJECT]
 Christey> This is too general to know which problem is being discussed.
   More precise candidates should be created.
 Christey> Consider adding BID:2111


CAN-1999-0144

Phase: Modified (20010301-02)
Reference: BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319024&w=2
Reference: BUGTRAQ:19970612 Re: Denial of service (qmail-smtpd)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319029&w=2
Reference: MISC:http://cr.yp.to/qmail/venema.html
Reference: MISC:http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
Reference: BID:2237
Reference: URL:http://www.securityfocus.com/bid/2237
Reference: XF:qmail-rcpt
Reference: URL:http://xforce.iss.net/static/208.php

Description:
Denial of service in Qmail by specifying a large number of recipients with the RCPT command.

Votes:

   ACCEPT(4) Baker, Frech, Meunier, Hill
   REVIEWING(1) Christey
Voter Comments:
 Christey> DUPE CAN-1999-0418 and CAN-1999-0250?
 Christey> Dan Bernstein, author of Qmail, says that this is not a
   vulnerability in qmail because Unix has built-in resource
   limits that can restrict the size of a qmail process; other
   limits can be specified by the administrator.  See
   http://cr.yp.to/qmail/venema.html
   
   Significant discussion of this issue took place on the qmail
   list.  The fundamental question appears to be whether 
   application software should set its own limits, or rely
   on limits set by the parent operating system (in this case,
   UNIX).  Also, some people said that the only problem was that
   the suggested configuration was not well documented, but this
   was refuted by others.
   
   See the following threads at
   http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
   "Denial of service (qmail-smtpd)"
   "qmail-dos-2.c, another denial of service"
   "[PATCH] denial of service"
   "just another qmail denial-of-service"
   "the UNIX way"
   "Time for a reality check"
   
   Also see Bugtraq threads on a different vulnerability that
   is related to this topic:
   BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding
   http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html
 Baker> http://cr.yp.to/qmail/venema.html
   Berstein rejects this as a vulnerability, claiming this is a slander campaign by Wietse Venema.
   His page states this is not a qmail problem, rather it is a UNIX problem
   that many apps can consume all available memory, and that the administrator
   is responsible to set limits in the OS, rather than expect applications to
   individually prevent memory exhaustion.  CAN 1999-0250 does appear to
   be a duplicate of this entry, based on the research I have done so far.
   There were two different bugtraq postings, but the second one references
   the first, stating that the new exploit uses perl instead of shell scripting
   to accomplish the same attack/exploit.
 Baker> http://www.securityfocus.com/archive/1/6970
   http://www.securityfocus.com/archive/1/6969
   http://cr.yp.to/qmail/venema.html
   
   Should probably reject CAN-1999-0250, and add these references to this
   Candidate.
 Baker> http://www.securityfocus.com/bid/2237
 CHANGE> [Baker changed vote from REVIEWING to ACCEPT]
 Christey> qmail-dos-1.c, as published by Wietse Venema (CAN-1999-0250)
   in "BUGTRAQ:19970612 Denial of service (qmail-smtpd)", does not
   use any RCPT commands.  Instead, it sends long strings
   of "X" characters.  A followup by "super@UFO.ORG" includes
   an exploit that claims to do the same thing; however, that
   exploit does not send long strings of X characters - it sends
   a large number of RCPT commands.  It appears that super@ufo.org
   followed up to the wrong message.
   
   qmail-dos-2.c, as published by Wietse Venema (CAN-1999-0144)
   in "BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack"
   sends a large number of RCPT commands.
   
   ADDREF BID:2237
   ADDREF BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack
   ADDREF BUGTRAQ:19970612 Re: Denial of service (qmail-smtpd)
   
   Also see a related thread:
   BUGTRAQ:19990308 SMTP server account probing
   http://marc.theaimsgroup.com/?l=bugtraq&m=92100018214316&w=2
   
   This also describes a problem with mail servers not being able
   to handle too many "RCPT TO" requests.  A followup message
   notes that application-level protection is used in Sendmail
   to prevent this:
   BUGTRAQ:19990309 Re: SMTP server account probing
   http://marc.theaimsgroup.com/?l=bugtraq&m=92101584629263&w=2
   The person further says, "This attack can easily be
   prevented with configuration methods."


CAN-1999-0154

Phase: Proposed (20010912)
Reference: MSKB:Q163485
Reference: MSKB:Q164059
Reference: BUGTRAQ:19970220 ! [ADVISORY] Major Security Hole in MS ASP
Reference: XF:http-iis-aspdot
Reference: XF:http-iis-aspsource

Description:
IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

Votes:

   ACCEPT(4) Frech, Wall, Foat, Stracener
   NOOP(2) Cole, Christey
Voter Comments:
 Christey> This is the precursor to the problem that is identified in
   CAN-1999-0253.  
 Christey> CIAC:H-48
   URL:http://ciac.llnl.gov/ciac/bulletins/h-48.shtml
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-1999-0156

Phase: Proposed (19990714)
Reference: XF:ftp-pwless

Description:
wu-ftpd FTP daemon allows any user and password combination.

Votes:

   ACCEPT(2) Shostack, Northcutt
   NOOP(1) Baker
   RECAST(1) Frech
   REVIEWING(2) Christey, Prosser
Voter Comments:
 Prosser> but so far can find no reference to this one
 Frech> Our records indicate that this does not necessarly affect just wu-ftp (ie,
   also affects IIS FTP server).
 Christey> The references for XF:ftp-pwless are not specific enough,
   e.g. in terms of version numbers.  Perhaps this candidate
   should be rejected due to insufficient information.


CAN-1999-0163

Phase: Proposed (19990714)
Reference: XF:smtp-pipe

Description:
In older versions of Sendmail, an attacker could use a pipe character to execute root commands.

Votes:

   ACCEPT(2) Frech, Northcutt
   MODIFY(1) Prosser
   NOOP(2) Baker, Christey
   RECAST(1) Shostack
Voter Comments:
 Shostack> there was a 'To: |' and a 'From: |' attack, which I
   think are seperate.
 Prosser> older vulnerability, but one additional reference is-
   The Ultimate Sendmail Hole List by Markus Hübner @
   bau2.uibk.ac.at/matic/buglist.htm
   '|PROGRAM '
 Christey> Description needs to be more specific to distinguish between
   this and CAN-1999-0203, as alluded to by Adam Shostack


CAN-1999-0165

Phase: Proposed (19990714)
Reference: XF:nfs-cache

Description:
NFS cache poisoning

Votes:

   ACCEPT(3) Baker, Frech, Northcutt
   MODIFY(1) Shostack
   NOOP(1) Prosser
   REVIEWING(1) Christey
Voter Comments:
 Shostack> need more data
 Christey> need more refs
 Christey> Add period to the end of the description.


CAN-1999-0169

Phase: Proposed (19990714)
Reference: XF:nfs-uid

Description:
NFS allows attackers to read and write any file on the system by specifying a false UID.

Votes:

   ACCEPT(2) Frech, Northcutt
   REJECT(1) Shostack
Voter Comments:
 Shostack> this is not a vulnerability but a design feature.


CAN-1999-0171

Phase: Proposed (19990714)
Reference: XF:syslog-flood

Description:
Denial of service in syslog by sending it a large number of superfluous messages.

Votes:

   ACCEPT(2) Frech, Northcutt
   NOOP(1) Baker
   REJECT(2) Shostack, Christey
Voter Comments:
 Shostack> design issue, not a vulnerability.  Alternately, add:
   DOS on server by opening a large number of telnet sessions..
 Christey> Duplicate of CVE-1999-0566


CAN-1999-0186

Phase: Proposed (19990726)
Reference: SUN:00178
Reference: XF:snmp-backdoor-access

Description:
In Solaris, an SNMP subagent has a default community string that allows remote attackers to execute arbitrary commands as root, or modify system parameters.

Votes:

   ACCEPT(2) Baker, Dik
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> Change XF:snmp-backdoor-access to XF:sol-hidden-commstr
   Add ISS:Hidden Community String in SNMP Implementation
 Christey> What is the proper level of abstraction to use here?  Should
   we have a separate entry for each different default community
   string?  See:
   http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and
   http://cve.mitre.org/Board_Sponsors/archives/msg00250.html
   http://cve.mitre.org/Board_Sponsors/archives/msg00251.html
   
   Until the associated content decisions have been approved
   by the Editorial Board, this candidate cannot be accepted
   for inclusion in CVE.
 Christey> ADDREF BID:177
 Christey> ISS:19981102 Hidden community string in SNMP implementation
   http://xforce.iss.net/alerts/advise11.php
   
   Change description to include "hidden"
 Christey> XF:snmp-backdoor-access is missing.


CAN-1999-0187

Phase: Modified (19990805)
Reference: SUN:00179

Description:
** REJECT ** Duplicate of CAN-1999-0022 (SUN:00179 is referenced in CERT:CA-97.23.rdist) The rdist program in Solaris has some buffer overflows that allow attackers to gain root access.

Votes:

   ACCEPT(2) Hill, Northcutt
   RECAST(3) Baker, Frech, Prosser
   REJECT(1) Dik
   REVIEWING(1) Christey
Voter Comments:
 Prosser> The Sun Patches in Ref roll-up fixes for an earlier BO in
   rdist lookup( )(ref CERT 96.14)as well as the BO in rdist function expstr()
   (ref CERT 97-23) and various vendor bulletins.  However both of these rdist
   BO's affect many more OSs than just Sun, i.e., BSD/OS 2.1, DEC OSF's, AIX,
   FreeBSD, SCO, SGI, etc.  Believe this falls into the SF-codebase content
   decision
 Frech> XF:rdist-bo (error msg formation)
   XF:rdist-bo2 (execute code)
   XF:rdist-bo3 (execute user-created code)
   XF:rdist-sept97 (root from local)
 Christey> Duplicate of CAN-1999-0022 (SUN:00179 is referenced in
   CERT:CA-97.23.rdist), but as Mike and Andre noted, there
   are multiple flaws here, so a RECAST may be necessary.
 Dik> As currently phrasedm thissa duplicate of CVE-1999-0022
 Baker> Based on our new philosophy, this should be recast/merged or re-described.


CAN-1999-0193

Phase: Proposed (19990714)

Description:
Denial of service in Ascend and 3com routers, which can be rebooted by sending a zero length TCP option.

Votes:

   ACCEPT(5) Shostack, Bishop, Ozancin, Cole, Northcutt
   MODIFY(2) Baker, Blake
   NOOP(4) Frech, Wall, Landfield, Armstrong
   REVIEWING(2) Levy, Christey
Voter Comments:
 Frech> possibly XF:ascend-kill
   I can't find a reference that lists both routers in the same reference.
 Wall> Comment:  There is a reference about the zero length TCP option in BugTraq on
   Feb 5, 1999
   and it mentions Cisco, but not directly Ascend or 3Com.  CIAC Advisory I-038
   mentions
   vulnerabilities in Ascend, but does not mention TCP.  CIAC Advisory I-052
   mentions
   3Com vulnerabilities, but not TCP.  Too confusing withour better references.
 Landfield> What are the references for this ? I cannot find a means to check it out.
 CHANGE> [Frech changed vote from REVIEWING to NOOP]
 Frech> Cannot reconcile to our database without further references.
 Blake> I'm with Andre.  I only remember and can find reference to the Ascend
   issue.  Do we have a refernce to the 3Coms?  If not, that should be
   removed from the description.
 Baker> http://xforce.iss.net/static/614.php	Misc Defensive Info
   http://www.securityfocus.com/archive/1/5682	Misc Offensive Info
   http://www.securityfocus.com/archive/1/5647	Misc Defensive Info
   http://www.securityfocus.com/archive/1/5640	Misc Defensive Info
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]


CAN-1999-0195

Phase: Modified (19991130-01)
Reference: BUGTRAQ:19990128 rpcbind: deceive, enveigle and obfuscate

Description:
Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1.

Votes:

   ACCEPT(2) Shostack, Balinsky
   MODIFY(1) Frech
   NOOP(3) Baker, Wall, Northcutt
   REVIEWING(2) Levy, Christey
Voter Comments:
 Frech> XF:rpcbind-spoof
 Christey> CAN-1999-0195 = CAN-1999-0461 ?
   If this is approved over CAN-1999-0461, make sure it gets
   XF:pmap-sset


CAN-1999-0197

Phase: Proposed (19990726)

Description:
finger 0@host on some systems may print information on some user accounts.

Votes:

   MODIFY(2) Frech, Shostack
   REJECT(1) Northcutt
Voter Comments:
 Shostack> fingerd may respond to 'finger 0@host' with account info
 Frech> Need more reference to establish this 'exposure'.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:finger-unused-accounts(8378)
   We're entering it into our database solely to track
   competition. The only references seem to be product listings:
   http://hq.mcafeeasap.com/vulnerabilities/vuln_data/1000.asp (1002
   Finger 0@host check)
   http://www.ipnsa.com/ipnsa_vuln.htm?step=1000 (Finger 0@host check)
   http://cgi.nessus.org/plugins/dump.php3?id=10069 (Finger zero at host
   feature)


CAN-1999-0198

Phase: Proposed (19990726)

Description:
finger .@host on some systems may print information on some user accounts.

Votes:

   MODIFY(2) Frech, Shostack
   REJECT(1) Northcutt
Voter Comments:
 Shostack> as above
 Frech> Need more reference to establish this 'exposure'.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:finger-unused-accounts(8378)
   We're entering it into our database solely to track
   competition. The only references seem to be product listings:
   http://hq.mcafeeasap.com/vulnerabilities/vuln_data/1000.asp (1004
   Finger .@target-host check)
   http://www.ipnsa.com/ipnsa_vuln.htm?step=1000 (Finger .@target-host
   check )
   http://cgi.nessus.org/plugins/dump.php3?id=10072 (Finger dot at host
   feature)


CAN-1999-0200

Phase: Modified (19991130-01)
Reference: MSKB:Q137853

Description:
Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Shostack
   NOOP(2) Wall, Northcutt
   REJECT(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Shostack> WFTP is not sufficient; is this wu-, ws-, war-, or another?
 Frech> Other have mentioned this before, but it may be WU-FTP.
   POSSIBLY XF:ftp-exec; does this have to do with the Site Exec allowing root
   access without anon FTP or a regular account?
   POSSIBLY XF:wu-ftpd-exec;same as above conditions, but instead from a
   non-anon FTP account and gain root privs.
 Christey> added MSKB reference
 CHANGE> [Christey changed vote from REVOTE to REJECT]
 Christey> The MSKB article may have confused things even more.  There
   were reports of problems in a Windows-based FTP server called
   WFTP (http://www.wftpd.com/) that is not a Microsft FTP
   server.  It's best to just kill this candidate where it
   stands and start fresh.


CAN-1999-0205

Phase: Modified (19990925-01)
Reference: BUGTRAQ:19990708 SM 8.6.12

Description:
Denial of service in Sendmail 8.6.11 and 8.6.12.

Votes:

   ACCEPT(2) Hill, Northcutt
   MODIFY(2) Frech, Prosser
   NOOP(1) Baker
   REVIEWING(2) Ozancin, Christey
Voter Comments:
 Frech> XF:sendmail-alias-dos
 Prosser> additional source
   Bugtraq
   "Re:  SM 8.6.12"
   http://www.securityfocus.com
 Christey> The Bugtraq thread does not provide any proof, including a
   comment by Eric Allman that he hadn't been provided any
   details either.
   
   See http://www.securityfocus.com/templates/archive.pike?list=1&date=1995-07-8&thread=199507131402.KAA02492@bedbugs.net.ohio-state.edu
   for the thread.
 Christey> Change Bugtraq reference date to 19950708.


CAN-1999-0213

Phase: Modified (20001009-01)
Reference: XF:sun-libnsl
Reference: SUNBUG:4305859

Description:
libnsl in Solaris allowed an attacker to perform a denial of service of rpcbind.

Votes:

   ACCEPT(6) Ozancin, Landfield, Cole, Dik, Hill, Blake
   MODIFY(3) Baker, Frech, Levy
   NOOP(4) Bishop, Wall, Armstrong, Meunier
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:sun-libnsl
 Dik> Sun bug #4305859
 Baker> http://xforce.iss.net/static/1204.php	Misc Defensive Info
   http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/172&type=0&nav=sec.sba	Vendor Info
   http://www-1.ibm.com/services/continuity/recover1.nsf/advisories/A1050E354364BF498525680F0077E414/$file/ERS-OAR-E01-1998_074_1.txt	Vendor Info
   http://www.securityfocus.com/archive/1/9749	Misc Defensive Info
 Christey> I don't think this is the bug that everyone thinks it is.
   This candidate came from CyberCop Scanner 2.4/2.5, which
   only reports this as a DoS problem.  If SUN:00172 is an
   advisory for this, then it may be a duplicate of
   CVE-1999-0055.  There appears to be overlap with other
   references as well.  HOWEVER, this particular one deals with a
   DoS in rpcbind - which isn't mentioned in the sources for
   CVE-1999-0055.
 Levy> BID 148


CAN-1999-0216

Phase: Modified (19991203-01)
Reference: BUGTRAQ:19971130 Linux inetd..
Reference: XF:linux-inetd-dos
Reference: HP:HPSBUX9803-077
Reference: XF:hp-inetd

Description:
Denial of service of inetd on Linux through SYN and RST packets.

Votes:

   ACCEPT(1) Hill
   MODIFY(2) Baker, Frech
   RECAST(1) Meunier
Voter Comments:
 Meunier> The location of the vulnerability, whether in the Linux kernel or the
   application, is debatable.  Any program making the same (reasonnable)
   assumption is vulnerable, i.e., implements the same vulnerability:
   "Assumption that TCP-three-way handshake is complete after calling Linux
   kernel function accept(), which returns socket after getting SYN.   Result
   is process death by SIGPIPE"
   Moreover, whether it results in DOS (to third parties) depends on the
   process that made the assumption.
   I think that the present entry should be split, one entry for every
   application that implements the vulnerability (really describing threat
   instances, which is what other people think about when we talk about
   vulnerabilities), and one entry for the Linux kernel that allows the
   vulnerability to happen.
 Frech> XF:hp-inetd
   XF:linux-inetd-dos
 Baker> Since we have an hpux bulletin, the description should not specifically say Linux, should it?  It applies to mulitple OS and should be likely either modified, or in extreme case, recast


CAN-1999-0220

Phase: Proposed (19990728)

Description:
Attackers can do a denial of service of IRC by crashing the server.

Votes:

   NOOP(1) Northcutt
   REJECT(2) Frech, Christey
Voter Comments:
 Frech> Would reconsider if any references were available.
 Christey> No references available, combined with extremely vague
   description, equals REJECT.


CAN-1999-0222

Phase: Proposed (19990714)

Description:
Denial of service in Cisco IOS web server allows attackers to reboot the router using a long URL.

Votes:

   ACCEPT(1) Baker
   MODIFY(3) Frech, Shostack, Levy
   NOOP(3) Balinsky, Wall, Northcutt
   RECAST(1) Ziese
   REJECT(1) Christey
Voter Comments:
 Shostack> I follow cisco announcements and problems pretty closely, and haven't
   seen this.  Source?
 Frech> XF:cisco-web-crash
 Christey> XF:cisco-web-crash has no additional references.  I can't find
   any references in Bugtraq or Cisco either.  This bug is
   supposedly tested by at least one security product, but that
   product's database doesn't have any references either.  So
   a question becomes, how did it make it into at least two
   security companies' databases?
 Levy> BUGTGRAQ: http://www.securityfocus.com/archive/1/60159
   BID 1154
 Ziese> The vulnerability is addressed by a vendor acknowledgement.  This one, if
   recast to reflect that "...after using a long url..." should be replaced
   with
   "...A defect in multiple releases of Cisco IOS software will cause a Cisco
   router or switch to halt and reload if the IOS HTTP service is enabled,
   browsing to "http://router-ip/anytext?/" is attempted, and the enable
   password is supplied when requested. This defect can be exploited to produce
   a denial of service (DoS) attack."
   Then I can accept this and mark it as "Verfied by my Company".  If it can't
   be recast because this (long uri) is diffferent then our release (special
   url construction).
 CHANGE> [Christey changed vote from REVIEWING to REJECT]
 Christey> Elias Levy's suggested reference is CVE-2000-0380.
   I don't think that Kevin's description is really addressing
   this either.  The lack of references and a specific
   description make this candidate unusable, so it should be
   rejected.


CAN-1999-0226

Phase: Proposed (19990728)

Description:
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(1) Frech
   REJECT(1) Christey
Voter Comments:
 Christey> Too general, and no references.
 Frech> XF:nt-frag(528)
   See reference from BugTraq Mailing List, "A New Fragmentation Attack" at
   http://www.securityfocus.com/templates/archive.pike?list=1&date=1997-07-8&ms
   g=Pine.SUN.3.94.970710054440.11707A-100000@dfw.dfw.net


CAN-1999-0229

Phase: Modified (19991228-02)
Reference: MSKB:Q115052

Description:
Denial of service in Windows NT IIS server using ..\..

Votes:

   ACCEPT(2) Baker, Shostack
   MODIFY(2) Frech, Wall
   NOOP(1) Northcutt
   REJECT(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Wall> Denial of service in Windows NT IIS Server 1.0 using ..\...
   Source: Microsoft Knowledge Base Article Q115052 - IIS Server.
 Frech> XF:http-dotdot (not necessarily IIS?)
 Christey> DELREF XF:http-dotdot - it deals with a read/access dot dot
   problem.
 Christey> This actually looks like XF:iis-dot-dot-crash(1638)
   http://xforce.iss.net/static/1638.php
   If so, include the version number (2.0)
   
 CHANGE> [Christey changed vote from REVOTE to REJECT]
 Christey> Bill Wall intended to suggest Q155052, but the affected
   IIS version there is 1.0; the effect is to read files,
   so this sounds like a directory traversal problem,
   instead of an inability to process certain strings.
   
   As a result, this candidate is too general, since it could
   apply to 2 different problems, so it should be REJECTed.
 Christey> Consider adding BID:2218


CAN-1999-0231

Phase: Modified (19991207-01)
Reference: BUGTRAQ:19990317 Re: SLMail 2.6 DoS - Imail also

Description:
Buffer overflow in IP-Switch IMail and Seattle Labs Slmail 2.6 packages using a long VRFY command, causing a denial of service and possibly remote access.

Votes:

   ACCEPT(1) Levy
   NOOP(3) Landfield, Christey, Northcutt
   RECAST(1) Frech
   REVIEWING(1) Ozancin
Voter Comments:
 Frech> XF:slmail-vrfyexpn-overflow (for Slmail v3.2 and below)
   XF:smtp-vrfy-bo (many mail packages)
 Northcutt> (There is no way I will have access to these systems)
 Christey> Some sources report that VRFY and EXPN are both affected.


CAN-1999-0232

Phase: Modified (19991220-01)

Description:
Buffer overflow in NCSA WebServer (version 1.5c) gives remote access.

Votes:

   ACCEPT(2) Hill, Northcutt
   MODIFY(1) Frech
   NOOP(1) Prosser
   REJECT(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Frech> Unable to provide a match due to vague/insufficient description/references.
   Possible matches are:
   XF:ftp-ncsa (probably not, considering you've mentioned the webserver.)
   XF:http-ncsa-longurl (highest probability)
 Christey> CAN-1999-0235 is the one associated with XF:http-ncsa-longurl
   More research is necessary for this one.
 Baker> Since this has no references at all, and is vague and we have a
   CAN for the most likely issue, we should kill this one


CAN-1999-0235

Phase: Modified (19991220-01)
Reference: CERT:CA-95:04
Reference: CIAC:F-11

Description:
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.

Votes:

   ACCEPT(3) Hill, Prosser, Northcutt
   MODIFY(1) Frech
   REJECT(2) Baker, Christey
Voter Comments:
 Frech> XF:http-ncsa-longurl
 Christey> CAN-1999-0235 has the same ref's as CVE-1999-0267
 Baker> Not to mention, the X-force listings of http-ncsa-longurl and http-port both
   refer to the same problem.  This should be rejected as 1999-0267 is the same problem.


CAN-1999-0238

Phase: Proposed (19990623)
Reference: XF:http-cgi-phpfileread

Description:
php.cgi allows attackers to read any file on the system.

Votes:

   ACCEPT(5) Baker, Frech, Collins, Prosser, Northcutt
   NOOP(1) Christey
Voter Comments:
 Prosser> additional source
   AUSCERT External Security Bulletin ESB-97.047
   http://www.auscert.org.au
 Christey> ADDREF BUGTRAQ:19970416 Update on PHP/FI hole
   URL:http://www.dataguard.no/bugtraq/1997_2/0069.html
   The attacker specifies the filename as an argument to the
   program.
   Add "PHP/FI" to description to facilitate search.
   AUSCERT URL is ftp://ftp.auscert.org.au/pub/auscert/ESB/ESB-97.047
 Christey> Consider adding BID:2250


CAN-1999-0240

Phase: Proposed (19990728)

Description:
Some filters or firewalls allow fragmented SYN packets with IP reserved bits in violation of their implemented policy.

Votes:

   ACCEPT(1) Northcutt
   REJECT(1) Frech
Voter Comments:
 Frech> Would reconsider if any references were available.


CAN-1999-0241

Phase: Modified (19990925-01)
Reference: XF:http-xguess-cookie

Description:
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.

Votes:

   ACCEPT(3) Proctor, Hill, Northcutt
   MODIFY(2) Frech, Prosser
   NOOP(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Frech> Also add to references:
   XF:sol-mkcookie
 Prosser> additional source
   Bugtraq
   "X11 cookie hijacker"
   http://www.securityfocus.com
 Christey> The cookie hijacker thread has to do with stealing cookies
   through a file with bad permissions.  I'm not sure the
   X-Force reference identifies this problem either.
 Christey> CIAC:G-04
   URL:http://ciac.llnl.gov/ciac/bulletins/g-04.shtml
   SGI:19960601-01-I
   URL:ftp://patches.sgi.com/support/free/security/advisories/19960601-01-I
   CERT:VB-95:08


CAN-1999-0242

Phase: Modified (20000106-01)
Reference: BUGTRAQ:19951222 mailx-5.5 (slackware /bin/mail) security hole
Reference: XF:linux-pop3d

Description:
Remote attackers can access mail files via POP3 in some Linux systems that are using shadow passwords.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Shostack, Wall, Christey, Northcutt
   REVIEWING(1) Levy
Voter Comments:
 Frech> Ambiguous description: need more detail. Possibly:
   XF:linux-pop3d (mktemp() leads to reading e-mail)
 Christey> At first glance this might look like CAN-1999-0123 or
   CVE-1999-0125, however this particular candidate arises out
   of a brief mention of the problem in a larger posting which
   discusses CAN-1999-0123 (which may be the same bug as
   CVE-1999-0125).  See the following phrase in the Bugtraq
   post: "one such example of this is in.pop3d"
   
   However, the original source of this candidate's description
   explicitly mentions shadowed passwords, though it has no
   references to help out here.


CAN-1999-0243

Phase: Proposed (19990714)

Description:
Linux cfingerd could be exploited to gain root access.

Votes:

   ACCEPT(1) Shostack
   NOOP(4) Baker, Levy, Wall, Northcutt
   REJECT(2) Frech, Christey
Voter Comments:
 Christey> This has no sources; neither does the original database that
   this entry came from.  It's a likely duplicate of 
   CAN-1999-0813.
 Frech> I disagree on the dupe; see Linux-Security Mailing List,
   "[linux-security] Cfinger (Yet more :)" at
   http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as
   if v1.2.3 is vulnerable, perhaps 1.3.0 also. CAN-1999-0813 pertains
   to 1.4.x and below and shows up two years later.
 CHANGE> [Frech changed vote from REVIEWING to REJECT]
 Frech> If the reference I previously supplied is correct, then
   it appears as if the poster modified the source using authorized 
   access to make it vulnerable. Modifying the source in this manner 
   does not qualify as being listed a vulnerability.
   I disagree on the dupe; see Linux-Security Mailing List,
   "[linux-security] Cfinger (Yet more :)" at
   http://www.geocrawler.com/archives/3/92/1996/9/0/2217716/. Seems as
   if v1.2.3 is vulnerable, perhaps 1.3.0 also. CAN-1999-0813 pertains
   to 1.4.x and below and shows up two years later.


CAN-1999-0246

Phase: Proposed (19990630)
Reference: XF:hp-remote

Description:
HP Remote Watch allows a remote user to gain root access.

Votes:

   ACCEPT(4) Frech, Hill, Prosser, Northcutt
   NOOP(1) Baker
   RECAST(1) Christey
Voter Comments:
 Frech> Comment: Determine if it's RemoteWatch or Remote Watch.
 Christey> HP:HPSBUX9610-039 alludes to multiple vulnerabilities in
   Remote Watch (the advisory uses two words, not one, for the
   "Remote Watch" name)
   
   ADDREF BUGTRAQ:19961015 HP/UX Remote Watch (was Re: BoS: SOD remote exploit)
   URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=199610151351.JAA18241@grymoire.crd.ge.com
 Prosser> agree that the advisory mentions two vulnerabilities in Remote
   Watch, one being a socket connection and other with the showdisk utility
   which seems to be a suid vulnerability.  Never get much details on this
   anywhere since the recommendation is to remove the program since it is
   obsolete and superceded by later tools. Believe the biggest concern here is
   to just not run the tool at all.
 Christey> CIAC:H-16
   Also, http://www.cert.org/vendor_bulletins/VB-96.20.hp
   And possibly AUSCERT:AA-96.07 at
   ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.07.HP-UX.Remote.Watch.vul
 Christey> Also BUGTRAQ:19961013 BoS: SOD remote exploit
   http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419969&w=2
   Include "remwatch" in the description to facilitate search.


CAN-1999-0249

Phase: Proposed (19990714)

Description:
Windows NT RSHSVC program allows remote users to execute arbitrary commands.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Wall
   NOOP(2) Shostack, Northcutt
   RECAST(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Wall> Windows NT Rshsvc.exe from the Windows NT Resource Kit allows
   remote
   users to execute arbitrary commands.
   Source: rshsvc.txt from the Windows NT Resource Kit.
 Frech> XF:rsh-svc
 Christey> MSKB:Q158320, last reviewed in January 1999, refers to a case
   where remote users coming from authorized machines are
   allowed access regardless of what .rhosts says.  XF:rsh-svc
   refers to a bug circa 1997 where any remote entity could
   execute commands as system.


CAN-1999-0250

Phase: Modified (20010301-01)
Reference: BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602558319024&w=2
Reference: MISC:http://cr.yp.to/qmail/venema.html
Reference: MISC:http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
Reference: XF:qmail-leng

Description:
Denial of service in Qmail through long SMTP commands.

Votes:

   ACCEPT(2) Meunier, Hill
   MODIFY(1) Frech
   REJECT(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:qmail-rcpt
 Christey> DUPE CAN-1999-0418 and CAN-1999-0144?
 Christey> Dan Bernstein, author of Qmail, says that this is not a
   vulnerability in qmail because Unix has built-in resource
   limits that can restrict the size of a qmail process; other
   limits can be specified by the administrator.  See
   http://cr.yp.to/qmail/venema.html
   
   Significant discussion of this issue took place on the qmail
   list.  The fundamental question appears to be whether 
   application software should set its own limits, or rely
   on limits set by the parent operating system (in this case,
   UNIX).  Also, some people said that the only problem was that
   the suggested configuration was not well documented, but this
   was refuted by others.
   
   See the following threads at
   http://www.ornl.gov/its/archives/mailing-lists/qmail/1997/06/threads.html
   "Denial of service (qmail-smtpd)"
   "qmail-dos-2.c, another denial of service"
   "[PATCH] denial of service"
   "just another qmail denial-of-service"
   "the UNIX way"
   "Time for a reality check"
   
   Also see Bugtraq threads on a different vulnerability that
   is related to this topic:
   BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding
   http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html
 Baker> This appears to be the same vulnerability listed in CAN 1999-0144.  In reading
   through both bugtraq postings, the one that is referenced by 0144 is
   based on a shell code exploit to cause memory exhaustion. The bugtraq
   posting referenced by this entry refers explicitly to the prior
   posting for 0144, and states that the same effect could be
   accomplished by a perl exploit, which was then attached.
 Baker> http://www.securityfocus.com/archive/1/6969    CAN-1999-0144
   http://www.securityfocus.com/archive/1/6970    CAN-1999-0250
   
   Both references should be added to CAN-1999-0144, and CAN-1999-0250
   should likely be rejected.
 CHANGE> [Baker changed vote from REVIEWING to REJECT]
 Christey> XF:qmail-leng no longer exists; check with Andre to see if they
   regarded it as a duplicate as well.
   
   qmail-dos-1.c, as published by Wietse Venema (CAN-1999-0250)
   in "BUGTRAQ:19970612 Denial of service (qmail-smtpd)", does not
   use any RCPT commands.  Instead, it sends long strings
   of "X" characters.  A followup by "super@UFO.ORG" includes
   an exploit that claims to do the same thing; however, that
   exploit does not send long strings of X characters - it sends
   a large number of RCPT commands.  It appears that super@ufo.org
   followed up to the wrong message.
   
   qmail-dos-2.c, as published by Wietse Venema (CAN-1999-0144)
   in "BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack"
   sends a large number of RCPT commands.
   
   ADDREF BUGTRAQ:19970612 Denial of service (qmail-smtpd)
   ADDREF BUGTRAQ:19970612 qmail-dos-2.c, another denial of service attack
   
   Also see a related thread:
   BUGTRAQ:19990308 SMTP server account probing
   http://marc.theaimsgroup.com/?l=bugtraq&m=92100018214316&w=2
   
   This also describes a problem with mail servers not being able
   to handle too many "RCPT TO" requests.  A followup message
   notes that application-level protection is used in Sendmail
   to prevent this:
   BUGTRAQ:19990309 Re: SMTP server account probing
   http://marc.theaimsgroup.com/?l=bugtraq&m=92101584629263&w=2
   The person further says, "This attack can easily be
   prevented with configuration methods."


CAN-1999-0253

Phase: Modified (2000106-01)
Reference: XF:http-iis-2e
Reference: L0PHT:19970319

Description:
IIS 3.0 with the iis-fix hotfix installed allows remote intruders to read source code for ASP programs by using a %2e instead of a . (dot) in the URL.

Votes:

   ACCEPT(9) Baker, Frech, Bishop, Landfield, Cole, Armstrong, Collins, Blake, Northcutt
   MODIFY(1) LeBlanc
   NOOP(3) Ozancin, Wall, Prosser
   REVIEWING(1) Christey
Voter Comments:
 Christey> This is a problem that was introduced after patching a
   previous dot bug with the iis-fix hotfix (see CAN-1999-0154).
   Since the hotfix introduced the problem, this should be
   treated as a seaprate issue.
 Wall> Agree with the comment.
 LeBlanc> - this one is so old, I don't remember it at all and can't verify or
   deny the issue. If you can find some documentation that says we fixed it (KB
   article, hotfix, something), then I would change this to ACCEPT
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> BID:1814
   URL:http://www.securityfocus.com/bid/1814


CAN-1999-0254

Phase: Proposed (19990726)
Reference: ISS:Hidden SNMP community in HP OpenView
Reference: XF:hpov-hidden-snmp-comm

Description:
A hidden SNMP community string in HP OpenView allows remote attackers to modify MIB tables and obtain sensitive information.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Christey> What is the proper level of abstraction to use here?  Should
   we have a separate entry for each different default community
   string?  See:
   http://cve.mitre.org/Board_Sponsors/archives/msg00242.html and
   http://cve.mitre.org/Board_Sponsors/archives/msg00250.html
   http://cve.mitre.org/Board_Sponsors/archives/msg00251.html
   
   Until the associated content decisions have been approved
   by the Editorial Board, this candidate cannot be accepted
   for inclusion in CVE.


CAN-1999-0255

Phase: Proposed (19990623)

Description:
Buffer overflow in ircd allows arbitrary command execution.

Votes:

   ACCEPT(3) Baker, Hill, Northcutt
   MODIFY(1) Frech
   NOOP(1) Prosser
   REJECT(1) Christey
Voter Comments:
 Frech> XF:irc-bo
 Christey> This is too general and doesn't have any references.  The
   XF reference doesn't appear toe xist any more.
   
   Perhaps this reference would help:
   BUGTRAQ:19970701 ircd buffer overflow
 Baker> It appears that the XForce entry has been corrected, and there is a patch posted in the original bugtraq post.


CAN-1999-0257

Phase: Proposed (19990726)

Description:
Nestea variation of teardrop IP fragmentation denial of service.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:nestea-linux-dos
 Christey> Not sure how many separate "instances" of Teardrop
   and its ilk.  Also see comments on CAN-1999-0001.
   
   See: CAN-1999-0015, CAN-1999-0104, CAN-1999-0257, CAN-1999-0258
   
   Is CAN-1999-0001 the same as CVE-1999-0052?  That one is related
   to nestea (CAN-1999-0257) and probably the one described in
   BUGTRAQ:19981023 nestea v2 against freebsd 3.0-Release
   The patch for nestea is in ip_input.c around line 750.
   The patches for CAN-1999-0001 are in lines 388&446.  So, 
   CAN-1999-0001 is different from CAN-1999-0257 and CVE-1999-0052.
   The FreeBSD patch for CVE-1999-0052 is in line 750.
   So, CAN-1999-0257 and CVE-1999-0052 may be the same, though
   CVE-1999-0052 should be RECAST since this bug affects Linux
   and other OSes besides FreeBSD.
   
   Also see BUGTRAQ:19990909 CISCO and nestea.
   
   Finally, note that there is no fundamental difference between
   nestea and nestea2/nestea-v2; they are different ports that
   exploit the same problem.
   
   The original nestea advisory is at
   http://www.technotronic.com/rhino9/advisories/06.htm
   but notice that the suggested fix is in line 375 of
   ip_fragment.c, not ip_input.c.
 Christey> See the SCO advisory at:
   http://www.securityfocus.com/templates/advisory.html?id=1411
   which may further clarify the issue.
 Christey> BUGTRAQ:19980501 nestea does other things
   http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925819&w=2
   BUGTRAQ:19980508 nestea2 and HP Jet Direct cards.
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925870&w=2
   BUGTRAQ:19981027 nestea v2 against freebsd 3.0-Release
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90951521507669&w=2
   
   Nestea source code is in
   MISC:http://oliver.efri.hr/~crv/security/bugs/Linux/ipfrag6.html


CAN-1999-0258

Phase: Proposed (19990726)

Description:
Bonk variation of teardrop IP fragmentation denial of service.

Votes:

   MODIFY(2) Frech, Wall
   REVIEWING(1) Christey
Voter Comments:
 Wall> Reference Q179129
 Frech> XF:teardrop-mod
 Christey> Not sure how many separate "instances" of Teardrop there are.
   See: CAN-1999-0015, CAN-1999-0104, CAN-1999-0257, CAN-1999-0258
 Christey> See the SCO advisory at:
   http://www.securityfocus.com/templates/advisory.html?id=1411
   which may further clarify the issue.
 Christey> BUGTRAQ:19980108 bonk.c
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88429524325956&w=2
   NTBUGTRAQ:19980108 bonk.c
   URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88433857200304&w=2
   NTBUGTRAQ:19980109 Re: Bonk.c
   URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88441302913269&w=2
   NTBUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks
   URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=88901842000424&w=2
   BUGTRAQ:19980304 Update on wide-spread NewTear Denial of Service attacks
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88903296104349&w=2
   CIAC:I-031a
   http://ciac.llnl.gov/ciac/bulletins/i-031a.shtml
   
   CERT summary CS-98.02 implies that bonk, boink, and newtear
   all exploit the same vulnerability.


CAN-1999-0261

Phase: Modified (20000827-01)
Reference: BUGTRAQ:19980504 Netmanage Holes
Reference: MISC:http://www.insecure.org/sploits/netmanage.chameleon.overflows.html

Description:
Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Landfield
   NOOP(3) Ozancin, Christey, Northcutt
Voter Comments:
 Frech> XF:chamelion-smtp-dos
 Landfield> - Specify what "a crash" means.
 Christey> ADDREF XF:chameleon-smtp-dos ?  (but it's not on the web site)
 Christey> Consider adding BID:2387


CAN-1999-0271

Phase: Modified (19990925-01)
Reference: BUGTRAQ:19980115 pnserver exploit..
Reference: BUGTRAQ:19980817 Re: Real Audio Server Version 5 bug?

Description:
Progressive Networks Real Video server (pnserver) can be crashed remotely.

Votes:

   ACCEPT(3) Baker, Blake, Northcutt
   MODIFY(1) Frech
   NOOP(1) Prosser
   REVIEWING(1) Christey
Voter Comments:
 Christey> Problem confirmed by RealServer vendor (URL listed in Bugtraq
   posting), but may be multiple codebases since several
   Real Audio servers are affected.
   
   Also, this may be the same as BUGTRAQ:19991105 RealNetworks RealServer G2 buffer overflow.
   See CVE-1999-0896
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> ADDREF XF:realvideo-telnet-dos


CAN-1999-0282

Phase: Proposed (19990623)
Reference: CERT:CA-95.12.sun.loadmodule.vul

Description:
Vulnerabilities in loadmodule and modload programs in SunOS and OpenWindows

Votes:

   ACCEPT(1) Dik
   MODIFY(1) Frech
   NOOP(2) Ozancin, Christey
   RECAST(1) Prosser
Voter Comments:
 Frech> XF:sun-loadmodule
   XF:sun-modload (CERT CA-93.18 very old!)
 Prosser> Believe the reference given, 95-12,  is referencing a later
   loadmodule(8) setuid problem in the X11/NeWS windowing system.  There is an
   earlier, similar setuid vulnerability in the CA-93.18, CIAC G-02 advisories
   for the SunOS 4.1.x/Solbourne and OpenWindow 3.0.  In fact, there may be the
   same as the HP patches are 100448-02 for the 93 loadmodule/modload
   vulnerability and 100448-03 for the 95 loadmodule vulnerability which
   normally indicated a patch update.  Looks like the original patch either
   didn't completely fix the problem or it resurfaced in X11 NeWS.  Can't tell
   much beyond that and this is my opinion only as have no way to check it.  
   Which one is this CVE referencing?  I accept both.
 Dik> There are three similar Sun bug ids associated with the patches.
   1076118 loadmodule has a security vulnerability
   1148753 loadmodule has a security vulnerability
   1222192 loadmodule has a security vulnerability
   as well as:
   1137491
   Ancient stuff.
 Christey> Add period to the end of the description.


CAN-1999-0283

Phase: Modified (19991203-01)
Reference: BUGTRAQ:19970716 Viewable .jhtml source with JavaWebServer
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88256790401004&w=2

Description:
The Java Web Server would allow remote users to obtain the source code for CGI programs.

Votes:

   ACCEPT(7) Northcutt, Baker, Wall, Cole, Dik, Collins, Blake
   MODIFY(1) Frech
   NOOP(5) Bishop, Landfield, Armstrong, Christey, Prosser
   REVIEWING(1) Ozancin
Voter Comments:
 Wall> Acknowledged by vendor at
   http://www.sun.com/software/jwebserver/techinfo/jws112info.html.
 Baker> Vulnerability Reference (HTML)	Reference Type
   http://www.securityfocus.com/archive/1/7260	Misc Defensive Info
   http://www.sun.com/software/jwebserver/techinfo/jws112info.html Vendor Info
 Christey> BID:1891
   URL:http://www.securityfocus.com/bid/1891
 Christey> Add version number (1.1 beta) and details of attack (appending
   a . or a \)
   
   The Sun URL referenced by Dave Baker no longer exists, so I
   wasn't able to verify that it addressed the problem described
   in the Bugtraq post.  This might not even be Sun's
   "Java Web Server," as CAN-2001-0186 describes some product
   called "Free Java Web Server"
 Dik> There appears to be some confusion.
   
   The particular bug seems to be on in JWS 1.1beta or 1.1 which was fixed
   in 1.1.2 (get foo.jthml source by appending "." of "\" to URL)
   
   There are other bugs that give access and that require a configuration
   change.
   
   http://www.sun.com/software/jwebserver/techinfo/security_advisory.html
 Christey> Need to make sure to create CAN's for the other bugs,
   as documented in:
   NTBUGTRAQ:19980724 Alert: New Source Bug Affect Sun JWS
   http://marc.theaimsgroup.com/?l=ntbugtraq&m=90222454131622&w=2
   BUGTRAQ:19980725 Alert: New Source Bug Affect Sun JWS
   http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526086&w=2
   The reported bugs are:
   1) file read by appending %20
   2) Directly call /servlet/file
   URL:http://www.sddt.com/cgi-bin/Subscriber?/library/98/07/24/tbd.html
   #2 is explicitly mentioned in the Sun advisory for
   CAN-1999-0283.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:javawebserver-cgi-source(5383)


CAN-1999-0284

Phase: Proposed (19990623)
Reference: XF:smtp-helo-bo

Description:
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.

Votes:

   ACCEPT(2) Northcutt, Blake
   MODIFY(3) Frech, Ozancin, Levy
   REVIEWING(1) Christey
Voter Comments:
 Frech> "Windows NT-based mail servers" (A trademark thing, and for clarification)
   XF:mdaemon-helo-bo
   XF:lotus-notes-helo-crash
   XF:slmail-helo-overflow
   XF:smtp-helo-bo (mentions several products)
   XF:smtp-exchangedos
 Levy> - Need one per software. Each one should be its own
   vulnerability.
 Ozancin> => Windows NT is correct
 Christey> These are probably multiple codebases, so we'll need to use
   dot notation.  Also need to see if this should be merged
   with CAN-1999-0098 (Sendmail SMTP HELO).


CAN-1999-0285

Phase: Proposed (19990630)

Description:
Denial of service in telnet from the Windows NT Resource Kit, by opening then immediately closing a connection.

Votes:

   ACCEPT(1) Hill
   NOOP(1) Wall
   REJECT(2) Frech, Christey
Voter Comments:
 Christey> No references, no information.
 CHANGE> [Frech changed vote from REVIEWING to REJECT]
 Frech> No references; closest documented match is with
   CVE-2001-0346, but that's for Windows 2000.


CAN-1999-0286

Phase: Proposed (19990714)

Description:
In some NT web servers, appending a space at the end of a URL may allow attackers to read source code for active pages.

Votes:

   ACCEPT(3) Shostack, Cole, Armstrong
   MODIFY(3) Levy, Wall, Blake
   NOOP(5) Northcutt, Baker, Bishop, Ozancin, Landfield
   REJECT(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Wall> In some NT web servers, appending a dot at the end of a URL may
   allows attackers to read source code for active pages.
   Source:  MS Knowledge Base Article Q163485 - "Active Server Pages Script Appears
   in Browser"
 Frech> In the meantime, reword description as 'Windows NT' (trademark issue)
 Christey> Q163485 does not refer to a space, it refers to a dot.
   However, I don't have other references.
   
   Reading source code with a dot appended is in CAN-1999-0154,
   which will be proposed.  A subsequent bug similar to the
   dot bug is CAN-1999-0253.
 Levy> NTBUGTRAQ: http://www.securityfocus.com/archive/2/22014
   NTBUGTRAQ: http://www.securityfocus.com/archive/2/22019
   BID 273
 Blake> Reference:  http://www.allaire.com/handlers/index.cfm?ID=10967
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 CHANGE> [Frech changed vote from REVIEWING to REJECT]
 Frech> BID articles)


CAN-1999-0287

Phase: Proposed (19990714)

Description:
Vulnerability in the Wguest CGI program.

Votes:

   MODIFY(2) Frech, Shostack
   NOOP(4) Northcutt, Levy, Wall, Blake
   REJECT(2) Baker, Christey
Voter Comments:
 Shostack> allows file reading
 Frech> XF:http-cgi-webcom-guestbook
 Christey> CAN-1999-0287 is probably a duplicate of CAN-1999-0467.  In
   NTBUGTRAQ:19990409 Webcom's CGI Guestbook for Win32 web servers
   Mnemonix says that he had previously reported on a similar
   problem.  Let's refer to the NTBugtraq posting as
   CAN-1999-0467.  We will refer to the "previous report" as
   CAN-1999-0287, which could be found at:
   http://oliver.efri.hr/~crv/security/bugs/NT/httpd41.html
   
   0287 describes an exploit via the "template" hidden variable.
   The exploit describes manually editing the HTML form to
   change the filename to read from the template variable.
   
   The exploit as described in 0467 encodes the template variable
   directly into the URL.  However, hidden variables are also
   encoded into the URL, which would have looked the same to
   the web server regardless of the exploit.  Therefore 0287
   and 0467 are the same.
 Christey> BID:2024


CAN-1999-0298

Phase: Modified (20000524-01)
Reference: NAI:19970205 Vulnerabilities in Ypbind when run with -ypset/-ypsetme
Reference: URL:http://www.nai.com/nai_labs/asp_set/advisory/06_ypbindsetme_adv.asp

Description:
ypbind with -ypset and -ypsetme options activated in Linux Slackware and SunOS allows local and remote attackers to overwrite files via a .. (dot dot) attack.

Votes:

   ACCEPT(4) Northcutt, Levy, Cole, Dik
   MODIFY(1) Frech
   NOOP(3) Baker, Shostack, Christey
Voter Comments:
 Christey> ADDREF BID:1441
   URL:http://www.securityfocus.com/bid/1441
 Dik> If you run with "-ypset", then you're always insecure.
   With ypsetme, only root on the local host
   can run ypset in Solaris 2.x+.
   Probably true for SunOS 4, hence my vote.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> ADDREF XF:ypbind-ypset-root
 CHANGE> [Dik changed vote from REVIEWING to ACCEPT]
 Dik> This vulnerability does exist in SunOS 4.x in non default configurations.
   In Solaris 2.x, the vulnerability only applies to files named "cache_binding"
   and not all files ending in .2
   Both releases are not vulnerable in the default configuration (both
   disabllow ypset by default which prevents this problem from occurring)


CAN-1999-0306

Phase: Proposed (19990714)
Reference: XF:hp-xlock

Description:
buffer overflow in HP xlock program.

Votes:

   ACCEPT(3) Northcutt, Baker, Frech
   MODIFY(1) Prosser
   NOOP(1) Shostack
   REJECT(1) Christey
Voter Comments:
 Prosser> This is another of those with multiple affected OSs.
   Refs:  CA-97.13, http://207.237.120.45/linux/xlock-exploit.txt,
   HPSBUX9711-073, SGI 19970502-02-PX, Sun Bulletin 000150
 Christey> XF:hp-xlock points to SGI:19970502-02-PX which says this is
   the same problem as in CERT:CA-97.13, which is CVE-1999-0038.


CAN-1999-0307

Phase: Modified (19991207-01)
Reference: BUGTRAQ:19961116 This week: turn me on, dead man
Reference: XF:hpux-cstm-bo

Description:
Buffer overflow in HP-UX cstm program allows local users to gain root privileges.

Votes:

   ACCEPT(2) Northcutt, Frech
   NOOP(3) Prosser, Baker, Shostack
   RECAST(1) Christey
Voter Comments:
 Prosser> only ref I can find is an old SOD exploit on
   www.outpost9.com
 Christey> MERGE CAN-1999-0336 (the exact exploit works with both
   cstm and mstm, which are clearly part of the same package,
   so CD:SF-EXEC says to merge them.)
   
   Also, there does not seem to be any recognition of this problem
   by HP.  The only other information besides the Bugtraq post
   is the SOD exploit.
   
   See the original post:
   http://www.securityfocus.com/templates/archive.pike?list=1&date=1996-11-15&msg=Pine.LNX.3.91.961116112242.15276J-100000@underground.org


CAN-1999-0317

Phase: Modified (19991216-01)
Reference: BUGTRAQ:19990818 slackware-3.5 /bin/su buffer overflow
Reference: XF:su-bo

Description:
Buffer overflow in Linux su command gives root access to local users.

Votes:

   ACCEPT(3) Northcutt, Frech, Hill
   NOOP(1) Prosser
   RECAST(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Christey> DUPE CAN-1999-0845?
   Also, ADDREF XF:unixware-su-username-bo
   A report summary by Aleph One states that nobody was able to
   confirm this problem on any Linux distribution.
 Baker> If this is the same as the unixware, the n it is a dupe of 1999-0845.  There is about a two and half month difference in the bugtraq reporting of these.
   Sounds like the same bug however...
 Christey> XF:su-bo no longer seems to exist.
   How about XF:linux-subo(734) ?
   http://xforce.iss.net/static/734.php
   
   BID:475 also seems to describe the same problem
   (http://www.securityfocus.com/bid/475) in which case,
   vsyslog is blamed in:
   BUGTRAQ:19971220 Linux vsyslog() overflow
   http://www.securityfocus.com/archive/1/8274


CAN-1999-0319

Phase: Proposed (19990623)
Reference: XF:xmcd-tiflestr

Description:
Buffer overflow in xmcd 2.1 allows local users to gain access through a user resource setting.

Votes:

   ACCEPT(3) Northcutt, Frech, Hill
   NOOP(2) Prosser, Baker
   REVIEWING(1) Christey
Voter Comments:
 Christey> BUGTRAQ:19961126 Security Problems in XMCD 2.1
   A followup to this post says that xmcd is not suid here.


CAN-1999-0330

Phase: Modified (20000105-01)
Reference: BUGTRAQ:19940101 (No Subject)
Reference: XF:bdash-bo

Description:
Linux bdash game has a buffer overflow that allows local users to gain root access.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Northcutt, Shostack, Wall
   REVIEWING(1) Levy
Voter Comments:
 Frech> XF:bdash-bo


CAN-1999-0331

Phase: Proposed (19990714)
Reference: XF:msie-bo

Description:
Buffer overflow in Internet Explorer 4.0(1)

Votes:

   ACCEPT(2) Northcutt, Baker
   MODIFY(2) Frech, Shostack
   RECAST(1) Prosser
   REJECT(2) LeBlanc, Christey
Voter Comments:
 Shostack> this is a high cardinality item
 Prosser> needs to be more specific.
 Frech> Replace reference with XF:iemk-bug (msie-bo is obsolete and a vague
   duplicate)
   Description (from xfdb): Some versions of Internet Explorer for Windows
   contain a vulnerability that may crash the broswer when a malicious web site
   contains a certain kind of URL (that begins with "mk://") with more
   characters than the browser supports. 
 Christey> The description is too vague.
 LeBlanc> too vague
 Christey> Add period to the end of the description.


CAN-1999-0333

Phase: Modified (19990925-01)
Reference: RSI:RSI.0009.09-08-98.HP-UX.OMNIBACK
Reference: HP:HPSBUX9810-085
Reference: XF:omniback-remote

Description:
HP OpenView Omniback allows remote execution of commands as root via spoofing, and local users can gain root access via a symlink attack.

Votes:

   ACCEPT(1) Frech
   MODIFY(1) Prosser
   RECAST(1) Christey
Voter Comments:
 Prosser> additional source
   HP Security Bulletin 85
   http://us-support.external.hp.com
   http://europe-support.external.hp.com
 Christey> Two separate bugs, so SF-LOC says this candidate should be
   split
 Christey> ADDREF CIAC:J-007
   URL:http://ciac.llnl.gov/ciac/bulletins/j-007.shtml


CAN-1999-0336

Phase: Modified (19991207-01)
Reference: BUGTRAQ:19961116 This week: turn me on, dead man
Reference: XF:hpux-mstm-bo

Description:
Buffer overflow in mstm in HP-UX allows local users to gain root access.

Votes:

   ACCEPT(2) Northcutt, Frech
   NOOP(3) Prosser, Baker, Shostack
   RECAST(1) Christey
Voter Comments:
 Prosser> same as CAN-1999-0307, only ref I can find is an old SOD
   exploit on www.outpost9.com
 Christey> MERGE CAN-1999-0307 (the exact exploit works with both
   cstm and mstm, which are clearly part of the same package,
   so CD:SF-EXEC says to merge them.)
   
   Also, there does not seem to be any recognition of this problem
   by HP.  The only other information besides the Bugtraq post
   is the SOD exploit.


CAN-1999-0345

Phase: Proposed (19990728)

Description:
Jolt ICMP attack causes a denial of service in Windows 95 and Windows NT systems.

Votes:

   ACCEPT(2) Cole, Blake
   MODIFY(2) Frech, Wall
   NOOP(4) Northcutt, Bishop, Ozancin, Landfield
   RECAST(1) Meunier
   REJECT(4) Baker, Levy, LeBlanc, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Wall> Invalid ICMP datagram fragments causes a denial of service in Windows 95 and
   Windows NT systems.
   Reference: Q154174.
   Jolt is also known as sPING, ICMP bug, Icenewk, and Ping of Death.
   It is a modified teardrop 2 attack.  
 Frech> XF:nt-ssping
   ADDREF XF:ping-death
   ADDREF XF:teardrop-mod
   ADDREF XF:mpeix-echo-request-dos
 Christey> I can't tell whether the Jolt exploit at:
   
   http://www.securityfocus.com/templates/archive.pike?list=1&date=1997-06-28&msg=Pine.BSF.3.95q.970629163422.3264A-200000@apollo.tomco.net
   
   is exploiting any different flaw than teardrop does.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Baker> Jolt (original) is basically just a fragmented oversized ICMP that
   kills Win boxes ala Ping of Death.
   Teardrop is altering the offset in fragmented tcp packets so that the
   end of subsequent fragments is inside first packet...
   Teardrop 2 is UDP packets, if I remember right.
   Seems like Jolt (original, not jolt 2) is just exploit code that
   creates a ping of death (CVE 1999-0128)
 Levy> I tend to agree with Baker.
 CHANGE> [Armstrong changed vote from REVIEWING to REJECT]
 Armstrong> This code does not use fragment overlap.  It is simply a large ICMP echo request.
 Christey> See the SCO advisory at:
   http://www.securityfocus.com/templates/advisory.html?id=1411
   which may further clarify the issue.
 LeBlanc> This is a hodge-podge of DoS attacks. Jolt isn't the same
   thing as ping of death - POD was an oversized ICMP packet, Jolt froze
   Linux and Solaris (and I think not NT), IIRC Jolt2 did get NT boxes.
   Teardrop and teardrop2 were related attacks (usually ICMP frag attacks),
   but each of these is a distinct vulnerability, affected a discrete group
   of systems, and should have distinct CVE numbers. CVE entries should be
   precise as to what the problem is.
 Meunier> I agree with Leblanc in that Jolt is multi-faceted.  Jolt has
   characteristics of Ping of Death AND teardrop, but it doesn't do
   either exactly.  Moreover, it sends a truncated IP fragment.  I
   disagree with Armstrong; jolt uses overlapping fragments.  It's not a
   simple ping of death either.  It may be that the author's intent was
   to construct a "super attack" somehow combining elements of other
   vulnerabilities to try to make it more potent.  In any case it
   succeeded in confusing the CVE board :-).
   
   I notice that Jolt uses echo replies (type 0) instead of echo
   requests (to get past firewalls?).  Jolt is peculiar in that it also
   sends numerous overlapping fragments.  The "Pascal Simulator" :-) says
   it sends:
   
   - 172 fragments of length 400 with offset starting at 5120 and
   increasing by about 47 (odd arithmetic of 5120 OR ((n* 380) >> 3)),
   which eventually results in sending fragments inside an already
   covered area once ((n* 380) >> 3) is greater than 5120, which occurs
   when n is reaches 108.  This would look a bit like TearDrop if
   fragments were reassembled on-the-fly.
   
   - 1 fragment such that the total length of all the fragments
   is greater than 65535 (my calculation is 172*380 + 418 = 65778; the
   comment about 65538 must be wrong).  The last packet is size 418
   according to the IP header but the buffer is of size 400.  The sendto
   takes as argument the size of the buffer so a truncated packet is
   sent.
   
   So, I am not sure if the problem is because the last packet
   doesn't extend to the payload it says it has or because the total size
   of all fragments is greater than 65535.  The author says it may take
   more than one sending, so perhaps this has to do with an incorrect
   error handling and recovery.  One would need to experiment and isolate
   each of those characteristics and test them independently.  Inasmuch
   as each of those things is likely a different vulnerability, then I
   agree with Leblanc that this entry should be split.  I'll try that if
   I ever get bored.  Jolt 2 should also have a different entry (see
   below).
   
   Jolt 2 runs in an infinite loop, sending the same fragmented
   IP packet, which can pretend to be "ICMP" or "UDP" data; however this
   is meaningless, as it's just a late fragment of an IP packet.  The
   attack works only as long as packets are sent.  According to
   http://www.securityfocus.com/archive/1/62170 the packets are
   truncated, and would overflow over the 65535 byte limit, which is
   similar to Jolt.  Note that Jolt does send that much data whereas
   jolt2 doesn't.  Since jolt2 is simpler and narrower than jolt, and it
   has weaker consequences, I believe that it's a different
   vulnerability.
   
   "Jolt 2 vulnerability causes a temporary denial-of-service in
   Windows-type OSes" would be a title for it.


CAN-1999-0347

Phase: Proposed (19990623)
Reference: BUGTRAQ:Jan26,1999
Reference: NTBUGTRAQ:Jan28,1999

Description:
Javascript bug in Internet Explorer 4.01 by adding %01URL allows reading local files and spoofing of web pages from other sites.

Votes:

   ACCEPT(4) Northcutt, Baker, Levy, LeBlanc
   MODIFY(2) Prosser, Frech
   REVIEWING(1) Christey
Voter Comments:
 Prosser> this is a modified Cross-Frame vulnerability that circumvents
   the original Cross-Frame Patch.  Addressed in MS Bulletin MS99.012
   http://www.microsoft.com/security/bulletins/ms99-012.asp
 Christey> Duplicate of CAN-1999-0490?
 LeBlanc> If Prosser is correct that this is MS99-012, accept
 Christey> BUGTRAQ:19990126 Javascript ecurity bug in Internet Explorer
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91745430007021&w=2
   NTBUGTRAQ:19990128 Javascript %01 bug in Internet Explorer
   URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91756771207719&w=2
   BID:197
   URL:http://www.securityfocus.com/bid/197
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:ie-window-spoof(2069)


CAN-1999-0352

Phase: Proposed (19990721)
Reference: ISS:Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software
Reference: XF:controlit-passwd-encrypt

Description:
ControlIT 4.5 and earlier (aka Remotely Possible) has weak password encryption.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(2) Northcutt, Wall
   RECAST(1) Ozancin
Voter Comments:
 Ozancin> Can we combine this with CAN-1999-0356 - ControlIT(tm) 4.5 and earlier uses
   weak encryption.


CAN-1999-0354

Phase: Proposed (19990623)
Reference: NTBUGTRAQ:Jan27,1999
Reference: MS:MS99-002
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-002.asp

Description:
Internet Explorer 4.x or 5.x with Word 97 allows arbitrary execution of Visual Basic programs to the IE client through the Word 97 template, which doesn't warn the user that the template contains executable content. Also applies to Outlook when the client views a malicious email message.

Votes:

   ACCEPT(2) Ozancin, Wall
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:word97-template-macro
 Christey> CHANGEREF NTBUGTRAQ:19990127 IE 4/5/Outlook + Word 97 security hole
   URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91747570922757&w=2
   BID:196
   http://www.securityfocus.com/bid/196
 Christey> MSKB:Q214652
   http://support.microsoft.com/support/kb/articles/q214/6/52.asp


CAN-1999-0356

Phase: Proposed (19990721)
Reference: ISS:Multiple vulnerabilities in ControlIT(tm) (formerly Remotely Possible/32) enterprise management software
Reference: XF:controlit-bookfile-access

Description:
ControlIT v4.5 and earlier uses weak encryption to store usernames and passwords in an address book.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(2) Northcutt, Wall
   RECAST(1) Ozancin

CAN-1999-0359

Phase: Proposed (20010214)
Reference: BUGTRAQ:19990127 UNIX shell modem access vulnerabilities
Reference: XF:ptylogin-dos

Description:
ptylogin in Unix systems allows users to perform a denial of service by locking out modems, dial out with that modem, or obtain passwords.

Votes:

   ACCEPT(2) Frech, Cole
Voter Comments:
 Frech> XF:ptylogin-dos 


CAN-1999-0360

Phase: Modified (20000530-01)
Reference: BUGTRAQ:19990130 Security Advisory for Internet Information Server 4 with Site
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91763097004101&w=2
Reference: NTBUGTRAQ:Jan29,1999

Description:
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing them to execute commands remotely.

Votes:

   ACCEPT(6) Northcutt, Wall, Landfield, Cole, Collins, Blake
   MODIFY(3) Baker, Frech, LeBlanc
   NOOP(4) Prosser, Ozancin, Armstrong, Christey
Voter Comments:
 Christey> I can't find the original Bugtraq posting (it appears that
   mnemonix discovered the problem).
 LeBlanc> - if there was a fix or a KB article, I'd ACCEPT. A vuln based on a
   BUGTRAQ posting we can't find could be anything. 
 Baker> Vulnerability Reference (HTML)	Reference Type
   http://www.securityfocus.com/archive/1/12218	Misc Defensive InfoVulnerability Reference (HTML)	Reference Type
   THis is the URL for the Bugtraq posting.  It was cross posted to
   NT Bugtraq as well, but identical text.  It was Mnemonix...
 Christey> BID:1811
   URL:http://www.securityfocus.com/bid/1811
 Christey> CHANGEREF BUGTRAQ add "Server 2." to the subject.
   Also standardize NTBUGTRAQ reference title.
 Christey> Add "uploadn.asp" to the description.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:siteserver-user-dir-permissions(5384)


CAN-1999-0361

Phase: Proposed (19990728)
Reference: BUGTRAQ:Jan29,1999

Description:
NetWare version of LaserFiche stores usernames and passwords unencrypted, and allows administrative changes without logging.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Northcutt, Wall
Voter Comments:
 Frech> XF:compulink-pw-laserfiche(1679)
   Normalize BUGTRAQ reference to:
   BUGTRAQ:19990129 Compulink LaserFiche Client/Server - unencrypted passwords


CAN-1999-0364

Phase: Modified (20000426-01)
Reference: BUGTRAQ:19990204 Microsoft Access 97 Stores Database Password as Plaintext
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91816470220259&w=2

Description:
Microsoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.

Votes:

   ACCEPT(2) Baker, LeBlanc
   MODIFY(1) Frech
   NOOP(2) Northcutt, Wall
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:access-weak-passwords(1774)
   An older published reference (from our own Adam) would be
   better:
   ailab.coderpunks Newsgroup, 1998/06/23 "Re: MS Access 2.0"
   http://x15.dejanews.com/[ST_rn=ps]/getdoc.xp?AN=365308578&CONTEXT=9192
   07028.1462108427&hitnum=1


CAN-1999-0370

Phase: Modified (19991210-01)
Reference: SUN:00184
Reference: BID:165
Reference: URL:http://www.securityfocus.com/bid/165

Description:
In Sun Solaris and SunOS, man and catman contain vulnerabilities that allow overwriting arbitrary files.

Votes:

   ACCEPT(4) Prosser, Northcutt, Baker, Dik
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Reference: XF:sun-man
 Christey> ADDREF CIAC:J-028
   
   Is the Linux man symlink problem the same as the one for Sun?
   See BUGTRAQ:19990602 /tmp symlink problems in SuSE Linux 6.1
   Also see BID:305
 Dik> sun bug 4154565


CAN-1999-0381

Phase: Proposed (19990726)
Reference: BUGTRAQ:19990225 SUPER buffer overflow
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.3.96.990225011801.12757A-100000@eleet
Reference: XF:linux-super-logging-bo
Reference: BID:342
Reference: URL:http://www.securityfocus.com/bid/342

Description:
super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access.

Votes:

   ACCEPT(7) Baker, Frech, Ozancin, Levy, Landfield, Cole, Blake
   MODIFY(1) Bishop
   NOOP(2) Wall, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Christey> Is this the same as CVE-1999-0373?  They both have the same
   X-Force reference.
   
   BID:342 suggests that there are two.
   
   http://www.debian.org/security/1999/19990215a suggests
   that there are two.  However, CVE-1999-0373 is written up in
   a fashion that is too general; and both XF:linux-super-bo and
   XF:linux-super-logging-bo refer to CVE-1999-0373.
   CVE-1999-0373 may need to be split.
   
 Frech> From what I can surmise, ISS released the original advisory (attached to
   linux-super-bo), and Sekure SDI expanded on it by releasing another related
   overflow in syslog (which is linux-super-logging-bo).
   
   When I was originally assigning these issues, I placed both XF references
   and the ISS advisory on the -0373 candidate, since there was nothing else
   available. Based on the information above, I'd request that
   XF:linux-super-logging-bo be removed from CVE-1999-0373.
 Christey> Given Andre's feedback, these are different issues.
   CVE-1999-0373 does not need to be split because the ISS
   reference is sufficient to distinguish that CVE from this
   candidate; however, the CVE-1999-0373 description should
   probably be modified slightly.
 Bishop> (as indicated by Christey)
 CHANGE> [Cole changed vote from NOOP to ACCEPT]
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> There are 2 bugs, as confirmed by the super author at:
   BUGTRAQ:19990226 Buffer Overflow in Super (new)
   http://www.securityfocus.com/archive/1/12713
   BID:397 also seems to cover this one, and it may cover
   CVE-1999-0373 as well.


CAN-1999-0389

Phase: Modified (19991207-01)
Reference: DEBIAN:19990104
Reference: BUGTRAQ:19990103 [SECURITY] New versions of netstd fixes buffer overflows
Reference: BID:324
Reference: URL:http://www.securityfocus.com/bid/324

Description:
Buffer overflow in the bootp server in the Debian Linux netstd package.

Votes:

   ACCEPT(2) Ozancin, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> Is CAN-1999-0389 a duplicate of CAN-1999-0798?  CAN-1999-0389
   has January 1999 dates associated with it, while CAN-1999-0798
   was reported in late December.
   
   Also, is this the same line of code as CVE-1999-0914?  Both are in
   the netstd package, it could look like a library problem.
   
   However, deep in the changelog in the
   netstd_3.07-7slink.3.diff on Debian, Herbert Xu includes
   the following entry:
   
   +netstd (3.07-7slink.1) frozen; urgency=high
   +
   +  * bootpd:     Applied patch from Redhat as well as a fix for the overflow in
   +                report() (fixes #30675).
   +  * netkit-ftp: Applied patch from RedHat that fixes some obscure overflow
   +                bugs.
   +
   + -- Herbert Xu <herbert@debian.org>  Sat, 19 Dec 1998 14:36:48 +1100
   
   This tells me that two separate bugs are involved.
   
   Note that Red Hat posted *some* fix for *some* bootp problem
   in June 1998.  See:
   http://www.redhat.com/support/errata/rh42-errata-general.html#bootp
 Frech> XF:debian-netstd-bo
 Christey> Further analysis indicates that this is a duplicate of CVE-1999-0799
 CHANGE> [Christey changed vote from REJECT to REVIEWING]
 Christey> The fix information for BID:324 suggests that there are two
   overflows, one of which is in handle_request (bootpd.c) and is
   likely related to a file name; but there is another issue in
   report (report.c) which also looks like a straightforward
   overflow, which would suggest that this is not a duplicate of
   CAN-1999-0798 or CVE-1999-0799.
   
   Note: see comments for CAN-1999-0798 which explain how that
   candidate is not related to CAN-1999-0799.


CAN-1999-0394

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990115 DPEC Online Courseware

Description:
DPEC Online Courseware allows an attacker to change another user's password without knowing the original password.

Votes:

   NOOP(1) Christey
   REJECT(1) Frech
Voter Comments:
 Frech> If I understand the issue, this HIGHCARD involves insecure web programming. 
   If I don't understand, mark this as my first NOOP.
 Christey> CONFIRM:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D19990803132618.16407.qmail%40securityfocus.com
   ADDREF BID:565
   URL:http://www.securityfocus.com/vdb/bottom.html?vid=565


CAN-1999-0397

Phase: Proposed (19990728)
Reference: L0PHT:Jan21,1999
Reference: BUGTRAQ:Jan21,1999

Description:
The demo version of the Quakenbush NT Password Appraiser sends passwords across the network in plaintext.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(1) Frech
   REJECT(1) Wall
Voter Comments:
 Wall> Reject based on beta copy.
 Frech> XF:quakenbush-pw-appraiser(1652)


CAN-1999-0398

Phase: Modified (20000106-01)
Reference: BUGTRAQ:19990123 SSH 1.x and 2.x Daemon
Reference: BUGTRAQ:19990124 SSH Daemon
Reference: XF:ssh-exp-account-access

Description:
In some instances of SSH 1.2.27 and 2.0.11 on Linux systems, SSH will allow users with expired accounts to login.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> Followups to the bugtraq message (1/24/99) indicate that 1.2.27 was not yet
   released. v1.2.26 should be substituted in the description for '27.
   XF:ssh-exp-account-access


CAN-1999-0399

Phase: Modified (20000105-01)
Reference: BUGTRAQ:19990124 Mirc 5.5 'DCC Server' hole
Reference: XF:mirc-dcc-metachar-filename

Description:
The DCC server command in the Mirc 5.5 client doesn't filter characters from file names properly, allowing remote attackers to place a malicious file in a different location, possibly allowing the attacker to execute commands.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:mirc-dcc-metachar-filename


CAN-1999-0400

Phase: Modified (20000105-01)
Reference: BUGTRAQ:19990127 2.2.0 SECURITY (fwd)
Reference: XF:linux-kernel-ldd-dos
Reference: BID:344
Reference: URL:http://www.securityfocus.com/bid/344

Description:
Denial of service in Linux 2.2.0 running the ldd command on a core file.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> BUGTRAQ:Jan27,1999
   (http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-01-22&
   msg=Pine.LNX.4.05.9901270538380.539-100000@vitelus.com)
   XF:linux-kernel-ldd-dos


CAN-1999-0401

Phase: Modified (20000105-01)
Reference: BUGTRAQ:19990202 [patch] /proc race fixes for 2.2.1 (fwd)
Reference: XF:linux-race-condition-proc

Description:
A race condition in Linux 2.2.1 allows local users to read arbitrary memory from /proc files.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:linux-race-condition-proc


CAN-1999-0406

Phase: Proposed (19990728)
Reference: BUGTRAQ:Feb19,1999
Reference: XF:digital-networker-bo

Description:
Digital Unix Networker program nsralist has a buffer overflow which allows local users to obtain root privilege.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> In description, change 'which' to 'that'.


CAN-1999-0411

Phase: Proposed (19990726)
Reference: BUGTRAQ:Feb19,1999
Reference: XF:sco-startup-scripts

Description:
Several startup scripts in SCO OpenServer Enterprise System v 5.0.4p, including S84rpcinit, S95nis, S85tcp, and S89nfs, are vulnerable to a symlink attack, allowing a local user to gain root access.

Votes:

   MODIFY(2) Baker, Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> Neither XFDB nor the BugTraq article (incidentally, shows up as 7 March, not
   19 February) does not mention gaining root access... it says a local user
   could
   "delete or overwrite arbitrary files on the system."
 Baker> By overwriting arbitrary files, one could then gain root access.  I agree with a minor description change to reflect this.
 Christey> Normalize Bugtraq reference to:
   BUGTRAQ:19990307 Little exploit for startup scripts (SCO 5.0.4p).
   http://marc.theaimsgroup.com/?l=bugtraq&m=92087765014242&w=2
   Also, SCO:SB-99.17
   ftp://ftp.sco.com/SSE/security_bulletins/SB-99.17c


CAN-1999-0418

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990308 SMTP server account probing
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92100018214316&w=2

Description:
Denial of service in SMTP applications such as Sendmail, when a remote attacker (e.g. spammer) uses many "RCPT TO" commands in the same connection.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
   REVIEWING(1) Christey
Voter Comments:
 Christey> DUPE CAN-1999-0144 and CAN-1999-0250?
 Frech> XF:smtp-rctpto-dos(7499)


CAN-1999-0419

Phase: Modified (20000105-01)
Reference: BUGTRAQ:19990319 Microsoft's SMTP service broken/stupid
Reference: XF:smtp-4xx-error-dos

Description:
When the Microsoft SMTP service attempts to send a message to a server and receives a 4xx error code, it quickly and repeatedly attempts to redeliver the message, causing a denial of service.

Votes:

   MODIFY(2) Frech, LeBlanc
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:smtp-4xx-error-dos
 LeBlanc> - if we can find a KB or something that shows that this wasn't just
   user error, I'd vote ACCEPT.
 Christey> David Lemson, Microsoft SMTP Service Program Manager,
   posted a followup that said "We have confirmed this as a
   problem..."
   http://marc.theaimsgroup.com/?l=bugtraq&m=92171608127206&w=2


CAN-1999-0426

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990319 The default permissions on /dev/kmem is insecure.

Description:
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.

Votes:

   MODIFY(1) Frech
   REJECT(1) Christey
Voter Comments:
 Frech> XF:linux-dev-kmem-spoof
 Christey> DUPE CVE-1999-0414
   XF:linux-dev-kmem-spoof does not exist.
 Christey> *Now* XF:linux-dev-kmem-spoof(3500) exists...


CAN-1999-0427

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990320 Eudora Attachment Buffer Overflow
Reference: XF:eudora-long-attachments

Description:
Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> Change version number to 4.2beta. Second to last paragraph in bugtraq
   reference states: "Both the Win 95 and Win NT versions, along with the 4.2
   beta of Eudora are affected."
 Christey> This issue seems to have been rediscovered in
   BUGTRAQ:20000515 Eudora Pro & Outlook Overflow - too long filenames again
   http://marc.theaimsgroup.com/?l=bugtraq&m=95842482413076&w=2
   
   Also see
   BUGTRAQ:19990320 Eudora Attachment Buffer Overflow
   http://marc.theaimsgroup.com/?l=bugtraq&m=92195396912110&w=2
   
   Is this a duplicate/subsumed by CAN-1999-0004?


CAN-1999-0431

Phase: Modified (20000106-01)
Reference: BUGTRAQ:19990324 DoS for Linux 2.1.89 - 2.2.3: 0 length fragment bug
Reference: XF:linux-zerolength-fragment

Description:
Linux 2.2.3 and earlier allow a remote attacker to perform an IP fragmentation attack, causing a denial of service.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:linux-zerolength-fragment  
 Christey> Consider adding BID:2247


CAN-1999-0434

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990331 Bug in xfs
Reference: BID:359
Reference: URL:http://www.securityfocus.com/bid/359

Description:
XFree86 xfs command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.

Votes:

   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:xfree86-xfs-symlink-dos
 Christey> Is this the same problem as CVE-1999-0433?  CVE-1999-0433
   deals with a symlink attack on one file (/tmp/.X11-unix),
   while xfs (this candidate) deals with /tmp/.font-unix
   XF:xfree86-xfs-symlink-dos doesn't exist.
 Christey> ADDREF DEBIAN:19990331 symbolic link can be used to make any file world readable
   Note: Debian's advisory says that this is not a problem for Debian.


CAN-1999-0435

Phase: Proposed (19990623)
Reference: HP:HPSBUX9903-096

Description:
MC/ServiceGuard and MC/LockManager in HP-UX allows local users to gain privileges through SAM.

Votes:

   ACCEPT(1) Ozancin
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:hp-servicegaurd
 Christey> ADDREF CIAC:J-039


CAN-1999-0443

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990409 Patrol security bugs
Reference: URL:http://www.securityfocus.com/archive/1/13204
Reference: XF:bmc-patrol-replay

Description:
Patrol management software allows a remote attacker to conduct a replay attack to steal the administrator password.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> Change "Patrol management software" to "The PATROL management product from
   BMC Software".


CAN-1999-0444

Phase: Modified (20000106-01)
Reference: BUGTRAQ:19990412 ARP problem in Windows9X/NT
Reference: XF:windows-arp-dos

Description:
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> ADDREF: XF:windows-arp-dos  


CAN-1999-0450

Phase: Proposed (19990726)
Reference: BUGTRAQ:19990122 Perl.exe and IIS security advisory
Reference: BID:194
Reference: URL:http://www.securityfocus.com/bid/194

Description:
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe) .

Votes:

   ACCEPT(2) Ozancin, Wall
   NOOP(1) Christey
   REJECT(2) Frech, LeBlanc
Voter Comments:
 Frech> Can't find in database.
 Christey> This looks like another discovery of CAN-2000-0071 
 LeBlanc> - I just tried to repro this based on the BUGTRAQ vuln information,
   and it does not repro - 
   GET /bogus.pl HTTP/1.0
   HTTP/1.1 404 Object Not Found
   Server: Microsoft-IIS/5.0
   Date: Thu, 05 Oct 2000 21:04:20 GMT
   Content-Length: 3243
   Content-Type: text/html
   No path is returned whatsoever. This may have been a problem on some version
   of IIS in the past, but the BUGTRAQ ID says all versions are vulnerable.
   Let's try and figure out what version had the problem, whether it is
   intrinsic to IIS or the result of adding a 3rd party implementation of perl,
   and when it got fixed, then we can try again.
 CHANGE> [Frech changed vote from REVIEWING to REJECT]
 Christey> Add "no-such-file.pl" as an example to the desc, to facilitate
   search (it's used by CGI scanners and in the original example)


CAN-1999-0451

Phase: Proposed (19990726)
Reference: BUGTRAQ:Jan19,1999
Reference: BID:343
Reference: URL:http://www.securityfocus.com/bid/343

Description:
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.

Votes:

   ACCEPT(2) Baker, Ozancin
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:linux-ports-dos(8364)


CAN-1999-0452

Phase: Proposed (19990726)

Description:
A service or application has a backdoor password that was placed there by the developer.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Frech
Voter Comments:
 Frech> Much too broad. Also may be HIGHCARD (or will be in the future).
 Baker> I think we want to address this using the dot notation idea.  We do need to address this, just not a separate entry for every single occurance.


CAN-1999-0453

Phase: Modified (20010425-01)
Reference: BUGTRAQ:19990118 Remote Cisco Identification

Description:
An attacker can identify a CISCO device by sending a SYN packet to port 1999, which is for the Cisco Dicsovery Protocol (CDP).

Votes:

   ACCEPT(2) Baker, Balinsky
   MODIFY(1) Frech
   NOOP(2) Northcutt, Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:cisco-ident(2289)
   ADDREF BUGTRAQ:19990118 Remote Cisco Identification
   In description, probably better to use "Cisco" as product/company name.
 Balinsky> CiscoSecure IDS has a signature for this...ID 3602 Cisco IOS Identity.
 Christey> There may be a slight abstraction problem here, e.g. look
   at the candidate for queso/nmap; also see followup Bugtraq post
   from "Basement Research" on 19990120 which says that there are
   many other features in Cisco products that allow remote
   identification.


CAN-1999-0454

Phase: Proposed (19990728)

Description:
A remote attacker can sometimes identify the operating system of a host based on how it reacts to some IP or ICMP packets, using a tool such as nmap or queso.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Christey
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> Nmap and queso are the tip of the iceberg and not the most advanced
   ways to accomplish this.  To pursue making the world signature free
   is as much a vulnerability as having signatures, nay more.
 Frech> XF:decod-nmap(2053)
   XF:decod-queso(2048)
 Christey> Add "fingerprinting" to facilitate search.
   Some references:
   MISC:http://www.insecure.org/nmap/nmap-fingerprinting-article.html
   BUGTRAQ:19981228 A few more fingerprinting techniques - time and netmask
   http://marc.theaimsgroup.com/?l=bugtraq&m=91489155019895&w=2
   BUGTRAQ:19990222 Preventing remote OS detection
   http://marc.theaimsgroup.com/?l=bugtraq&m=91971553006937&w=2
   BUGTRAQ:20000901 ICMP Usage In Scanning v2.0 - Research Paper
   http://marc.theaimsgroup.com/?l=bugtraq&m=96791499611849&w=2
   BUGTRAQ:20000912 Using the Unused (Identifying OpenBSD,
   http://marc.theaimsgroup.com/?l=bugtraq&m=96879267724690&w=2
   BUGTRAQ:20000912 The DF Bit Playground (Identifying Sun Solaris & OpenBSD OSs)
   http://marc.theaimsgroup.com/?l=bugtraq&m=96879481129637&w=2
   BUGTRAQ:20000816 TOSing OSs out of the window / Fingerprinting Windows 2000 with
   http://marc.theaimsgroup.com/?l=bugtraq&m=96644121403569&w=2
   BUGTRAQ:20000609 p0f - passive os fingerprinting tool
   http://marc.theaimsgroup.com/?l=bugtraq&m=96062535628242&w=2


CAN-1999-0455

Phase: Modified (19991210-01)
Reference: ALLAIRE:ASB-001
Reference: XF:coldfusion-expression-evaluator
Reference: BID:115
Reference: URL:http://www.securityfocus.com/bid/115

Description:
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server via exprcalc.cfm, which does not restrict access to the server properly.

Votes:

   ACCEPT(3) Frech, Ozancin, Balinsky
   MODIFY(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Wall> The reference should be ASB99-01 (Expression Evaluator Security Issues)
   make application plural since there are three sample applications
   (openfile.cfm, displayopenedfile.cfm, and exprcalc.cfm).
 Christey> The CD:SF-EXEC and CD:SF-LOC content decisions apply here.
   Since there are 3 separate "executables" with the same
   (or similar) problem, we need to make sure that CD:SF-EXEC
   determines what to do here.  There is evidence that some
   of these .cfm scripts have an "include" file, and if so, 
   then CD:SF-LOC says that we shouldn't make separate entries
   for each of these scripts.  On the other hand, the initial
   L0pht discovery didn't include all 3 of these scripts, and
   as far as I can tell, Allaire had patched the first problem
   before the others were discovered.  So, CD:DISCOVERY-DATE
   may argue that we should split these because the problems
   were discovered and patched at different times.
   
   In any case, this candidate can not be accepted until the
   Editorial Board has accepted the CD:SF-EXEC, CD:SF-LOC,
   and CD:DISCOVERY-DATE content decisions.


CAN-1999-0459

Phase: Proposed (19990728)
Reference: XF:linux-milo-halt

Description:
Local users can perform a denial of service in Alpha Linux, using MILO to force a reboot.

Votes:

   ACCEPT(1) Frech
   NOOP(1) Northcutt
   REJECT(1) Wall
Voter Comments:
 Wall> Reject based on beta copy.


CAN-1999-0460

Phase: Proposed (19990726)
Reference: BUGTRAQ:19990218 Linux autofs overflow in 2.0.36+
Reference: BID:312
Reference: URL:http://www.securityfocus.com/bid/312

Description:
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.

Votes:

   ACCEPT(2) Baker, Ozancin
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:linux-autofs-bo(8365)


CAN-1999-0461

Phase: Proposed (19990728)

Description:
Versions of rpcbind including Linux, IRIX, and Wietse Venema's rpcbind allow a remote attacker to insert and delete entries by spoofing a source address.

Votes:

   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> ADDREF XF:pmap-sset
 Christey> CAN-1999-0195 = CAN-1999-0461 ?
   If this is approved over CAN-1999-0195, make sure it gets
   XF:pmap-sset


CAN-1999-0462

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990114 Secuity hole with perl (suidperl) and nosuid mounts on Linux
Reference: BID:339
Reference: URL:http://www.securityfocus.com/bid/339

Description:
suidperl in Linux Perl does not check the nosuid mount option on file systems, allowing local users to gain root access by placing a setuid script in a mountable file system, e.g. a CD-ROM or floppy disk.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:perl-suidperl-bo
 Christey> XF:perl-suidperl-bo doesn't exist.


CAN-1999-0465

Phase: Proposed (19990728)
Reference: XF:http-img-overflow

Description:
Remote attackers can crash Lynx and Internet Explorer using an IMG tag with a large width parameter.

Votes:

   ACCEPT(2) Northcutt, Frech
   REJECT(2) LeBlanc, Wall
Voter Comments:
 Wall> Reject based on client-side DoS
 LeBlanc> Client side DOS


CAN-1999-0467

Phase: Modified (20000106-01)
Reference: NTBUGTRAQ:19990409 Webcom's CGI Guestbook for Win32 web servers
Reference: XF:http-cgi-webcom-guestbook

Description:
The Webcom CGI Guestbook programs wguest.exe and rguest.exe allow a remote attacker to read arbitrary files using the "template" parameter.

Votes:

   ACCEPT(4) Blake, Frech, Ozancin, Landfield
   NOOP(2) Northcutt, Christey
Voter Comments:
 Christey> CAN-1999-0287 is probably a duplicate of CAN-1999-0467.  In
   NTBUGTRAQ:19990409 Webcom's CGI Guestbook for Win32 web servers
   Mnemonix says that he had previously reported on a similar
   problem.  Let's refer to the NTBugtraq posting as
   CAN-1999-0467.  We will refer to the "previous report" as
   CAN-1999-0287, which can be found at:
   http://oliver.efri.hr/~crv/security/bugs/NT/httpd41.html
   
   0287 describes an exploit via the "template" hidden variable.
   The exploit describes manually editing the HTML form to
   change the filename to read from the template variable.
   
   The exploit as described in 0467 encodes the template variable
   directly into the URL.  However, hidden variables are also
   encoded into the URL, which would have looked the same to
   the web server regardless of the exploit.  Therefore 0287
   and 0467 are the same.
 Christey> 
   The CD:SF-EXEC content decision also applies here.  We have 2
   programs, wguest.exe and rguest.exe, which appear to have the
   same problem.  CD:SF-EXEC needs to be accepted by the Editorial
   Board before this candidate can be converted into a CVE
   entry.  When finalized, CD:SF-EXEC will decide whether
   this candidate should be split or not.
 Christey> BID:2024


CAN-1999-0469

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990409 IE 5.0 security vulnerabilities - %01 bug again
Reference: XF:ie-window-spoof

Description:
Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the client.

Votes:

   ACCEPT(1) Wall
   NOOP(1) Northcutt
   REJECT(3) Frech, LeBlanc, Christey
Voter Comments:
 Wall> Reference: Microsoft Security Bulletin MS99-012
 Christey> DUPE CAN-1999-0488
 Frech> Defer to Christey's vote.
   However, XF:ie-mshtml-crossframe(2216) assigned to CAN-1999-0488.
 LeBlanc> Duplicate


CAN-1999-0476

Phase: Proposed (19990721)
Reference: BUGTRAQ:19990331 Potential vulnerability in SCO TermVision Windows 95 client
Reference: XF:sco-termvision-password

Description:
A weak encryption algorithm is used for passwords in SCO TermVision, allowing them to be easily decrypted by a local user.

Votes:

   ACCEPT(3) Baker, Frech, Ozancin
   NOOP(3) Northcutt, LeBlanc, Wall

CAN-1999-0477

Phase: Modified (19991210-01)
Reference: L0PHT:Cold Fusion App Server
Reference: XF:coldfusion-expression-evaluator
Reference: BID:115
Reference: URL:http://www.securityfocus.com/bid/115

Description:
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via openfile.cfm, which does not restrict access to the server properly.

Votes:

   ACCEPT(3) Frech, Ozancin, Christey
   REJECT(1) Wall
Voter Comments:
 Wall> Duplicate of 0455
 Christey> CAN-1999-0477 and CAN-1999-0455 were discovered at different
   times.  Also, the attack was different.  So "Same Attack" and
   "Same Time of Discovery" dictate that these should remain
   separate.


CAN-1999-0480

Phase: Modified (20000106-01)
Reference: BUGTRAQ:19980315 Midnight Commander /tmp race

Description:
Local attackers can conduct a denial of service in Midnight Commander 4.x with a symlink attack.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:midnight-commander-symlink-dos
 Christey> XF:midnight-commander-symlink-dos(3505)


CAN-1999-0486

Phase: Modified (20000106-01)
Reference: BUGTRAQ:19990420 AOL Instant Messenger URL Crash

Description:
Denial of service in AOL Instant Messenger when a remote attacker sends a malicious hyperlink to the receiving client, potentially causing a system crash.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:aol-im.
 Christey> XF:aol-im appears to be related to the problem discussed in
   BUGTRAQ:19980224 AOL Instant Messanger Bug
   
   This one is related to BUGTRAQ:19990420 AOL Instant Messenger URL Crash


CAN-1999-0488

Phase: Modified (19991205-01)
Reference: MS:MS99-012
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-012.asp

Description:
Internet Explorer 4.0 and 5.0 allows a remote attacker to execute security scripts in a different security context using malicious URLs, a variant of the "cross frame" vulnerability.

Votes:

   ACCEPT(1) Landfield
   MODIFY(2) Frech, Wall
   NOOP(2) Ozancin, Christey
Voter Comments:
 Frech> XF:ie-mshtml-crossframe
 Wall> (source: MSKB:Q168485)
 Christey> CAN-1999-0469 appears to be a duplicate; prefer this one over
   that one, since this one has an MS advisory.  Confirm with
   Microsoft that these are really duplicates.
   
   Also review CVE-1999-0487, which appears to be a similar
   bug.


CAN-1999-0489

Phase: Modified (19991205-01)
Reference: MS:MS99-015
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-015.asp

Description:
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to paste a file name into the file upload intrinsic control, a variant of "untrusted scripted paste" as described in MS:MS98-013.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Wall
   NOOP(1) Ozancin
   RECAST(1) Prosser
   REJECT(1) Christey
   REVIEWING(1) Frech
Voter Comments:
 Frech> Wasn't Untrusted scripted paste MS98-015? I can find no mention of a
   clipboard in either.
   I cannot proceed on this one without further clarification.
 Wall> (source: MS:MS99-012)
 Prosser> agree with Andre here.  The Untrusted Scripted paste
   vulnerability was originally addressed in MS98-015 and it is in the file
   upload intrinsic control in which an attacker can paste the name of a file
   on the target's drive in the control and a form submission would then send
   that file from the attacked machine to the remote web site.  This one has
   nothing to do with the clipboard.  What the advisory mentioned here,
   MS99-012, does is replace the MSHTML parsing engine which is supposed to fix
   the original Untrusted Scripted Paste issue and a variant, as well as the
   two Cross-Frame variants and a privacy issue in IMG SRC.  
   The vulnerability that allowed reading of a user's clipboard is the Forms
   2.0 Active X control vulnerability discussed in MS99-01
 Christey> The advisory should have been listed as MS99-012.  
   CVE-1999-0468 describes the untrusted scripted paste problem
   in MS99-012.
 Frech> Pending response to guidance request. 12/6/01.


CAN-1999-0490

Phase: Modified (19991205-01)
Reference: MS:MS99-012
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-012.asp

Description:
MSHTML.DLL in Internet Explorer 5.0 allows a remote attacker to learn information about a local user's files via an IMG SRC tag.

Votes:

   ACCEPT(2) Wall, Landfield
   MODIFY(1) Frech
   NOOP(1) Ozancin
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:ie-scriplet-fileread
 Christey> Duplicate of CAN-1999-0347?


CAN-1999-0492

Phase: Proposed (19990726)
Reference: BUGTRAQ:Apr23,1999

Description:
The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.

Votes:

   ACCEPT(3) Northcutt, Armstrong, Collins
   MODIFY(4) Blake, Baker, Frech, Shostack
   NOOP(4) Wall, Landfield, Cole, Christey
   REVIEWING(1) Ozancin
Voter Comments:
 Shostack> isn't that what finger is supposed to do?
 Landfield> Maybe we need a new category of "unsafe system utilities and protocols"
 Blake> Ffingerd 1.19 allows remote attackers to differentiate valid and invalid
   usernames on the target system based on its responses to finger queries.
 Christey> CHANGEREF BUGTRAQ [canonicalize]
   BUGTRAQ:19990423 Ffingerd privacy issues
   http://marc.theaimsgroup.com/?l=bugtraq&m=92488772121313&w=2
   
   Here's the nature of the problem.
   (1) FFingerd allows users to decide not to be fingered,
   printing a message "That user does not want to be fingered"
   (2) If the fingered user does not exist, then FFingerd's
   intended default is to print that the user does not
   want to be fingered; however, the error message has a
   period at the end.
   Thus, ffingerd can allow someone to determine who valid users
   on the server are, *in spite of* the intended functionality of
   ffingerd itself.  Thus this exposure should be viewed in light
   of the intended functionality of the application, as opposed
   to the common usage of the finger protocol in general.
   
   Also, the vendor posted a followup and said that a patch was
   available.  See:
   http://marc.theaimsgroup.com/?l=bugtraq&m=92489375428016&w=2
 Baker> Vulnerability Reference (HTML)	Reference Type
   http://www.securityfocus.com/archive/1/13422	Misc Defensive Info
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:ffinger-user-info(5393)


CAN-1999-0495

Phase: Proposed (19990728)

Description:
A remote attacker can gain access to a file system using .. (dot dot) when accessing SMB shares.

Votes:

   ACCEPT(6) Blake, Northcutt, Baker, Ozancin, Cole, Collins
   MODIFY(1) Frech
   NOOP(4) Bishop, Wall, Landfield, Armstrong
   REVIEWING(2) Levy, Christey
Voter Comments:
 Frech> XF:nb-dotdotknown(837)
   References would be appreciated. We've got no reference for this issue;
   confidence rating is consequently low. 
 Levy> Some refernces:
   http://www.securityfocus.com/archive/1/3894
   http://www.securityfocus.com/archive/1/3533
   http://www.securityfocus.com/archive/1/3535


CAN-1999-0497

Phase: Proposed (19990728)

Description:
Anonymous FTP is enabled

Votes:

   ACCEPT(1) Shostack
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Frech> ftp-anon(52) at http://xforce.iss.net/static/52.php
   ftp-anon2(543) at http://xforce.iss.net/static/543.php
 Christey> Add period to the end of the description.


CAN-1999-0498

Phase: Modified (19990925-01)
Reference: CERT:CA-91.18.Active.Internet.tftp.Attacks

Description:
TFTP is not running in a restricted directory, allowing a remote attacker to access sensitive information such as password files.

Votes:

   ACCEPT(3) Blake, Northcutt, Hill
   MODIFY(1) Frech
   NOOP(1) Baker
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:linux-tftp
 Christey> XF:linux-tftp refers to CAN-1999-0183


CAN-1999-0499

Phase: Proposed (19990721)

Description:
NETBIOS share information may be published through SNMP registry keys in NT.

Votes:

   ACCEPT(5) Northcutt, Baker, Shostack, Ozancin, Wall
   MODIFY(1) Frech
   REJECT(1) LeBlanc
Voter Comments:
 Frech> Change wording to 'Windows NT.'
   XF:snmp-netbios
 LeBlanc> Share info can be obtained via SNMP queries, but I question
   whether this is a vulnerability. The system can be configured not to do
   this, and one may argue that SNMP itself is an insecure configuration.
   Furthermore, the share information isn't published via registry keys -
   the description could refer to more than one actual issue. SNMP is meant
   to allow people to obtain information about systems. I'm willing to
   discuss this with the rest of the board.


CAN-1999-0501

Phase: Proposed (19990714)

Description:
A Unix account has a guessable password.

Votes:

   ACCEPT(3) Northcutt, Baker, Shostack
   RECAST(2) Frech, Meunier
   REVIEWING(1) Christey
Voter Comments:
 Frech> Guessable falls into the class of CAN-1999-0502, since I can guess a
   default, null, etc. password.
   Suggest changing to something like "has an existing non-default password
   that can be guessed."
   I'm also including default passwords in this entry. 
   In that vein, we show the following references:
   XF:user-password
   XF:passwd-username
   XF:default-unix-sync
   XF:default-unix-4dgifts
   XF:default-unix-bin
   XF:default-unix-daemon
   XF:default-unix-lp
   XF:default-unix-me
   XF:default-unix-nuucp
   XF:default-unix-root
   XF:default-unix-toor
   XF:default-unix-tour
   XF:default-unix-tty
   XF:default-unix-uucp
 Christey> This candidate is affected by the CD:CF-PASS content decision,
   which determines the appropriate level of abstraction to
   use for password problems.  CD:CF-PASS needs to be accepted
   by the Editorial Board before this candidate can be
   converted into a CVE entry; the final version of CD:CF-PASS
   may require using a different LOA than this candidate is
   currently using.
 CHANGE> [Meunier changed vote from ACCEPT to RECAST]
 Meunier> This relates only to account password technology, so this candidate is
   independent of the operating system, application, web site or other
   application of this technology.  The appropriate (natural) level of
   abstraction is therefore without specifying that it is for UNIX.
   Change the description to "An account has a guessable password other
   than default, null, blank."  This should satisfy Andre's objection.
   
   This Candidate should be merged with any candidate relating to
   account password technology where "Unix" in the original description
   can be replaced by something else.


CAN-1999-0502

Phase: Proposed (19990714)

Description:
A Unix account has a default, null, blank, or missing password.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:passwd-blank
   XF:no-pass
   XF:dict
   XF:sgi-accounts
   XF:linux-caldera-lisa
 Christey> This candidate is affected by the CD:CF-PASS content decision,
   which determines the appropriate level of abstraction to
   use for password problems.  CD:CF-PASS needs to be accepted
   by the Editorial Board before this candidate can be
   converted into a CVE entry; the final version of CD:CF-PASS
   may require using a different LOA than this candidate is
   currently using.


CAN-1999-0503

Phase: Proposed (19990714)

Description:
A Windows NT local user or administrator account has a guessable password.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Note: I am assuming that this entry includes Windows 2000 accounts and
   machine/service accounts listed in User Manager.
   XF:nt-guess-admin
   XF:nt-guess-user
   XF:nt-guess-guest
   XF:nt-guessed-operpwd
   XF:nt-guessed-powerwd
   XF:nt-guessed-disabled
   XF:nt-guessed-backup
   XF:nt-guessed-acctoper-pwd
   XF:nt-adminuserpw
   XF:nt-guestuserpw
   XF:nt-accountuserpw
   XF:nt-operator-userpw
   XF:nt-service-user-pwd
   XF:nt-server-oper-user-pwd
   XF:nt-power-user-pwd
   XF:nt-backup-operator-userpwd
   XF:nt-disabled-account-userpwd
 Christey> This candidate is affected by the CD:CF-PASS content decision,
   which determines the appropriate level of abstraction to
   use for password problems.  CD:CF-PASS needs to be accepted
   by the Editorial Board before this candidate can be
   converted into a CVE entry; the final version of CD:CF-PASS
   may require using a different LOA than this candidate is
   currently using.


CAN-1999-0504

Phase: Proposed (19990714)

Description:
A Windows NT local user or administrator account has a default, null, blank, or missing password.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:nt-guestblankpw
   XF:nt-adminblankpw
   XF:nt-adminnopw
   XF:nt-usernopw
   XF:nt-guestnopw
   XF:nt-accountblankpw
   XF:nt-nopw
   XF:nt-operator-blankpwd
   XF:nt-server-oper-blank-pwd
   XF:nt-power-user-blankpwd
   XF:nt-backup-operator-blankpwd
   XF:nt-disabled-account-blankpwd
 Christey> This candidate is affected by the CD:CF-PASS content decision,
   which determines the appropriate level of abstraction to
   use for password problems.  CD:CF-PASS needs to be accepted
   by the Editorial Board before this candidate can be
   converted into a CVE entry; the final version of CD:CF-PASS
   may require using a different LOA than this candidate is
   currently using.


CAN-1999-0505

Phase: Proposed (19990714)

Description:
A Windows NT domain user or administrator account has a guessable password.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:nt-guessed-domain-userpwd
   XF:nt-guessed-domain-guestpwd
   XF:nt-guessed-domain-adminpwd
   XF:nt-domain-userpwd
   XF:nt-domain-admin-userpwd
   XF:nt-domain-guest-userpwd
   XF:win2k-certpub-usrpwd
   XF:win2k-dhcpadm-usrpwd
   XF:win2k-dnsadm-usrpwd
   XF:win2k-entadm-usrpwd
   XF:win2k-schema-usrpwd
   XF:win2k-guessed-certpub
   XF:win2k-guessed-dhcpadm
   XF:win2k-guessed-dnsadm
   XF:win2k-guessed-entadm
   XF:win2k-guessed-schema


CAN-1999-0506

Phase: Proposed (19990714)

Description:
A Windows NT domain user or administrator account has a default, null, blank, or missing password.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:nt-domain-admin-blankpwd
   XF:nt-domain-admin-nopwd
   XF:nt-domain-guest-blankpwd
   XF:nt-domain-guest-nopwd
   XF:nt-domain-user-blankpwd
   XF:nt-domain-user-nopwd
   XF:win2k-certpub-blnkpwd
   XF:win2k-dhcpadm-blnkpwd
   XF:win2k-dnsadm-blnkpwd
   XF:win2k-entadm-blnkpwd
   XF:win2k-schema-blnkpwd


CAN-1999-0507

Phase: Proposed (19990714)

Description:
An account on a router, firewall, or other network device has a guessable password.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:firewall-tisopen
   XF:firewall-raptoropen
   XF:firewall-msopen
   XF:firewall-checkpointopen
   XF:firewall-ciscoopen


CAN-1999-0508

Phase: Proposed (19990714)

Description:
An account on a router, firewall, or other network device has a default, null, blank, or missing password.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> Note: Because the distinction between network hardware and software is not
   distinct, 
   the term 'network device' was liberally interpreted. Feel free to reject any
   of the
   below terms.
   XF:default-netranger
   XF:cayman-gatorbox
   XF:breezecom-default-passwords
   XF:default-portmaster
   XF:wingate-unpassworded
   XF:netopia-unpassworded
   XF:default-bay-switches
   XF:motorola-cable-default-pass
   XF:default-flowpoint
   XF:qms-2060-no-root-password
   XF:avirt-ras-password
   XF:webtrends-rtp-serv-install-password
   XF:cisco-bruteforce
   XF:cisco-bruteadmin
   XF:sambar-server-defaults
   XF:management-pfcuser
   XF:http-cgi-wwwboard-default
 Christey> DELREF XF:avirt-ras-password - does not fit CAN-1999-0508.


CAN-1999-0509

Phase: Modified (20000114-01)
Reference: CERT:CA-96.11

Description:
Perl, sh, csh, or other shell interpreters are installed in the cgi-bin directory on a WWW site, which allows remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(2) Northcutt, Wall
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> What is the right level of abstraction to use here?  Should
   we combine all possible interpreters into a single entry,
   or have a different entry for each one?  I've often seen
   Perl separated from other interpreters - is it included
   by default in some Windows web server configurations?
 Christey> Add tcsh, zsh, bash, rksh, ksh, ash, to support search.
 Frech> XF:http-cgi-vuln(146)


CAN-1999-0510

Phase: Proposed (19990726)

Description:
A router or firewall allows source routed packets from arbitrary hosts.

Votes:

   ACCEPT(2) Northcutt, Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:source-routing


CAN-1999-0511

Phase: Proposed (19990726)

Description:
IP forwarding is enabled on a machine which is not a router or firewall.

Votes:

   ACCEPT(2) Northcutt, Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:ip-forwarding


CAN-1999-0512

Phase: Modified (20020427-01)

Description:
A mail server is explicitly configured to allow SMTP mail relay, which allows abuse by spammers.

Votes:

   ACCEPT(3) Northcutt, Baker, Shostack
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:smtp-sendmail-relay(210)
   XF:ntmail-relay(2257)
   XF:exchange-relay(3107) (also assigned to CVE-1999-0682)
   XF:smtp-relay-uucp(3470)
   XF:sco-sendmail-spam(4342)
   XF:sco-openserver-mmdf-spam(4343)
   XF:lotus-domino-smtp-mail-relay(6591)
   XF:win2k-smtp-mail-relay(6803)
   XF:cobalt-poprelayd-mail-relay(6806)
   
   Candidate implicitly may refer to relaying settings enabled by default, or
   the bypass/circumvention of relaying. Both interpretations were used in
   assigning this candidate.
 Christey> The intention of this candidate is to cover configurations in
   which the admin has explicitly enabled relaying.  Other cases
   in which the application *intends* to prvent relaying, but
   there is some specific input that bypasses/tricks it, count
   as vulnerabilities (or exposures?) and as such would be
   assigned different numbers.
   
   http://www.sendmail.org/~ca/email/spam.html seems like a good
   general resource, as does ftp://ftp.isi.edu/in-notes/rfc2505.txt
 Christey> I changed the description to make it more clear that the issue
   is that of explicit configuration, as opposed to being the
   result of a vulnerability.


CAN-1999-0515

Phase: Proposed (19990728)

Description:
An unrestricted remote trust relationship for Unix systems has been set up, e.g. by using a + sign in /etc/hosts.equiv.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(1) Frech
   REJECT(1) Shostack
Voter Comments:
 Shostack> Overly broad
 Frech> XF:rsh-equiv(111)


CAN-1999-0516

Phase: Proposed (19990714)

Description:
An SNMP community name is guessable.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:snmp-get-guess
   XF:snmp-set-guess
   XF:sol-hidden-commstr
   XF:hpov-hidden-snmp-comm
 Christey> This candidate is affected by the CD:CF-PASS content decision,
   which determines the appropriate level of abstraction to
   use for password problems.  CD:CF-PASS needs to be accepted
   by the Editorial Board before this candidate can be
   converted into a CVE entry; the final version of CD:CF-PASS
   may require using a different LOA than this candidate is
   currently using.


CAN-1999-0517

Phase: Proposed (19990714)

Description:
An SNMP community name is the default (e.g. public), null, or missing.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:nt-snmp
   XF:snmp-comm
   XF:snmp-set-any
   XF:snmp-get-public
   XF:snmp-set-public
   XF:snmp-get-any
 Christey> This candidate is affected by the CD:CF-PASS content decision,
   which determines the appropriate level of abstraction to
   use for password problems.  CD:CF-PASS needs to be accepted
   by the Editorial Board before this candidate can be
   converted into a CVE entry; the final version of CD:CF-PASS
   may require using a different LOA than this candidate is
   currently using.
 Christey> Consider adding BID:2112


CAN-1999-0518

Phase: Proposed (19990714)

Description:
A NETBIOS/SMB share password is guessable.

Votes:

   ACCEPT(5) Northcutt, Baker, Shostack, LeBlanc, Meunier
   MODIFY(1) Frech
Voter Comments:
 Frech> Change description term to NetBIOS.
   XF:nt-netbios-perm
   XF:sharepass
   XF:win95-smb-password
   XF:nt-netbios-dict


CAN-1999-0519

Phase: Proposed (19990714)

Description:
A NETBIOS/SMB share password is the default, null, or missing.

Votes:

   ACCEPT(5) Northcutt, Baker, Shostack, LeBlanc, Meunier
   MODIFY(1) Frech
Voter Comments:
 Frech> Change description term to NetBIOS.
   XF:decod-smb-password-empty
   XF:nt-netbios-everyoneaccess
   XF:nt-netbios-guestaccess
   XF:nt-netbios-allaccess
   XF:nt-netbios-open
   XF:nt-netbios-write
   XF:nt-netbios-shareguest
   XF:nt-writable-netbios
   XF:nt-netbios-everyoneaccess-printer
   XF:nt-netbios-share-print-guest


CAN-1999-0520

Phase: Proposed (19990803)

Description:
A system-critical NETBIOS/SMB share has inappropriate access control.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   RECAST(1) Northcutt
   REJECT(1) LeBlanc
   REVIEWING(1) Christey
Voter Comments:
 Northcutt> I think we need to enumerate the shares and or the access control
 Christey> One question is, what is "inappropriate"?  It's probably
   very dependent on the policy of the enterprise on which
   this is found.  And should writable shares be different
   from readable shares?  (Or file systems, mail spools, etc.)
   Yes, the impact may be different, but we could have a
   large number of entries for each possible type of access.
   A content decision (CD:CF-DATA) needs to be reviewed
   and accepted by the Editorial Board in order to resolve
   this question.
 LeBlanc> Unacceptably vague - agree with Christey's comments.
 Frech> associated to:
   XF:nt-netbios-everyoneaccess(1)
   XF:nt-netbios-guestaccess(2)
   XF:nt-netbios-allaccess(3)
   XF:nt-netbios-open(15)
   XF:nt-netbios-write(19)
   XF:nt-netbios-shareguest(20)
   XF:nt-writable-netbios(26)
   XF:nb-rootshare(393)
   XF:decod-smb-password-empty(2358)


CAN-1999-0521

Phase: Proposed (19990714)

Description:
An NIS domain name is easily guessable.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:nis-dom
 Christey> Consider http://www.cert.org/advisories/CA-1992-13.html
   as well as ftp://ciac.llnl.gov/pub/ciac/bulletin/c-fy92/c-25.ciac-sunos-nis-patch


CAN-1999-0522

Phase: Proposed (19990803)
Reference: CERT:CA-96.10

Description:
The permissions for a system-critical NIS+ table (e.g. passwd) are inappropriate.

Votes:

   ACCEPT(1) Wall
   NOOP(1) Christey
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> Why not say world readable, this is what you do further down in the
   file (world exportable in CAN-1999-0554)
 Christey> ADDREF AUSCERT:AA-96.02


CAN-1999-0523

Phase: Proposed (19990726)

Description:
ICMP echo (ping) is allowed from arbitrary hosts.

Votes:

   MODIFY(1) Meunier
   REJECT(2) Northcutt, Frech
Voter Comments:
 Northcutt> (Though I sympathize with this one :)
 CHANGE> [Frech changed vote from REVIEWING to REJECT]
 Frech> Ping is a utility that can be run on demand; ICMP echo is a
   message 
   type. As currently worded, this candidate seems as if an arbitrary
   host 
   is vulnerable because it is capable of running an arbitrary program
   or
   function (in this case, ping/ICMP echo). There are many
   programs/functions that 
   'shouldn't' be on a computer, from a security admin's perspective.
   Even if this
   were a vulnerability, it would be impacted by CD-HIGHCARD.
 Meunier> Every ICMP message type presents a vulnerability or an
   exposure, if access is not controlled.  By that I mean not only those
   in RFC 792, but also those in RFC 1256, 950, and more.  I think that
   the description should be changed to "ICMP messages are acted upon
   without any access control".  ICMP is an error and debugging protocol.
   We complain about vendors leaving testing backdoors in their programs.
   ICMP is the equivalent for TCP/IP.  ICMP should be in the dog house,
   unless you are trying to troubleshoot something.  MTU discovery is
   just a performance tweak -- it's not necessary.  I don't know of any
   ICMP message type that is necessary if the network is functional.
   Limited logging of ICMP messages could be useful, but acting upon them
   and allowing the modification of routing tables, the behavior of the
   TCP/IP stack, etc... without any form of authentication is just crazy.


CAN-1999-0524

Phase: Proposed (19990726)

Description:
ICMP information such as netmask and timestamp is allowed from arbitrary hosts.

Votes:

   MODIFY(2) Frech, Meunier
   REJECT(1) Northcutt
Voter Comments:
 Frech> XF:icmp-timestamp
   XF:icmp-netmask
 Meunier> If this is not merged with 1999-0523 as I commented for that
   CVE, then the description should be changed to "ICMP messages of types
   13 and 14 (timestamp request and reply) and 17 and 18 (netmask request
   and reply) are acted upon without any access control".  It's a more
   precise and correct language.  I believe that this is a valid CVE
   entry (it's a common source of vulnerabilities or exposures) even
   though I see that the inferred action was "reject".  Knowing the time
   of a host also allows attacks against random number generators that
   are seeded with the current time.  I want to push to have it accepted.


CAN-1999-0525

Phase: Proposed (19990726)

Description:
IP traceroute is allowed from arbitrary hosts.

Votes:

   MODIFY(1) Frech
   REJECT(1) Northcutt
Voter Comments:
 Frech> XF:traceroute


CAN-1999-0527

Phase: Proposed (19990803)

Description:
The permissions for system-critical data in an anonymous FTP account are inappropriate. For example, the root directory is writeable by world, a real password file is obtainable, or executable commands such as "ls" can be overwritten.

Votes:

   ACCEPT(3) Northcutt, Baker, Wall
   MODIFY(1) Frech
Voter Comments:
 Northcutt> That that starts to get specific :)
 Frech> ftp-writable-directory(6253)
   ftp-write(53)
   "writeable" in the description should be "writable." 


CAN-1999-0528

Phase: Proposed (19990726)

Description:
A router or firewall forwards external packets that claim to come from inside the network that the router/firewall is in front of.

Votes:

   ACCEPT(3) Northcutt, Baker, Meunier
   MODIFY(1) Frech
Voter Comments:
 Frech> possibly XF:nisd-dns-fwd-check
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:firewall-external-packet-forwarding(8372)


CAN-1999-0529

Phase: Proposed (19990726)

Description:
A router or firewall forwards packets that claim to come from IANA reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x, etc.

Votes:

   ACCEPT(1) Frech
   MODIFY(1) Meunier
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> I have seen ISPs "assign" private addresses within their domain
 Meunier> A border router or firewall forwards packets that claim to come from IANA
   reserved or private addresses, e.g. 10.x.x.x, 127.x.x.x, 217.x.x.x,
   etc, outside of their area of validity.
 CHANGE> [Frech changed vote from REVIEWING to ACCEPT]


CAN-1999-0530

Phase: Proposed (19990728)

Description:
A system is operating in "promiscuous" mode which allows it to perform packet sniffing.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(1) Frech
   REJECT(1) Shostack
Voter Comments:
 Frech> XF:etherstatd(264)
   XF:sniffer-attack(778) 
   XF:decod-packet-capture-remote(1072)
   XF:netmon-running(1448)
   XF:netxray3-probe(1450)
   XF:sol-snoop-getquota-bo(3670) (also assigned to CVE-1999-0974)


CAN-1999-0531

Phase: Proposed (19990728)

Description:
An SMTP service supports EXPN, VRFY, HELP, ESMTP, and/or EHLO.

Votes:

   MODIFY(1) Frech
   NOOP(1) Christey
   RECAST(1) Shostack
   REJECT(1) Northcutt
Voter Comments:
 Shostack> I think expn != vrfy, help, esmtp.
 Frech> XF:lotus-domino-esmtp-bo(4499) (also assigned to CVE-2000-0452 and
   CAN-2000-1046)
   XF:smtp-expn(128)
   XF:smtp-vrfy(130)
   XF:smtp-helo-bo(886)
   XF:smtp-vrfy-bo(887)
   XF:smtp-expn-bo(888)
   XF:slmail-vrfyexpn-overflow(1721)
   XF:smtp-ehlo(323)
   
   Perhaps add RCPT? If so, add XF:smtp-rcpt(1928)
 Christey> XF:smtp-vrfy(130) ?


CAN-1999-0532

Phase: Proposed (19990726)

Description:
A DNS server allows zone transfers.

Votes:

   MODIFY(1) Frech
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> (With split DNS implementations this is quite appropriate)
 Frech> XF:dns-zonexfer


CAN-1999-0533

Phase: Proposed (19990726)

Description:
A DNS server allows inverse queries.

Votes:

   MODIFY(1) Frech
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> (rule of thumb)
 Frech> XF:dns-iquery


CAN-1999-0534

Phase: Proposed (19990721)

Description:
A Windows NT user has inappropriate rights or privileges, e.g. Act as System, Add Workstation, Backup, Change System Time, Create Pagefile, Create Permanent Object, Create Token Name, Debug, Generate Security Audit, Increase Priority, Increase Quota, Load Driver, Lock Memory, Profile Single Process, Remote Shutdown, Replace Process Token, Restore, System Environment, Take Ownership, or Unsolicited Input.

Votes:

   ACCEPT(5) Christey, Baker, Shostack, Ozancin, Wall
   MODIFY(2) Northcutt, Frech
Voter Comments:
 Northcutt> If we are going to write a laundry list put access to the scheduler in it.
 Christey> The list of privileges is very useful for lookup.
 Frech> XF:nt-create-token
   XF:nt-replace-token
   XF:nt-lock-memory
   XF:nt-increase-quota
   XF:nt-unsol-input
   XF:nt-act-system
   XF:nt-create-object
   XF:nt-sec-audit
   XF:nt-add-workstation
   XF:nt-manage-log
   XF:nt-take-owner
   XF:nt-load-driver
   XF:nt-profile-system
   XF:nt-system-time
   XF:nt-single-process
   XF:nt-increase-priority
   XF:nt-create-pagefile
   XF:nt-backup
   XF:nt-restore
   XF:nt-debug
   XF:nt-system-env
   XF:nt-remote-shutdown


CAN-1999-0535

Phase: Proposed (19990721)

Description:
A Windows NT account policy for passwords has inappropriate, security-critical settings, e.g. for password length, password age, or uniqueness.

Votes:

   ACCEPT(2) Shostack, Wall
   MODIFY(2) Baker, Frech
   RECAST(2) Northcutt, Ozancin
Voter Comments:
 Northcutt> inappropriate implies there is appropriate.  As a guy who has been
   monitoring
   networks for years I have deep reservations about justiying the existance
   of any fixed cleartext password. For appropriate to exist, some "we" would 
   have to establish some criteria for appropriate passwords.
 Baker> Perhaps this could be re-worded a bit.  The CVE CAN-1999-00582
   specifies "...settings for lockouts".  To remain consistent with the
   other, maybe it should specify "...settings for passwords" I think
   most people would agree that passwords should be at least 8
   characters; contain letters (upper and lowercase), numbers and at
   least one non-alphanumeric; should only be good a limited time 30-90
   days; and should not contain character combinations from user's prior
   2 or 3 passwords.
   Suggested rewrite - 
   A Windows NT account policy does not enforce reasonable minimum
   security-critical settings for passwords, e.g. passwords of sufficient
   length, periodic required password changes, or new password uniqueness
 Ozancin> What is appropriate?
 Frech> XF:nt-autologonpwd
   XF:nt-pwlen
   XF:nt-maxage
   XF:nt-minage
   XF:nt-pw-history
   XF:nt-user-pwnoexpire
   XF:nt-unknown-pwdfilter
   XF:nt-pwd-never-expire
   XF:nt-pwd-nochange
   XF:nt-pwdcache-enable
   XF:nt-guest-change-passwords


CAN-1999-0537

Phase: Proposed (19990726)

Description:
A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Frech
   REJECT(1) LeBlanc
Voter Comments:
 Frech> Good candidate for dot notation.
   XF:nav-java-enabled
   XF:nav-javascript-enabled
   XF:ie-active-content
   XF:ie-active-download
   XF:ie-active-scripting
   XF:ie-activex-execution
   XF:ie-java-enabled
   XF:netscape-javascript
   XF:netscape-java
   XF:zone-active-scripting
   XF:zone-activex-execution
   XF:zone-desktop-install
   XF:zone-low-channel
   XF:zone-file-download
   XF:zone-file-launch
   XF:zone-java-scripting
   XF:zone-low-java
   XF:zone-safe-scripting
   XF:zone-unsafe-scripting
 LeBlanc> Not a vulnerability. These are just checks for configuration
   settings that a user might have changed. I understand need to increase
   number of checks in a scanning product, but don't feel like these belong
   in CVE. Scanner vendors could argue that these entries are needed to
   keep a common language.


CAN-1999-0539

Phase: Proposed (19990728)

Description:
A trust relationship exists between two Unix hosts.

Votes:

   MODIFY(1) Frech
   REJECT(2) Northcutt, Shostack
Voter Comments:
 Northcutt> Too non specific
 Frech> XF:trusted-host(341)
   XF:trust-remote-same(717)
   XF:trust-remote-root(718)
   XF:trust-remote-nonroot(719)
   XF:trust-remote-any(720)
   XF:trust-other-host(723)
   XF:trust-all-nonroot(726)
   XF:trust-any-remote(727)
   XF:trust-local-acct(728)
   XF:trust-local-any(729)
   XF:trust-local-nonroot(730)
   XF:trust-all-hosts(731)
   XF:nt-trusted-domain(1284)
   XF:rsagent-trusted-domainadded(1588)
   XF:trust-remote-user(2955)
   XF:user-trust-hosts(3074)
   XF:user-trust-other-host(3077)
   XF:user-trust-remote-account(3079)


CAN-1999-0541

Phase: Proposed (19990714)

Description:
A password for accessing a WWW URL is guessable.

Votes:

   ACCEPT(4) Northcutt, Baker, Shostack, Meunier
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:http-password


CAN-1999-0546

Phase: Proposed (19990721)

Description:
The Windows NT guest account is enabled.

Votes:

   ACCEPT(5) Northcutt, Baker, Shostack, Ozancin, Wall
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:nt-guest-account


CAN-1999-0547

Phase: Proposed (19990728)

Description:
An SSH server allows authentication through the .rhosts file.

Votes:

   ACCEPT(2) Baker, Shostack
   MODIFY(1) Frech
   NOOP(1) Northcutt
Voter Comments:
 Frech> XF:sshd-rhosts(315)


CAN-1999-0548

Phase: Proposed (19990728)

Description:
A superfluous NFS server is running, but it is not importing or exporting any file systems.

Votes:

   ACCEPT(1) Shostack
   REJECT(1) Northcutt

CAN-1999-0549

Phase: Proposed (19990630)

Description:
Windows NT automatically logs in an administrator upon rebooting.

Votes:

   ACCEPT(1) Hill
   MODIFY(3) Blake, Frech, Ozancin
   NOOP(1) Wall
   REJECT(1) Baker
Voter Comments:
 Wall> Don't know what this is.  Don't think it is a vulnerability and would
   initially reject.  This is different than just renaming the
   administrator account.
 Frech> Would appreciate more information on this one, as in a reference.
 Blake> Reference: XF:nt-autologin
 Ozancin> Needs more detail
 Baker> I tried to find the XF:nt-autologin reference, and got no matching records from their search engine.
   No refs, no details, should reject
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:nt-autologon(5)


CAN-1999-0550

Phase: Proposed (19990726)

Description:
A router's routing tables can be obtained from arbitrary hosts.

Votes:

   MODIFY(1) Frech
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> Don't you mean obtained by arbitrary hosts
 Frech> XF:routed
   XF:decod-rip-entry
   XF:rip


CAN-1999-0554

Phase: Proposed (19990803)

Description:
NFS exports system-critical data to the world, e.g. / or a password file.

Votes:

   ACCEPT(2) Northcutt, Wall
   REVIEWING(1) Christey
Voter Comments:
 Christey> A content decision (CD:CF-DATA) needs to be reviewed
   and accepted by the Editorial Board in order to resolve
   this question.


CAN-1999-0555

Phase: Proposed (19990728)

Description:
A Unix account with a name other than "root" has UID 0, i.e. root privileges.

Votes:

   REJECT(2) Northcutt, Shostack
Voter Comments:
 Northcutt> This is very bogus


CAN-1999-0556

Phase: Proposed (19990728)

Description:
Two or more Unix accounts have the same UID.

Votes:

   NOOP(1) Christey
   REJECT(2) Northcutt, Shostack
Voter Comments:
 Christey> XF:duplicate-uid(876)
 Christey> Add terms "duplicate" and "user ID" to facilitate search.
   ftp://ftp.auscert.org.au/pub/auscert/papers/unix_security_checklist


CAN-1999-0559

Phase: Proposed (19990803)

Description:
A system-critical Unix file or directory has inappropriate permissions.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> Writable other than by root/bin/wheelgroup?


CAN-1999-0560

Phase: Proposed (19990803)

Description:
A system-critical Windows NT file or directory has inappropriate permissions.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> I think we should specify these


CAN-1999-0561

Phase: Proposed (19990728)

Description:
IIS has the #exec function enabled for Server Side Include (SSI) files.

Votes:

   NOOP(1) Northcutt
   RECAST(1) Shostack
   REJECT(1) LeBlanc
Voter Comments:
 LeBlanc> Does not meet definition of a vulnerability. This function is
   just enabled. You can turn it off if you want. if you trust the people
   putting up your web pages, this isn't a problem. If you don't, this is
   just one of many things you need to change.


CAN-1999-0562

Phase: Proposed (19990721)

Description:
The registry in Windows NT can be accessed remotely by users who are not administrators.

Votes:

   ACCEPT(4) Baker, Shostack, Ozancin, Wall
   MODIFY(1) Frech
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> This isn't all or nothing, users may be allowed to access part of the
   registry.
 Frech> XF:nt-winreg-all
   XF:nt-winreg-net


CAN-1999-0564

Phase: Proposed (19990728)

Description:
An attacker can force a printer to print arbitrary documents (e.g. if the printer doesn't require a password) or to become disabled.

Votes:

   ACCEPT(2) Baker, Shostack
   NOOP(1) Northcutt

CAN-1999-0565

Phase: Proposed (19990728)

Description:
A Sendmail alias allows input to be piped to a program.

Votes:

   ACCEPT(1) Northcutt
   RECAST(1) Shostack
Voter Comments:
 Shostack> Is this a default alias?  Is my .procmailrc an instance of this?


CAN-1999-0568

Phase: Proposed (19990728)

Description:
rpc.admind in Solaris is not running in a secure mode.

Votes:

   ACCEPT(1) Northcutt
   NOOP(1) Christey
   RECAST(2) Shostack, Dik
Voter Comments:
 Shostack> are there secure modes?
 Dik> Several:
   1) there is no "rpc.admind" daemon.
   there used to be a "admind" RPC daemon (100087/10)
   and there's now an "sadmind" daemon (100232/10)
   The switch over was somewhere around Solaris 2.4.
   2) Neither defaults to "secure mode"
   3) secure mode is "using secure RPC" which does
   proper over the wire authentication by specifying
   the "-S 2" option in inetd.conf
   (security level 2)
 Christey> XF:rpc-admind(626)
   http://xforce.iss.net/static/626.php
   MISC:http://pulhas.org/xploitsdb/mUNIXes/admind.html


CAN-1999-0569

Phase: Modified (19991130-01)

Description:
A URL for a WWW directory allows auto-indexing, which provides a list of all files in that directory if it does not contain an index.html file.

Votes:

   ACCEPT(1) Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> I do this intentionally somethings in high content directories
 Christey> XF:http-noindex(90) ?


CAN-1999-0570

Phase: Proposed (19990728)

Description:
Windows NT is not using a password filter utility, e.g. PASSFILT.DLL.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Wall
Voter Comments:
 Northcutt> Here we are crossing into the best practices arena again.  However since
   passfilt does establish a measurable standard and since we aren't the
   ones defining the stanard, simply saying it should be employed I will
   vote for this.  
 Frech> XF:nt-passfilt-not-inst(1308)
   XF:nt-passfilt-not-found(1309)
 Christey> Consider MSKB:Q161990 and MSKB:Q151082


CAN-1999-0571

Phase: Modified (20020312-01)
Reference: BUGTRAQ:Feb5,1999

Description:
A router's configuration service or management interface (such as a web server or telnet) is configured to allow connections from arbitrary hosts.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Christey, Northcutt
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:ascend-config-kill(889)
   XF:cisco-ios-crash(1238)
   XF:webramp-remote-access(1670)
   XF:ascom-timeplex-debug(1824)
   XF:netopia-unpassworded(1850)
   XF:cisco-web-crash(1886)
   XF:cisco-router-commands(1951)
   XF:motorola-cable-default-pass(2002)
   XF:default-flowpoint(2091)
   XF:netgear-router-idle-dos(4003)
   XF:cisco-cbos-telnet(4251)
   XF:routermate-snmp-community(4290)
   XF:cayman-router-dos(4479)
   XF:wavelink-authentication(5185)
   XF:ciscosecure-ldap-bypass-authentication(5274)
   XF:foundry-firmware-telnet-dos(5514)
   XF:netopia-view-system-log(5536)
   XF:cisco-webadmin-remote-dos(5595)
   XF:cisco-cbos-web-access(5626)
   XF:netopia-telnet-dos(6001)
   XF:cisco-sn-gain-access(6827)
   XF:cayman-dsl-insecure-permissions(6841)
   XF:linksys-etherfast-reveal-passwords(6949)
   XF:zyxel-router-default-password(6968)
   XF:cisco-cbos-web-config(7027)
   XF:prestige-wan-bypass-filter(7146)
 Christey> I changed the description to make it more explicit that this
   candidate is about router configuration, as opposed to
   vulnerabilities that accidentally make a configuration
   service accessible to anyone.


CAN-1999-0572

Phase: Proposed (19990721)

Description:
.reg files are associated with the Windows NT registry editor, making the registry susceptible to Trojan Horse attacks.

Votes:

   ACCEPT(4) Baker, Shostack, Ozancin, Wall
   MODIFY(1) Frech
   NOOP(2) Christey, Northcutt
Voter Comments:
 Northcutt> I don't quite get what this means, sorry
 Frech> XF:nt-regfile(178)
 Christey> MISC:http://security-archive.merton.ox.ac.uk/nt-security-199902/0087.html


CAN-1999-0575

Phase: Proposed (19990721)

Description:
A Windows NT system's user audit policy does not log an event success or failure, e.g. for Logon and Logoff, File and Object Access, Use of User Rights, User and Group Management, Security Policy Changes, Restart, Shutdown, and System, and Process Tracking.

Votes:

   ACCEPT(4) Christey, Shostack, Ozancin, Wall
   MODIFY(1) Frech
   RECAST(2) Northcutt, Baker
Voter Comments:
 Northcutt> It isn't a great truth that you should enable all or the above, if you
   do you potentially introduce a vulnerbility of filling up the file
   system with stuff you will never look at.
 Ozancin> It is far less interesting what a user does successfully that what they
   attempt and fail at.
 Christey> The list of event types is very useful for lookup.
 Frech> XF:nt-system-audit
   XF:nt-logon-audit
   XF:nt-object-audit
   XF:nt-privil-audit
   XF:nt-process-audit
   XF:nt-policy-audit
   XF:nt-account-audit
 CHANGE> [Baker changed vote from REVIEWING to RECAST]


CAN-1999-0576

Phase: Proposed (19990721)

Description:
A Windows NT system's file audit policy does not log an event success or failure for security-critical files or directories.

Votes:

   ACCEPT(3) Baker, Shostack, Wall
   MODIFY(2) Frech, Ozancin
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> 1.) Too general are we ready to state what the security-critical files
   and directories are
   2.) Does Ataris, Windows CE, PalmOS, Linux have such a capability
 Ozancin> Some files and directories are clearly understood to be critical. Others are
   unclear. We need to clarify that critical is.
 Frech> XF:nt-object-audit


CAN-1999-0577

Phase: Proposed (19990721)

Description:
A Windows NT system's file audit policy does not log an event success or failure for non-critical files or directories.

Votes:

   ACCEPT(2) Shostack, Wall
   MODIFY(3) Baker, Frech, Ozancin
   REJECT(1) Northcutt
Voter Comments:
 Ozancin> It is far less interesting what a user does successfully that what they
   attempt and fail at.
   Perhaps only failure should be logged.
 Frech> XF:nt-object-audit
 CHANGE> [Baker changed vote from REVIEWING to MODIFY]
 Baker> Failure on non-critical files is what should be monitored.


CAN-1999-0578

Phase: Proposed (19990721)

Description:
A Windows NT system's registry audit policy does not log an event success or failure for security-critical registry keys.

Votes:

   ACCEPT(4) Baker, Shostack, Ozancin, Wall
   MODIFY(1) Frech
   REJECT(1) Northcutt
Voter Comments:
 Ozancin> with reservation
   Again what is defined as critical
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:nt-object-audit(228)


CAN-1999-0579

Phase: Proposed (19990721)

Description:
A Windows NT system's registry audit policy does not log an event success or failure for non-critical registry keys.

Votes:

   ACCEPT(3) Baker, Shostack, Wall
   MODIFY(2) Frech, Ozancin
   REJECT(1) Northcutt
Voter Comments:
 Ozancin> Again only failure may be of interest. It would be impractical to wad
   through the incredibly large amount of logging that this would generate. It
   could overwhelm log entries that you might find interesting.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:nt-object-audit(228)


CAN-1999-0580

Phase: Proposed (19990803)

Description:
The HKEY_LOCAL_MACHINE key in a Windows NT system has inappropriate, system-critical permissions.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> I think we can define appropriate, take a look at the nt security .pdf
   and see if you can't see a way to phrase specific keys in a way that
   defines inappropriate.


CAN-1999-0581

Phase: Proposed (19990803)

Description:
The HKEY_CLASSES_ROOT key in a Windows NT system has inappropriate, system-critical permissions.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> I think we can define appropriate, take a look at the nt security .pdf
   and see if you can't see a way to phrase specific keys in a way that
   defines inappropriate.


CAN-1999-0582

Phase: Proposed (19990721)

Description:
A Windows NT account policy has inappropriate, security-critical settings for lockout, e.g. lockout duration, lockout after bad logon attempts, etc.

Votes:

   ACCEPT(3) Shostack, Ozancin, Wall
   MODIFY(2) Baker, Frech
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> The definition is?
 Baker> Maybe a rewording of this one too.  I think most people would agree on
   some "minimum" policies like 3-5 bad attempts lockout for an hour or
   until the administrator unlocks the account.
   Suggested rewrite -
   A Windows NT account policy does not enforce reasonable minimum
   security-critical settings for lockouts, e.g. lockout duration,
   lockout after bad logon attempts, etc.
 Ozancin> with reservations
   What is appropriate?
 Frech> XF:nt-thres-lockout
   XF:nt-lock-duration
   XF:nt-lock-window
   XF:nt-perm-lockout
   XF:lockout-disabled


CAN-1999-0583

Phase: Proposed (19990728)

Description:
There is a one-way or two-way trust relationship between Windows NT domains.

Votes:

   NOOP(1) Christey
   REJECT(2) Northcutt, Shostack
Voter Comments:
 Christey> XF:nt-trusted-domain(1284)


CAN-1999-0584

Phase: Proposed (19990728)

Description:
A Windows NT file system is not NTFS.

Votes:

   ACCEPT(2) Northcutt, Wall
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Wall> NTFS partition provides the security.  This could be re-worded
   to "A Windows NT file system is FAT" since it is either NTFS or FAT
   and FAT is less secure.
 Frech> XF:nt-filesys(195)
 Christey> MSKB:Q214579
   MSKB:Q214579
   http://support.microsoft.com/support/kb/articles/Q100/1/08.ASP


CAN-1999-0585

Phase: Proposed (19990721)

Description:
A Windows NT administrator account has the default name of Administrator.

Votes:

   ACCEPT(1) Ozancin
   MODIFY(1) Frech
   REJECT(3) Northcutt, Baker, Shostack
   REVIEWING(1) Wall
Voter Comments:
 Wall> Some sources say this is not a vulnerability, but a warning.  It just
   slows down the search for the admin account (SID = 500) which can
   always be found.
 Northcutt> I change this on all NT systems I am responsible for, but is
   root a vulnerability?
 Baker> There are ways to identify the administrator account anyway, so this
   is only a minor delay to someone that is knowledgeable.  This, in and
   of itself, doesn't really strike me as a vulnerability, anymore than
   the root account on a Unix box.
 Shostack> (there is no way to hide the account name today)
 Frech> XF:nt-adminexists


CAN-1999-0586

Phase: Proposed (19990728)

Description:
A network service is running on a nonstandard port.

Votes:

   RECAST(1) Shostack
   REJECT(1) Northcutt
Voter Comments:
 Shostack> Might be acceptable if clearer; is that a standard service on a
   non-standard port, or any service on an unassigned port?


CAN-1999-0587

Phase: Proposed (19990803)

Description:
A WWW server is not running in a restricted file system, e.g. through a chroot, thus allowing access to system-critical data.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> While I would accept this for Unix, I am not sure this applies to NT,
   VMS, palm pilots, or commodore 64


CAN-1999-0588

Phase: Proposed (19990726)

Description:
A filter in a router or firewall allows unusual fragmented packets.

Votes:

   MODIFY(1) Frech
   REJECT(1) Northcutt
Voter Comments:
 Northcutt> I want to vote to accept this one, but unusual is a shade broad.
 Frech> XF:nt-rras
   XF:cisco-fragmented-attacks
   XF:ip-frag


CAN-1999-0589

Phase: Proposed (19990803)

Description:
A system-critical Windows NT registry key has inappropriate permissions.

Votes:

   ACCEPT(1) Wall
   RECAST(2) Christey, Northcutt
Voter Comments:
 Northcutt> I think we can define appropriate, take a look at the nt security .pdf
   and see if you can't see a way to phrase specific keys in a way that
   defines inappropriate.
 Christey> Upon further reflection, this is too high-level for CVE.
   Specific registry keys with bad permissions is roughly
   equivalent to Unix configuration files that have bad
   permissions; those permission problems can be created by
   any vendor, not just a specific one.  Therefore this
   candidate should be RECAST into each separate registry
   key that has this problem.


CAN-1999-0590

Phase: Proposed (19990728)

Description:
A system does not present an appropriate legal message or warning to a user who is accessing it.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(1) Christey
   RECAST(1) Shostack
Voter Comments:
 Christey> ADDREF CIAC:J-043
   URL:http://ciac.llnl.gov/ciac/bulletins/j-043.shtml
   Also add "banner" to the description to facilitate search.


CAN-1999-0591

Phase: Proposed (19990803)

Description:
An event log in Windows NT has inappropriate access permissions.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> splain Lucy, splain


CAN-1999-0592

Phase: Proposed (19990728)

Description:
The Logon box of a Windows NT system displays the name of the last user who logged in.

Votes:

   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(2) Northcutt, Wall
Voter Comments:
 Wall> Information gathering, not vulnerability
 Northcutt> Ah a C2 weenie must have snuck this in, this can be a good thing 
   not just vulnerability
 Frech> XF:nt-display-last-username(1353)
   Use it if you will. :-) If not, let us know so I can remove the CAN
   reference from our database.
 Christey> MSKB:Q114463
   http://support.microsoft.com/support/kb/articles/q114/4/63.asp


CAN-1999-0593

Phase: Proposed (19990728)

Description:
A user is allowed to shut down a Windows NT system without logging in.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   REJECT(1) Northcutt
Voter Comments:
 Wall> Still a denial of service.
 Northcutt> May well be appropriate
 Frech> XF:nt-shutdown-without-logon(1291)


CAN-1999-0594

Phase: Proposed (19990728)

Description:
A Windows NT system does not restrict access to removable media drives such as a floppy disk drive or CDROM drive.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Wall> Perhaps it can be re-worded to "removable media drives
   such as a floppy disk drive or CDROM drive can be accessed (shared) in a
   Windows NT system."
 Northcutt> - what good is my NT w/o its floppy
 Frech> XF:nt-allocate-cdroms(1294)
   XF:nt-allocate-floppy(1318)
 Christey> MSKB:Q172520
   URL:http://support.microsoft.com/support/kb/articles/q172/5/20.asp


CAN-1999-0595

Phase: Proposed (19990728)
Reference: MSKB:Q182086

Description:
A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(1) Northcutt
Voter Comments:
 Frech> XF:nt-clearpage(216)
   XF:reg-pagefile-clearing(2551)


CAN-1999-0596

Phase: Proposed (19990728)

Description:
A Windows NT log file has an inappropriate maximum size or retention period.

Votes:

   MODIFY(1) Frech
   REJECT(2) Northcutt, Wall
Voter Comments:
 Northcutt> define appropriate
 Frech> XF:reg-app-log-small(2521)
   XF:reg-sec-log-maxsize(2577)
   XF:reg-sys-log-small(2586)


CAN-1999-0597

Phase: Proposed (19990728)

Description:
A Windows NT account policy does not forcibly disconnect remote users from the server when their logon hours expire.

Votes:

   ACCEPT(1) Northcutt
   MODIFY(1) Frech
   REJECT(1) Wall
Voter Comments:
 Frech> XF:nt-forced-logoff(1343)


CAN-1999-0598

Phase: Proposed (19990726)

Description:
A network intrusion detection system (IDS) does not properly handle packets that are sent out of order, allowing an attacker to escape detection.

Votes:

   ACCEPT(3) Northcutt, Baker, Armstrong
   NOOP(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Waiting for CIEL.
 Christey> This is a design flaw, along with the other reported IDS
   problems; at least reference Ptacek/Newsham's paper.
 Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html


CAN-1999-0599

Phase: Proposed (19990726)

Description:
A network intrusion detection system (IDS) does not properly handle packets with improper sequence numbers.

Votes:

   ACCEPT(2) Northcutt, Baker
   NOOP(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Waiting for CIEL.
 Christey> This is a design flaw, along with the other reported IDS
   problems; at least reference Ptacek/Newsham's paper.
 Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html


CAN-1999-0600

Phase: Proposed (19990726)

Description:
A network intrusion detection system (IDS) does not verify the checksum on a packet.

Votes:

   ACCEPT(2) Northcutt, Baker
   NOOP(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Waiting for CIEL.
 Christey> This is a design flaw, along with the other reported IDS
   problems; at least reference Ptacek/Newsham's paper.
 Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html


CAN-1999-0601

Phase: Proposed (19990726)

Description:
A network intrusion detection system (IDS) does not properly handle data within TCP handshake packets.

Votes:

   ACCEPT(2) Northcutt, Baker
   NOOP(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Waiting for Godot, er, CIEL.
 Christey> This is a design flaw, along with the other reported IDS
   problems; at least reference Ptacek/Newsham's paper.
 Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html


CAN-1999-0602

Phase: Proposed (19990726)

Description:
A network intrusion detection system (IDS) does not properly reassemble fragmented packets.

Votes:

   ACCEPT(2) Northcutt, Baker
   NOOP(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Waiting for CIEL.
 Christey> This is a design flaw, along with the other reported IDS
   problems; at least reference Ptacek/Newsham's paper.
 Christey> URL:http://www.robertgraham.com/mirror/Ptacek-Newsham-Evasion-98.html


CAN-1999-0603

Phase: Proposed (19990728)

Description:
In Windows NT, an inappropriate user is a member of a group, e.g. Administrator, Backup Operators, Domain Admins, Domain Guests, Power Users, Print Operators, Replicators, System Operators, etc.

Votes:

   MODIFY(1) Frech
   REJECT(2) Northcutt, Wall
Voter Comments:
 Frech> XF:nt-system-operator
   XF:nt-admin-group
   XF:nt-replicator
   XF:nt-print-operator
   XF:nt-power-user
   XF:nt-guest-in-group
   XF:nt-backup-operator
   XF:nt-domain-admin
   XF:nt-domain-guest
   XF:win2k-acct-oper-grp
   XF:win2k-admin-grp
   XF:win2k-backup-oper-grp
   XF:win2k-certpublishers-grp
   XF:win2k-dhcp-admin-grp
   XF:win2k-dnsadm-grp
   XF:win2k-domainadm-grp
   XF:win2k-entadm-grp
   XF:win2k-printoper-grp
   XF:win2k-replicator-grp
   XF:win2k-schemaadm-grp
   XF:win2k-serveroper-grp
   You asked for it... :-) Use or reject at your discretion. If rejected,
   please let us know so we can remove CAN references from database.


CAN-1999-0604

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990420 Shopping Carts exposing CC data
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92462991805485&w=2

Description:
An incorrect configuration of the WebStore 1.0 shopping cart CGI program "web_store.cgi" could disclose private information.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Northcutt, Wall
Voter Comments:
 Frech> XF:webstore-misconfig(3861)


CAN-1999-0605

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990420 Shopping Carts exposing CC data
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92462991805485&w=2

Description:
An incorrect configuration of the Order Form 1.0 shopping cart CGI program could disclose private information.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Christey, Northcutt, Wall
Voter Comments:
 Frech> XF:orderform-misconfig(3860)
 Christey> BID:2021
 Christey> Mention affected files: order_log_v12.dat and order_log.dat
   fix version number (1.2)


CAN-1999-0606

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990420 Shopping Carts exposing CC data
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92462991805485&w=2

Description:
An incorrect configuration of the EZMall 2000 shopping cart CGI program "mall2000.cgi" could disclose private information.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Christey, Northcutt, Wall
Voter Comments:
 Frech> XF:ezmall2000-misconfig(3859)
 Christey> Add mall_log_files/order.log to desc


CAN-1999-0607

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990420 Shopping Carts exposing CC data
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92462991805485&w=2

Description:
An incorrect configuration of the QuikStore shopping cart CGI program "quikstore.cgi" could disclose private information.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Christey, Northcutt, Wall
Voter Comments:
 Frech> XF:quikstore-misconfig(3858)
 Christey> http://www.quikstore.com/help/pages/Security/security.htm says:
   
   "It is IMPORTANT that during the setup of the QuikStore program, you
   check to make sure that the cgi-bin or executable program directory
   of your web site not be viewable from the outside world. You don't
   want the users to have access to your programs or log files that could
   be stored there!
   
   ...
   
   If you can view or download these files from the browser, someone
   else can too"
   
   So is this a configuration problem?  See the configuration file at
   http://www.quikstore.com/help/pages/Configuration/configparametersfull.htm
   The [DIRECTORY_PATHS] section identifies pathnames and describes how
   pathnames are constructed.  It clearly uses relative pathnames,
   so all data is underneath the base directory!!
   
   If we call this a configuration problem, then maybe this (and
   all other "CGI-data-in-web-tree" configuration problems) should
   be combined.
 Christey> Consider adding BID:1983


CAN-1999-0609

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990420 Shopping Carts exposing CC data
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92462991805485&w=2

Description:
An incorrect configuration of the SoftCart CGI program "SoftCart.exe" could disclose private information.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Christey, Northcutt, Wall
Voter Comments:
 Frech> XF:softcart-misconfig(3856)
 Christey> Consider adding BID:2055


CAN-1999-0610

Phase: Proposed (19990728)
Reference: BUGTRAQ:19990420 Shopping Carts exposing CC data
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92462991805485&w=2

Description:
An incorrect configuration of the Webcart CGI program could disclose private information.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Northcutt, Wall
Voter Comments:
 Frech> Cite reference as:
   BUGTRAQ:19990424  Re: Shopping Carts exposing CC data 
   URL:
   http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%
   3D1%26date%3D2000-08-22%26msg%3D3720E2B6.6031A2E7@datashopper.dk
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:webcart-data-exposure(8374)


CAN-1999-0611

Phase: Proposed (19990803)

Description:
A system-critical Windows NT registry key has an inappropriate value.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> I think we can define appropriate, take a look at the nt security .pdf
   and see if you can't see a way to phrase specific keys in a way that
   defines inappropriate.


CAN-1999-0613

Phase: Proposed (19990721)

Description:
The rpc.sprayd service is running.

Votes:

   ACCEPT(2) Baker, Ozancin
   MODIFY(1) Frech
   NOOP(1) Wall
   REJECT(1) Northcutt
Voter Comments:
 Frech> XF:sprayd


CAN-1999-0614

Phase: Proposed (19990804)

Description:
The FTP service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0615

Phase: Proposed (19990804)

Description:
The SNMP service is running.

Votes:

   ACCEPT(3) Prosser, Baker, Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Baker> Although newer versions on snmp are not as vulnerable as prior versions,
   this can still be a significant risk of exploitation, as seen in recent
   attacks on snmp services via automated worms
 Christey> XF:snmp(132) ?
 Prosser> This fits the "exposure" description although we also know there are many vulnerabilities in SNMP.  This is more of a policy/best practice issue for administrators.  If you need SNMP lock it down as tight as you can, if you don't need it, don't run it.


CAN-1999-0616

Phase: Proposed (19990804)

Description:
The TFTP service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0617

Phase: Proposed (19990804)

Description:
The SMTP service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0618

Phase: Modified (19990921-01)
Reference: XF:rexec

Description:
The rexec service is running.

Votes:

   ACCEPT(4) Northcutt, Baker, Ozancin, Wall
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:decod-rexec
   XF:rexec


CAN-1999-0619

Phase: Proposed (19990804)

Description:
The Telnet service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0620

Phase: Proposed (19990804)

Description:
A component service related to NIS is running.

Votes:

   ACCEPT(2) Baker, Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Christey> XF:ypserv(261)


CAN-1999-0621

Phase: Proposed (19990804)

Description:
A component service related to NETBIOS is running.

Votes:

   ACCEPT(2) Baker, Wall
   MODIFY(1) Frech
   REJECT(2) Northcutt, LeBlanc
Voter Comments:
 LeBlanc> There is insufficient description to even know what this is.
   Lots of component services related to NetBIOS run, and usually do not
   constitute a problem.
 Frech> associated to:
   XF:nt-alerter(29)
   XF:nt-messenger(69)
   XF:reg-ras-gateway-enabled(2567)


CAN-1999-0622

Phase: Proposed (19990804)

Description:
A component service related to DNS service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0623

Phase: Proposed (19990804)

Description:
The X Windows service is running.

Votes:

   ACCEPT(2) Baker, Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Christey> Add "X11" to facilitate search.


CAN-1999-0624

Phase: Interim (19990925)
Reference: XF:rstat-out
Reference: XF:rstatd

Description:
The rstat/rstatd service is running.

Votes:

   ACCEPT(3) Northcutt, Baker, Ozancin
   MODIFY(1) Frech
   NOOP(2) Wall, Meunier
Voter Comments:
 Frech> XF:rstat-out
   XF:rstatd


CAN-1999-0625

Phase: Proposed (19990721)

Description:
The rpc.rquotad service is running.

Votes:

   ACCEPT(3) Northcutt, Baker, Ozancin
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:rquotad


CAN-1999-0629

Phase: Proposed (19990721)

Description:
The ident/identd service is running.

Votes:

   ACCEPT(2) Baker, Ozancin
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
   REJECT(1) Northcutt
Voter Comments:
 Frech> possibly XF:identd?
 Christey> XF:ident-users(318) ?
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:identd-vuln(61)
   XF:ident-users(318)


CAN-1999-0630

Phase: Proposed (19990804)

Description:
The NT Alerter and Messenger services are running.

Votes:

   ACCEPT(2) Baker, Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Christey> http://support.microsoft.com/support/kb/articles/q189/2/71.asp


CAN-1999-0631

Phase: Proposed (19990804)

Description:
The NFS service is running.

Votes:

   ACCEPT(2) Baker, Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Christey> XF:nfs-nfsd(76) ?
 Christey> Add rpc.mountd/mountd to facilitate search.


CAN-1999-0632

Phase: Proposed (19990804)

Description:
The RPC portmapper service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0633

Phase: Proposed (19990804)

Description:
The HTTP/WWW service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0634

Phase: Proposed (19990804)

Description:
The SSH service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0635

Phase: Proposed (19990804)

Description:
The echo service is running.

Votes:

   ACCEPT(3) Northcutt, Baker, Wall
   REVIEWING(1) Christey
Voter Comments:
 Northcutt> The method to my madness is echo is the common denom in the dos attack
 Christey> How much of this is an overlap with the echo/chargen flood
   problem (CVE-1999-0103)?  If this is only an exposure because
   of CVE-1999-0103, then maybe this should be REJECTed.


CAN-1999-0636

Phase: Proposed (19990804)

Description:
The discard service is running.

Votes:

   ACCEPT(1) Baker
   NOOP(1) Wall
   REJECT(1) Northcutt

CAN-1999-0637

Phase: Proposed (19990804)

Description:
The systat service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0638

Phase: Proposed (19990804)

Description:
The daytime service is running.

Votes:

   ACCEPT(1) Baker
   NOOP(1) Wall
   REJECT(1) Northcutt

CAN-1999-0639

Phase: Proposed (19990804)

Description:
The chargen service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt
   REVIEWING(1) Christey
Voter Comments:
 Christey> How much of this is an overlap with the echo/chargen flood
   problem (CVE-1999-0103)?  If this is only an exposure because
   of CVE-1999-0103, then maybe this should be REJECTed.


CAN-1999-0640

Phase: Proposed (19990804)

Description:
The Gopher service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0641

Phase: Proposed (19990804)

Description:
The UUCP service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0642

Phase: Proposed (19990804)

Description:
A POP service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0643

Phase: Proposed (19990804)

Description:
The IMAP service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0644

Phase: Proposed (19990804)

Description:
The NNTP news service is running.

Votes:

   ACCEPT(2) Baker, Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Christey> XF:nntp-post(88) ?


CAN-1999-0645

Phase: Proposed (19990804)

Description:
The IRC service is running.

Votes:

   ACCEPT(2) Baker, Wall
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Christey> XF:irc-server(767) ?


CAN-1999-0646

Phase: Proposed (19990804)

Description:
The LDAP service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0647

Phase: Proposed (19990721)

Description:
The bootparam (bootparamd) service is running.

Votes:

   ACCEPT(2) Baker, Ozancin
   MODIFY(1) Frech
   NOOP(1) Wall
   REJECT(1) Northcutt
Voter Comments:
 Frech> XF:bootp


CAN-1999-0648

Phase: Proposed (19990804)

Description:
The X25 service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0649

Phase: Proposed (19990804)

Description:
The FSP service is running.

Votes:

   ACCEPT(1) Baker
   NOOP(1) Wall
   REJECT(1) Northcutt

CAN-1999-0650

Phase: Proposed (19990804)

Description:
The netstat service is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0651

Phase: Proposed (19990804)

Description:
The rsh/rlogin service is running.

Votes:

   ACCEPT(2) Baker, Wall
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Christey> aka "shell" on UNIX systems (at least Solaris) in the
   /etc/inetd.conf file.
 Frech> associated to:
   XF:nt-rlogin(92) 
   XF:rsh-svc(114)
   XF:rshd(2995)


CAN-1999-0652

Phase: Proposed (19990804)

Description:
A database service is running, e.g. a SQL server, Oracle, or mySQL.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Wall
   REJECT(1) Northcutt
Voter Comments:
 Frech> XF:nt-sql-server(1289)
   XF:msql-detect(2211)
   XF:oracle-detect(2388)
   XF:sybase-detect-namedpipes(1461)


CAN-1999-0653

Phase: Proposed (19990804)

Description:
A component service related to NIS+ is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0654

Phase: Proposed (19990728)

Description:
The OS/2 or POSIX subsystem in NT is enabled.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Northcutt
Voter Comments:
 Wall> These subsystems could still allow a process to persist across logins.
 Frech> XF:nt-posix(217)
   XF:nt-posix-sub-c2(2397)
   XF:nt-posix-sub-onceonly(2478)
   XF:nt-os2-sub(218)
   XF:nt-os2-sub-c2(2396)
   XF:nt-os2-sub-onceonly(2477)
   XF:nt-os2-registry(2550)
 Christey> s2-file-os2(1865)


CAN-1999-0655

Phase: Proposed (19990721)

Description:
A service may include useful information in its banner or help function (such as the name and version), making it useful for information gathering activities.

Votes:

   ACCEPT(5) Northcutt, Baker, Frech, Ozancin, Wall
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to ACCEPT]


CAN-1999-0656

Phase: Proposed (19990804)

Description:
The ugidd service is running.

Votes:

   ACCEPT(1) Baker
   NOOP(1) Wall
   REJECT(1) Northcutt

CAN-1999-0657

Phase: Proposed (19990804)

Description:
WinGate is being used.

Votes:

   ACCEPT(1) Baker
   NOOP(1) Wall
   REJECT(1) Northcutt

CAN-1999-0658

Phase: Proposed (19990804)

Description:
DCOM is running.

Votes:

   ACCEPT(2) Baker, Wall
   REJECT(1) Northcutt

CAN-1999-0659

Phase: Proposed (19990804)

Description:
A Windows NT Primary Domain Controller (PDC) or Backup Domain Controller (BDC) is present.

Votes:

   REJECT(3) Northcutt, Baker, Wall
Voter Comments:
 Wall> Don't consider this a service or a problem.
 Baker> concur with wall on this


CAN-1999-0660

Phase: Proposed (19990804)

Description:
A hacker utility, back door, or Trojan Horse is installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc.

Votes:

   ACCEPT(4) Northcutt, Baker, Wall, Hill
   NOOP(1) Christey
Voter Comments:
 Christey> Add "back door" to description.


CAN-1999-0661

Phase: Modified (20020801-01)
Reference: CERT:CA-1994-07
Reference: URL:http://www.cert.org/advisories/CA-1994-07.html
Reference: CERT:CA-1994-14
Reference: URL:http://www.cert.org/advisories/CA-1994-14.html
Reference: CERT:CA-1999-01
Reference: URL:http://www.cert.org/advisories/CA-1999-01.html
Reference: CERT:CA-1999-02
Reference: URL:http://www.cert.org/advisories/CA-1999-02.html
Reference: BUGTRAQ:20020801 trojan horse in recent openssh (version 3.4 portable 1)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102820843403741&w=2
Reference: BUGTRAQ:20020801 OpenSSH Security Advisory: Trojaned Distribution Files
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102821663814127&w=2

Description:
A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, or (5) OpenSSH 3.4p1.

Votes:

   ACCEPT(4) Northcutt, Baker, Wall, Hill
   NOOP(1) Christey
Voter Comments:
 Christey> Should add the specific CERT advisory references for
   well-known Trojaned software.
   TCP Wrappers -> CERT:CA-1999-01
   CERT:CA-1999-02 includes util-linux
   wuarchive - CERT:CA-94.07
   IRC client - CERT:CA-1994-14
 Christey> BUGTRAQ:20020801 trojan horse in recent openssh (version 3.4 portable 1)
   Modify description to use dot notation.
 Christey> CERT:CA-2002-24
   URL:http://www.cert.org/advisories/CA-2002-24.html
   XF:openssh-backdoor(9763)
   URL:http://www.iss.net/security_center/static/9763.php
   BID:5374
   URL:http://www.securityfocus.com/bid/5374


CAN-1999-0662

Phase: Proposed (19990804)

Description:
A system-critical program or library does not have the appropriate patch, hotfix, or service pack installed, or is outdated or obsolete.

Votes:

   ACCEPT(4) Northcutt, Baker, Wall, Hill

CAN-1999-0663

Phase: Proposed (19990804)

Description:
A system-critical program, library, or file has a checksum or other integrity measurement that indicates that it has been modified.

Votes:

   ACCEPT(3) Baker, Wall, Hill
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> This needs to be worded carefully.  
   1. Rootkits evade checksum detection.
   2. The modification could be positive (a patch)


CAN-1999-0664

Phase: Proposed (19990803)

Description:
An application-critical Windows NT registry key has inappropriate permissions.

Votes:

   ACCEPT(1) Wall
   RECAST(2) Christey, Northcutt
Voter Comments:
 Northcutt> I think we can define appropriate, take a look at the nt security .pdf
   and see if you can't see a way to phrase specific keys in a way that
   defines inappropriate.
 Christey> Upon further reflection, this is too high-level for CVE.
   Specific registry keys with bad permissions is roughly
   equivalent to Unix configuration files that have bad
   permissions; those permission problems can be created by
   any vendor, not just a specific one.  Therefore this
   candidate should be RECAST into each separate registry
   key that has this problem.


CAN-1999-0665

Phase: Proposed (19990803)

Description:
An application-critical Windows NT registry key has an inappropriate value.

Votes:

   ACCEPT(1) Wall
   RECAST(1) Northcutt
Voter Comments:
 Northcutt> I think we can define appropriate, take a look at the nt security .pdf
   and see if you can't see a way to phrase specific keys in a way that
   defines inappropriate.


CAN-1999-0667

Phase: Proposed (19991222)

Description:
The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denial of service.

Votes:

   ACCEPT(2) Blake, Cole
   MODIFY(1) Stracener
   NOOP(1) Christey
   REJECT(1) Frech
Voter Comments:
 Stracener> Add Ref: BUGTRAQ:19970919 Playing redir games with ARP and ICMP
 Frech> Cannot proceed without a reference. Too vague, and resembles XF:netbsd-arp:
   CAN-1999-0763: NetBSD on a multi-homed host allows ARP packets on one
   network to modify ARP entries on another connected network.
   CAN-1999-0764: NetBSD allows ARP packets to overwrite static ARP entries.
   Will reconsider if reference provides enough information to render a
   distinction.
 Christey> This particular vulnerability was exploited by an attacker
   during the ID'Net IDS test network exercise at the SANS
   Network Security '99 conference.  The attacker adapted a
   publicly available program that was able to spoof another
   machine on the same physical network.
   
   See http://marc.theaimsgroup.com/?l=bugtraq&m=87602880019797&w=2
   for the Bugtraq reference that Tom Stracener suggested.
   This generated a long thread on Bugtraq in 1997.
 Blake> I'll second Tom's request to add the reference, it's a very
   posting good and the vulnerability is clearly derivative of
   the work.
   
   (I do recall talking to the guy and drafting a description.)


CAN-1999-0669

Phase: Interim (19991229)
Reference: MS:MS99-032
Reference: CIAC:J-064
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/j-064.shtml
Reference: XF:ms-scriptlet-eyedog-unsafe
Reference: MSKB:Q240308

Description:
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy.

Votes:

   ACCEPT(5) Prosser, Baker, Ozancin, Wall, Cole
   MODIFY(2) Frech, Stracener
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:ms-scriptlet-eyedog-unsafe
 Stracener> Add Ref: MSKB Q240308
 Christey> Should CAN-1999-0669 and 668 be merged?  If not, then this is
   a reason for not merging CAN-1999-0988 and CAN-1999-0828.


CAN-1999-0670

Phase: Proposed (19991208)
Reference: MS:MS99-032
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-032.asp
Reference: CIAC:J-064
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/j-064.shtml

Description:
Buffer overflow in the Eyedog ActiveX control allows a remote attacker to execute arbitrary commands.

Votes:

   ACCEPT(3) Prosser, Ozancin, Wall
   MODIFY(2) Frech, Stracener
   REJECT(2) Baker, Cole
Voter Comments:
 Frech> XF:ie-eyedog-bo
 Cole> Based on the references and information listed this is the same as
   CAN-1999-0669
 Stracener> Add Ref: MSKB Q240308
 Baker> Duplicate


CAN-1999-0673

Phase: Proposed (19991222)
Reference: BID:574
Reference: URL:http://www.securityfocus.com/bid/574

Description:
Buffer overflow in ALMail32 POP3 client via From: or To: headers.

Votes:

   ACCEPT(6) Blake, Baker, Levy, Wall, Cole, Collins
   MODIFY(2) Frech, Stracener
   NOOP(3) Oliver, Landfield, Armstrong
   REVIEWING(1) Ozancin
Voter Comments:
 Stracener> AddRef: ShadowPenguinSecurity:PenguinToolbox,No.037
 Frech> XF:almail-bo
 CHANGE> [Cole changed vote from NOOP to ACCEPT]


CAN-1999-0677

Phase: Modified (19991228-01)
Reference: BUGTRAQ:19990802 [LoWNOISE] Password hunting with webramp
Reference: BID:577
Reference: URL:http://www.securityfocus.com/bid/577

Description:
The WebRamp web administration utility has a default password.

Votes:

   ACCEPT(3) Blake, Baker, Stracener
   MODIFY(2) Frech, Cole
   NOOP(2) Christey, Armstrong
Voter Comments:
 Cole> I would add that is is not forced to be changed.
 Frech> XF:webramp-default-password
 Christey> This problem may have been detected in January 1999:
   BUGTRAQ:19990121 Re: WebRamp M3 remote network access bug
   http://marc.theaimsgroup.com/?l=bugtraq&m=91702375402055&w=2


CAN-1999-0684

Phase: Proposed (19991214)
Reference: HP:HPSBUX9904-097

Description:
Denial of service in Sendmail 8.8.6 in HPUX.

Votes:

   ACCEPT(2) Blake, Cole
   MODIFY(3) Prosser, Frech, Stracener
   REJECT(1) Christey
Voter Comments:
 Stracener> Add Ref: CIAC: J-040
 Prosser> Might change description to indicate DoS caused by multiple connections
 Christey> Andre's right.  This is a duplicate of CAN-1999-0684.
 Frech> Without further information and/or references, this issue looks like an
   ambiguous version of CVE-1999-0478: Denial of service in HP-UX sendmail
   8.8.6 related to accepting connections.
   
   (was REJECT)
   XF:hp-sendmail-connect-dos


CAN-1999-0698

Phase: Proposed (19991222)

Description:
Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux.

Votes:

   ACCEPT(6) Blake, Baker, Ozancin, Cole, Armstrong, Collins
   MODIFY(1) Frech
   NOOP(4) Levy, Wall, Landfield, Stracener
   REJECT(1) Christey
Voter Comments:
 Stracener> Is the candidate referring to the denial of service problem mentioned in
   the
   changelogs for versions previous to 1.4.3-1 or does it pertain to some
   problem with or
   1.4.8-1?
 Frech> Depending on the version, this could be any number of DoSes 
   related to ippl.
   From http://www.larve.net/ippl/:
   9 April 1999: version 1.4.3 released, correctly fixing a 
   potential denial of service attack.
   7 April 1999: version 1.4.2 released, fixing a potential 
   denial of service attack. 
   XF:linux-ippl-dos
 Christey> Changelog: http://pltplp.net/ippl/docs/HISTORY
   
   See comments for version 1.4.2 and 1.4.3
   Another source: http://freshmeat.net/news/1999/04/08/923586598.html
 CHANGE> [Stracener changed vote from REVIEWING to NOOP]
 CHANGE> [Christey changed vote from NOOP to REJECT]
 Christey> As mentioned by others, this could apply to several different
   versions.  Since the description is too vague, this CAN should
   be REJECTED and recast into other candidates.


CAN-1999-0712

Phase: Proposed (19991214)
Reference: CALDERA:CSSA-1999:009
Reference: XF:linux-coas

Description:
A vulnerability in Caldera Open Administration System (COAS) allows the /etc/shadow password file to be made world-readable.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Stracener
   MODIFY(1) Blake
   NOOP(1) Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Blake> This obscurely-written advisory seems to state that COAS will make the
   file world-readable, not that it allows the user to make it so.  I hardly
   think that allowing the user to turn off security is a vulnerability.
 Christey> It's difficult to write the description based on what's in
   the advisory.  If COAS inadvertently changes permissions
   without user confirmation, then it should be ACCEPTed with
   appropriate modification to the description.
 Christey> ADDREF BID:137
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]


CAN-1999-0718

Phase: Proposed (20010214)
Reference: NTBUGTRAQ:19990823 IBM Gina security warning
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9908&L=ntbugtraq&F=&S=&P=5534
Reference: BID:608
Reference: URL:http://www.securityfocus.com/bid/608
Reference: XF:ibm-gina-group-add
Reference: URL:http://xforce.iss.net/static/3166.php

Description:
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privileges by changing the GroupMapping registry key.

Votes:

   ACCEPT(3) Baker, Frech, Cole
Voter Comments:
 Frech> XF:ibm-gina-group-add 


CAN-1999-0736

Phase: Proposed (19991208)
Reference: L0PHT:May7,1999
Reference: MS:MS99-013
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-013.asp
Reference: MSKB:Q232449
Reference: MSKB:Q231368

Description:
The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(4) Prosser, Ozancin, Wall, Stracener
   MODIFY(2) Frech, Cole
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:iis-samples-showcode
 Cole> There are several sample files that allow this.  I would quote
   showcode.asp but make it more generic.
 Prosser> (Modify)
   Have a question on this and on the following three candidates as well.  All
   of these are part of the file viewers utilities that allow unauthorized
   files reading, but MSKB Q231368 also mentioned the diagnostics
   program,Winmsdp.exe, as another vulnerable viewer in this same set of
   viewers.  If we are going to split out the seperate viewer tools then
   shouldn't there should be a seperate CAN for Winmsdp.exe also.
 Christey> Mike's question basically touches on the CD:SF-EXEC
   content decision - what do you do when you have the same bug
   in multiple executables?  CD:SF-EXEC needs to be reviewed
   and approved by the Editorial Board before we can decide
   what to do with this candidate.
 Christey> Mark Burnett says that Microsoft's mention of winmsdp.exe in
   MSKB:Q231368 may be an error, and that winmsdp.exe is a
   Microsoft Diagnostics Report Generator which may not even
   be installed as part of IIS.
   
   Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html
 Christey> ADDREF BID:167
   URL:http://www.securityfocus.com/vdb/bottom.html?vid=167


CAN-1999-0737

Phase: Proposed (19991208)
Reference: MS:MS99-013
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-013.asp
Reference: MSKB:Q231656

Description:
The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(4) Prosser, Ozancin, Wall, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Cole
Voter Comments:
 Frech> XF:iis-samples-viewcode
 Cole> I would combine this with the previous.
 Prosser> (modify)
   See comments in 0736 above
 Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html
   for additional details.


CAN-1999-0738

Phase: Proposed (19991208)
Reference: MS:MS99-013
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-013.asp
Reference: MSKB:Q232449
Reference: MSKB:Q231368

Description:
The code.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(4) Prosser, Ozancin, Wall, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Cole
Voter Comments:
 Frech> XF:iis-samples-code
 Cole> Same as above
 Prosser> (modify)
   See comments in 0736 above
 Christey> See http://www.securityfocus.com/focus/microsoft/iis/showcode.html
   for additional details.


CAN-1999-0739

Phase: Proposed (19991208)
Reference: MS:MS99-013
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-013.asp
Reference: MSKB:Q232449
Reference: MSKB:Q231368

Description:
The codebrws.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(4) Prosser, Ozancin, Wall, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Cole
Voter Comments:
 Frech> XF:iis-samples-codebrws
 Cole> Same as above.
 Prosser> (modify)
   See comments in 0736 above
 Christey> codebrw2.asp and Codebrw1.asp also need to be included
   somewhere.
   
   Also see http://www.securityfocus.com/focus/microsoft/iis/showcode.html


CAN-1999-0741

Phase: Proposed (19991222)
Reference: BUGTRAQ:19990818 QMS 2060 printer security hole
Reference: BID:593
Reference: URL:http://www.securityfocus.com/bid/593
Reference: XF:qms-2060-no-root-password

Description:
QMS CrownNet Unix Utilities for 2060 allows root to log on without a password.

Votes:

   ACCEPT(4) Baker, Frech, Levy, Stracener
   NOOP(2) Christey, Oliver
Voter Comments:
 Christey> change description - anyone can log on *as* root
 Frech> (Note: this XF also cataloged under CAN-1999-0508.)


CAN-1999-0748

Phase: Proposed (19991214)
Reference: REDHAT:RHSA-1999:017-01

Description:
Buffer overflows in Red Hat net-tools package.

Votes:

   ACCEPT(3) Cole, Armstrong, Stracener
   MODIFY(1) Frech
   REJECT(1) Blake
Voter Comments:
 Blake> RHSA-1999:017-01 describes "potential security problem fixed" in the
   absence of knowing whether or not the problems actually existed, I don't
   think we have an entry here.
 Frech> XF:redhat-net-tool-bo


CAN-1999-0750

Phase: Proposed (19991222)
Reference: BUGTRAQ:19990913 Hotmail security vulnerability - injecting JavaScript using 'STYLE' tag
Reference: BID:630
Reference: URL:http://www.securityfocus.com/bid/630

Description:
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account.

Votes:

   ACCEPT(1) Levy
   MODIFY(2) Frech, Stracener
Voter Comments:
 Stracener> Many sites are vulnerable to this problem. I recommend removing the
   explicit references to Hotmail and making the description more generic.
   Suggest: Javascript can be injected using the STYLE tag in an HTML
   formatted e-mail, allowing remote attackers to execute commands on user
   accounts.
 Frech> XF:hotmail-html-style-embed


CAN-1999-0757

Phase: Proposed (20010214)
Reference: ALLAIRE:ASB99-08
Reference: URL:http://www.allaire.com/handlers/index.cfm?ID=10969&Method=Full
Reference: XF:coldfusion-encryption
Reference: URL:http://xforce.iss.net/static/2208.php

Description:
The ColdFusion CFCRYPT program for encrypting CFML templates has weak encryption, allowing attackers to decrypt the templates.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(1) Christey
Voter Comments:
 Frech> XF:coldfusion-encryption 
 Christey> BUGTRAQ:19990724 Re: New Allaire Security Zone Bulletins and KB Articles
   URL:http://www.securityfocus.com/archive/1/19471
 Christey> ADDREF BID:275
   URL:http://www.securityfocus.com/bid/275


CAN-1999-0767

Phase: Proposed (19991214)
Reference: SUN:00189

Description:
Buffer overflow in Solaris libc, ufsrestore, and rcp via LC_MESSAGES environmental variable.

Votes:

   ACCEPT(4) Blake, Baker, Cole, Dik
   MODIFY(2) Frech, Stracener
   REVIEWING(2) Christey, Prosser
Voter Comments:
 Stracener> Add Ref: CIAC: J-069
 Frech> XF:sun-libc-lcmessages
 Prosser> BID 268 is an additional reference for this one as it has info on the Sun
   vulnerability.  However, BID 268 also includes AIX in this vulnerability and
   refs APARS issued to fix a vulnerability in various 'nixs with the Natural
   Language Service environmental variables NSLPATH and PATH_LOCALE depending
   on the 'nix, ref CERT CA-97.10, CVE-1999-0041.  However, Georgi Guninski
   reported a BO in AIX with LC_MESSAGES + mount, also refed in BID 268, so it
   is possible the AIX APARs fix an earlier, similar vulnerability to the Sun
   BO in LC_MESSAGES.   This should probably be considered under a different
   CAN.  Any ideas? 
 Christey> Given that the buffer overflows in CVE-1999-0041 are NLSPATH
   and PATH_LOCALE, I'd say that's good evidence that this is not
   the same problem.  But a buffer overflow in libc in
   LC_MESSAGES... We must ask if these are basically the same
   codebase.
   
   ADDREF CIAC:J-069
 Christey> While the description indicates multiple programs, CD:SF-EXEC
   does not apply because the vulnerability was in libc, and
   rcp and ufsrestore were both statically linked against libc.
   Thus CD:SF-LOC applies, and a single candidate is maintained
   because the problem occurred in a library.
 Dik> Sun bug 4240566
 Christey> I'm consulting with Casper Dik and Troy Bollinger to see if
   this should be combined with the AIX buffer overflows for
   LC_MESSAGES; current indications are that they should be
   split.
 Christey> For further consultation, consider this post, though it's
   associated with CVE-1999-0041:
   BUGTRAQ:19970213 Linux NLSPATH buffer overflow
   http://www.securityfocus.com/archive/1/6296
   Also add "NLSPATH" and "PATH_LOCALE" to the description to
   facilitate search.


CAN-1999-0776

Phase: Proposed (19991214)
Reference: NTBUGTRAQ:19990506 ".."-hole in Alibaba 2.0
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9905&L=NTBUGTRAQ&P=R1533
Reference: XF:http-alibaba-dotdot

Description:
Alibaba HTTP server allows remote attackers to read files via a .. (dot dot) attack.

Votes:

   ACCEPT(4) Frech, Ozancin, Levy, Stracener
   MODIFY(1) Baker
   NOOP(6) Blake, LeBlanc, Wall, Landfield, Cole, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Christey> This candidate is unconfirmed by the vendor.
   
   Posted by Arne Vidstrom.
 Blake> I'd like to change my vote on this from ACCEPT to NOOP.  I did some
   digging and the vendor seems to have discontinued the product, so no
   information is available beyond Arne's post.  Unless Andre has a copy
   in his archive and can test it, I think we have to leave it out.
 Wall> I agree with Blake.  We have not seen the product and it has been discontinued.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> If this is (or was) tested by some tool, we should ACCEPT it.
 Baker> http://www.securityfocus.com/bid/270
 Christey> BID:270
   URL:http://www.securityfocus.com/bid/270


CAN-1999-0784

Phase: Proposed (20010214)
Reference: NTBUGTRAQ:19980827 NERP DoS attack possible in Oracle
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/1998/msg00536.html
Reference: BUGTRAQ:19990104 Re: Fw:"NERP" DoS attack possible in Oracle
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/1999_1/0056.html
Reference: BUGTRAQ:19981228 Oracle8 TNSLSNR DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/1998_4/0764.html

Description:
Denial of service in Oracle TNSLSNR SQL*Net Listener via a malformed string to the listener port, aka NERP.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Cole
Voter Comments:
 Frech> XF:oracle-tnslsnr-dos(1551)


CAN-1999-0792

Phase: Modified (20000827)
Reference: MISC:http://www2.merton.ox.ac.uk/~security/rootshell/0022.html

Description:
ROUTERmate has a default SNMP community name which allows remote attackers to modify its configuration.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Stracener
   NOOP(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Stracener> Change the Ref to read: ROOTSHELL: Osicom Technologies ROUTERmate
   Security
   Advisory
 Frech> XF:routermate-snmp-community
 Christey> BUGTRAQ:19980914 [rootshell] Security Bulletin #23
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90581019105693&w=2


CAN-1999-0795

Phase: Proposed (19991222)
Reference: NAI:NAI-27

Description:
The NIS+ rpc.nisd server allows remote attackers to execute certain RPC calls without authentication to obtain system information, disable logging, or modify caches.

Votes:

   ACCEPT(2) Baker, Stracener
   MODIFY(1) Frech
   NOOP(1) Ozancin
Voter Comments:
 Frech> XF:sun-nisplus


CAN-1999-0798

Phase: Proposed (19991222)
Reference: BUGTRAQ:19981204 bootpd remote vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91278867118128&w=2

Description:
Buffer overflow in bootpd on OpenBSD, FreeBSD, and Linux systems via a malformed header type.

Votes:

   ACCEPT(2) Ozancin, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> Is CAN-1999-0389 a duplicate of CAN-1999-0798?  CAN-1999-0389
   has January 1999 dates associated with it, while CAN-1999-0798
   was reported in late December.
   
   http://marc.theaimsgroup.com/?l=bugtraq&m=91278867118128&w=2
   
   SCO appears to have acknowledged this as well:
   ftp://ftp.sco.com/SSE/security_bulletins/SB-99.01a
   
   The poster also claims that OpenBSD fixed this as well.
 Frech> XF:bootp-remote-bo
 Christey> Further analysis indicates that this is a duplicate of CVE-1999-0799
 CHANGE> [Christey changed vote from REJECT to NOOP]
 Christey> What was I thinking?  Brian Caswell pointed out that this is
   *not* the same bug as CVE-1999-0799.  As reported in the
   1998 Bugtraq post, the bug is in bootpd.c, and is related
   to providing an htype value that is used as an index
   into an array, and exceeds the intended boundaries of that
   array.


CAN-1999-0805

Phase: Proposed (20010214)
Reference: BUGTRAQ:19990512 DoS with Netware 4.x's TTS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/1999_2/0439.html
Reference: XF:novell-tts-dos
Reference: URL:http://xforce.iss.net/static/2184.php

Description:
Novell NetWare Transaction Tracking System (TTS) in Novell 4.11 and earlier allows remote attackers to cause a denial of service via a large number of requests.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(2) Christey, Cole
Voter Comments:
 Christey> BID:276
   URL:http://www.securityfocus.com/vdb/bottom.html?vid=276
 Frech> XF:novell-tts-dos


CAN-1999-0808

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980518 DHCP 1.0 and 2.0 SECURITY ALERT! (fwd)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925960&w=2
Reference: CIAC:I-053
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/i-053.shtml
Reference: MISC:ftp://ftp.isc.org/isc/dhcp/dhcp-1.0-history/dhcp-1.0.0-1.0pl1.diff.gz

Description:
Multiple buffer overflows in ISC DHCP Distribution server (dhcpd) 1.0 and 2.0 allow a remote attacker to cause a denial of service (crash) and possibly execute arbitrary commands via long options.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:dhcp-remote-dos(7248)


CAN-1999-0816

Phase: Modified (20000313-01)
Reference: BUGTRAQ:19980510 Security Vulnerability in Motorola CableRouters
Reference: URL:http://www.netspace.org/cgi-bin/wa?A2=ind9805B&L=bugtraq&P=R1621
Reference: XF:motorola-cable-default-pass

Description:
The Motorola CableRouter allows any remote user to connect to and configure the router on port 1024.

Votes:

   ACCEPT(3) Baker, Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Christey, LeBlanc
Voter Comments:
 Christey> This candidate is unconfirmed by the vendor.
 Frech> XF:motorola-cable-default-pass


CAN-1999-0818

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991130 another hole of Solaris7 kcms_configure
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=38433B7F5A.53F4SHADOWPENGUIN@fox.nightland.net
Reference: BID:831
Reference: URL:http://www.securityfocus.com/bid/831

Description:
Buffer overflow in Solaris kcms_configure via a long NETPATH environmental variable.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(4) Prosser, Frech, Cole, Dik
   REVIEWING(1) Christey
Voter Comments:
 Cole> This can cause code to be executed.
 Frech> XF:sol-kcms-conf-netpath-bo
 Dik> the bug has nothing to do with kcms_configure; it's a bug
   in libnsl.so.  All set-uid executables that trigger this code path are
   vulnerable.  Sun bug 4295834; fixed in Solaris 8.
 Prosser> Okay, I am confused.  Based on Casper's comments and checking
   on the Sun patch site, I found the 4295834 bug(4295834 NETPATH security
   problem in libnsl) fixed in  SunOS 5.4, Patch 101974-37(x86) 101973 (sparc).
   Multiple libnsl vulnerabilities was first reported in an 98 Sun Bulletin
   #00172 for 5.4 up through 2.6.   Was this NETPATH a problem that resurfaced
   in 7 (looks like in 5.4 as well) and was fixed in 8?
 Christey> Need to dig up my offline email on this.
 Christey> May be a duplicate of CVE-1999-0321, whose sole reference
   (XF:sun-kcms-configure-bo) no longer exists.  Also examine
   BID:452 and
   BUGTRAQ:19981223 Merry Christmas to Sun! (Was: L0pht NFR N-Code
   Modules Updated)
   
   which are the same as XF:sol-kcms-conf-p-bo(3652), which could
   be the new name for XF:sun-kcms-configure-bo.


CAN-1999-0821

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991130 Several FreeBSD-3.3 vulnerabilities
Reference: BID:838
Reference: URL:http://www.securityfocus.com/bid/838

Description:
FreeBSD seyon allows local users to gain privileges by providing a malicious program in the -emulator argument.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) Cole
   REVIEWING(1) Prosser
Voter Comments:
 Cole> I would combine this with the previous.  To me the general
   vulnerabilities are similar it is just the end result that changes.
 Frech> XF:freebsd-seyon-setgid
 Christey> ADDREF? CALDERA:CSSA-1999-037.0


CAN-1999-0822

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991130 serious Qpopper 3.0 vulnerability
Reference: BUGTRAQ:19991130 qpop3.0b20 and below - notes and exploit
Reference: BID:830
Reference: URL:http://www.securityfocus.com/bid/830

Description:
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.

Votes:

   ACCEPT(3) Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Prosser
Voter Comments:
 Frech> XF:qpopper-auth-bo
 Christey> ADDREF? DEBIAN:19991215 buffer overflow in qpopper v3.0
   ADDREF XF:qpopper-auth-bo


CAN-1999-0825

Phase: Modified (20000121-01)
Reference: BUGTRAQ:19991203 UnixWare read/modify users' mail
Reference: BUGTRAQ:19991215 Recent postings about SCO UnixWare 7
Reference: BUGTRAQ:19991223 FYI, SCO Security patches available.
Reference: BID:849
Reference: URL:http://www.securityfocus.com/bid/849

Description:
The default permissions for UnixWare /var/mail allow local users to read and modify other users' mail.

Votes:

   ACCEPT(3) Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Prosser
Voter Comments:
 Frech> XF:sco-mail-permissions
 Christey> ADDREF ftp://ftp.sco.com/SSE/security_bulletins/SB-99.25a


CAN-1999-0827

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991130 Default IE 5.0 security settings allow frame spoofing

Description:
By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing.

Votes:

   ACCEPT(3) LeBlanc, Armstrong, Stracener
   MODIFY(2) Frech, Cole
   REVIEWING(1) Prosser
Voter Comments:
 Cole> The BID is 855.  If I have the right vulnerability, this allows an
   attacker to access URL's of there choosing which could lead to a compromise
   of private information.
 Frech> XF:http-frame-spoof
   Question: Similar vulnerability to MS98-020 / CAN-1999-0869?
 LeBlanc> MSRC tells me this is patched in MS00-009


CAN-1999-0828

Phase: Modified (20000121-01)
Reference: BUGTRAQ:19991203 UnixWare and the dacread permission
Reference: BUGTRAQ:19991204 UnixWare pkg* command exploits
Reference: BUGTRAQ:19991223 FYI, SCO Security patches available.
Reference: BUGTRAQ:19991220 SCO OpenServer Security Status
Reference: BID:853
Reference: URL:http://www.securityfocus.com/bid/853

Description:
UnixWare pkg commands such as pkginfo, pkgcat, and pkgparam allow local users to read arbitrary files via the dacread permission.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(2) Frech, Cole
   REVIEWING(2) Christey, Prosser
Voter Comments:
 Cole> This is BID 850.
 Christey> See comments on CAN-1999-0988.  Perhaps these two should be
   merged. ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a
   loosely alludes to this problem; the README for patch SSE053
   effectively confirms it.
 Frech> XF:sco-pkg-dacread-fileread


CAN-1999-0829

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991201 HP Secure Web Console

Description:
HP Secure Web Console uses weak encryption.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(1) Prosser
Voter Comments:
 Cole> I could not find details on this using the above references.
 Frech> XF:hp-secure-console


CAN-1999-0830

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991126 [w00giving '99 #6]: UnixWare 7's Xsco

Description:
Buffer overflow in SCO UnixWare Xsco command via a long argument.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(3) Prosser, Frech, Cole
   REVIEWING(1) Christey
Voter Comments:
 Cole> This is BID 824 and the BUGTRAQ reference is 19991125.
 Frech> XF:sco-unixware-xsco
 Christey> Confirmed by vendor, albeit vaguely:
   http://marc.theaimsgroup.com/?l=bugtraq&m=94581379905584&w=2
   
 Prosser> agree with Steve on vendor confirmation, however not sure the
   fix ref'd in BID 824 (SSE041) is right.  It lists fixes for libnsl and
   tcpip.so, nothing about xsco.  SSE050b
   (ftp://ftp.sco.com/SSE/security_bulletins/SB-99.26b) fixes a buffer overflow
   in xsco on OpenServer (the vendor message Steve refers to) but not the
   UnixWare vulnerability reported on Bugtraq and in BID824. Anyone more
   familar with SCO shed some light on this? Are they the same codebase so fix
   would be same?  From the SCO site it seems the UnixWare and OpenSever
   products are similar but have differences.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> BID:824
   http://www.securityfocus.com/bid/824


CAN-1999-0840

Phase: Proposed (19991208)
Reference: BID:832
Reference: URL:http://www.securityfocus.com/bid/832
Reference: BUGTRAQ:19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow

Description:
Buffer overflow in CDE dtmail and dtmailpr programs via the -f option.

Votes:

   ACCEPT(3) Armstrong, Dik, Stracener
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(1) Prosser
Voter Comments:
 Cole> I went to 1129 and it looks like a reference for a different
   vulnerability.
 Frech> In the description, should dtmailptr be dtmailpr?
   XF:solaris-dtmailpr-overflow
   XF:solaris-dtmail-overflow
 Dik> sun bug: 4166321


CAN-1999-0841

Phase: Proposed (19991208)
Reference: BID:832
Reference: URL:http://www.securityfocus.com/bid/832
Reference: BUGTRAQ:19991129 Solaris7 dtmail/dtmailpr/mailtool Buffer Overflow

Description:
Buffer overflow in CDE mailtool allows local users to gain root privilege via a long MIME Content-Type.

Votes:

   ACCEPT(4) Cole, Armstrong, Dik, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Prosser
Voter Comments:
 Frech> XF:cde-mailtool-bo
 Dik> bug 4163471
   (Root access is only possible when mail is send to root and he
   uses dtmail to read it)


CAN-1999-0843

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991104 Cisco NAT DoS (VD#1)
Reference: BUGTRAQ:19991128 Re: Cisco NAT DoS (VD#1)

Description:
Denial of service in Cisco routers running NAT via a PORT command from an FTP client to a Telnet port.

Votes:

   ACCEPT(3) Balinsky, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Armstrong
   REVIEWING(3) Christey, Prosser, Ziese
Voter Comments:
 Frech> XF:cisco-nat-dos
 Christey> Mike Prosser's REVIEWING vote expires July 17, 2000
 Ziese> After reviewing
   http://www.cisco.com/warp/public/707/iostelnetopt-pub.shtml 
   I can not confirm this exists unless it's restructred to
   describe a problem against IOS per se; not NAT per se.  I am
   reviewing this and it may take some time.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Not sure if Kevin's suggested reference really describes this
   one.  However, a followup email by Jim Duncan of Cisco does
   acknowledge the problem as discussed in the Bugtraq post:
   http://marc.theaimsgroup.com/?l=vuln-dev&m=94385601831585&w=2
   The original post is:
   http://marc.theaimsgroup.com/?l=bugtraq&m=94184947504814&w=2
   
   It could be that the researcher believed that the problem was
   NAT, but in fact it wasn't.
   
   I need to follow up with Ziese/Balinsky on this one.


CAN-1999-0844

Phase: Proposed (19991208)
Reference: NTBUGTRAQ:19991124 Remote DoS Attack in WorldClient Server v2.0.0.0 Vulnerability
Reference: BUGTRAQ:19991130 Fwd: RE: Multiples Remotes DoS Attacks in MDaemon Server v2.8.5.0 Vulnerability
Reference: BID:823
Reference: URL:http://www.securityfocus.com/bid/823
Reference: BID:820
Reference: URL:http://www.securityfocus.com/bid/820

Description:
Denial of service in MDaemon WorldClient and WebConfig services via a long URL.

Votes:

   ACCEPT(1) Stracener
   MODIFY(2) Frech, Cole
   NOOP(1) Armstrong
   RECAST(1) Christey
   REVIEWING(1) Prosser
Voter Comments:
 Cole> 823 and 820 are two different vulnerabilities and should be
   separated out.  They are both buffer overflows but accomplish it in a
   different fashion and the end exploit is different.
 Frech> (RECAST?)
   XF:mdaemon-worldclient-dos
   XF:mdaemon-webconfig-dos
   Recast request: This is really two services exhibiting the same problem.
 Christey> as suggested by others.
   
   Also see confirmation at:
   http://mdaemon.deerfield.com/helpdesk/hotfix.cfm


CAN-1999-0845

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991126 [w00giving '99 #5 and w00news]: UnixWare 7's su
Reference: SCO:99.19
Reference: BUGTRAQ:19991128 SCO su patches

Description:
Buffer overflow in SCO su program allows local users to gain root access via a long username.

Votes:

   ACCEPT(4) Prosser, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> DUPE CAN-1999-0317?
 Frech> XF:sco-su-username-bo
 Christey> ADDREF BID:826
   CONFIRM:ftp://ftp.sco.com/SSE/sse039.tar.Z


CAN-1999-0846

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991129 MDaemon 2.7 J DoS
Reference: BUGTRAQ:19991130 Fwd: RE: Multiples Remotes DoS Attacks in MDaemon Server v2.8.5.0 Vulnerability

Description:
Denial of service in MDaemon 2.7 via a large number of connection attempts.

Votes:

   ACCEPT(4) Prosser, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:mdaemon-dos
 Christey> CAN-1999-0844 is confirmed by MDaemon at
   http://mdaemon.deerfield.com/helpdesk/hotfix.cfm but there
   is no apparent confirmation for this problem, even
   though it was posted the same day.
 Prosser> Looks like from a follow-on message on Bugtraq from Nobuo
   <http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-11-28&msg=199912011604.HJI39569.BX-NOJ@lac.co.jp> Deerfield sent a reply about the
   DoS problems in MDaemon 2.8.5, that also talks about fixing the 2.7 J DoS
   that Nobuo initially reported. Can't find the original message, so may have
   been limited distro. Looks like an upgrade to the latest release might be
   the final solution here.


CAN-1999-0850

Phase: Proposed (19991208)
Reference: BID:845
Reference: URL:http://www.securityfocus.com/bid/845
Reference: BUGTRAQ:19991202 Insecure default permissions for MailMan Professional Edition, version 3.0.18

Description:
The default permissions for Endymion MailMan allow local users to read email or modify files.

Votes:

   ACCEPT(2) Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Armstrong
   REVIEWING(1) Prosser
Voter Comments:
 Frech> XF:endymion-mailman-perms


CAN-1999-0852

Phase: Proposed (19991208)
Reference: BID:844
Reference: URL:http://www.securityfocus.com/bid/844
Reference: BUGTRAQ:19991202 WebSphere protections from installation

Description:
IBM WebSphere sets permissions that allow a local user to modify a deinstallation script or its data files stored in /usr/bin.

Votes:

   ACCEPT(3) Cole, Armstrong, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Prosser
Voter Comments:
 Frech> XF:websphere-protect


CAN-1999-0855

Phase: Proposed (19991208)
Reference: BID:834
Reference: URL:http://www.securityfocus.com/bid/834
Reference: BUGTRAQ:19991130 FreeBSD 3.3 gated-3.1.5 local exploit

Description:
Buffer overflow in FreeBSD gdc program.

Votes:

   ACCEPT(3) Prosser, Armstrong, Stracener
   MODIFY(2) Frech, Cole
   NOOP(1) Christey
Voter Comments:
 Cole> The BID is 834 and the reference is 19991201 not 1130.
 Frech> XF:freebsd-gdc-bo
 Christey> ADDREF BID:780 ?


CAN-1999-0857

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991130 FreeBSD 3.3 gated-3.1.5 local exploit
Reference: BID:835
Reference: URL:http://www.securityfocus.com/bid/835

Description:
FreeBSD gdc program allows local users to modify files via a symlink attack.

Votes:

   ACCEPT(3) Prosser, Armstrong, Stracener
   MODIFY(2) Frech, Cole
Voter Comments:
 Cole> This is via debug output.
 Frech> XF:freebsd-gdc


CAN-1999-0860

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991130 Solaris 2.x chkperm/arp vulnerabilities
Reference: BID:837
Reference: URL:http://www.securityfocus.com/bid/837

Description:
Solaris chkperm allows local users to read files owned by bin via the VMSYS environmental variable and a symlink attack.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(2) Frech, Dik
   NOOP(1) Christey
   REJECT(1) Cole
   REVIEWING(1) Prosser
Voter Comments:
 Cole> This is the same as the pervious.
 Frech> XF:sol-chkperm-vmsys
 Dik> include reference to Sun bug 4296167
 Christey> Remove BID:837, which is for arp, not chkperm


CAN-1999-0862

Phase: Proposed (19991208)
Reference: BUGTRAQ:19991202 PostgreSQL RPM's permission problems

Description:
Insecure directory permissions in RPM distribution for PostgreSQL allows local users to gain privileges by reading a plaintext password file.

Votes:

   ACCEPT(3) Cole, Armstrong, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Prosser
Voter Comments:
 Frech> XF:postgresql-insecure-perms


CAN-1999-0863

Phase: Proposed (19991208)
Reference: BUGTRAQ:19970617 Seyon vulnerability - IRIX
Reference: BUGTRAQ:19991108 FreeBSD 3.3's seyon vulnerability
Reference: BUGTRAQ:19991130 Several FreeBSD-3.3 vulnerabilities

Description:
Buffer overflow in FreeBSD seyon via HOME environmental variable, -emulator argument, -modems argument, or the GUI.

Votes:

   ACCEPT(4) Prosser, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:freebsd-seyon-bo
 Christey> ADDREF? CALDERA:CSSA-1999-037.0
 Christey> May be multiple bugs here, or a single library problem.
   CD:SF-LOC needs to be resolved before determining if this
   candidate should be SPLIT.  Also see CAN-1999-0821.


CAN-1999-0872

Phase: Proposed (19991214)
Reference: BID:759
Reference: URL:http://www.securityfocus.com/bid/759
Reference: BID:611
Reference: URL:http://www.securityfocus.com/bid/611
Reference: REDHAT:RHSA-1999:030-02

Description:
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.

Votes:

   MODIFY(2) Frech, Cole
   REJECT(3) Christey, Blake, Stracener
Voter Comments:
 Cole> 611 is the mail to listed above but 759 is for the mail from and
   should be listed as a separate vulenrability.
 Blake> This does not appear materially different from CAN-1999-0768
 Christey> This is an apparent duplicate of CAN-1999-0768.
   REDHAT:RHSA-1999:030-02 describes two issues, one of which is
   CAN-1999-0768, and the other is CVE-1999-0769.
 Stracener> This is a duplicate of candidate CAN-1999-0768.
 Frech> XF:cron-sendmail-bo-root
 Christey> BID:759 is improperly assigned to this candidate and doesn't
   even describe it.  It may have been inadvertently copied
   from CAN-1999-0873.


CAN-1999-0882

Phase: Proposed (19991214)
Reference: BUGTRAQ:19991025 Falcon Web Server
Reference: BINDVIEW:Falcon Web Server

Description:
Falcon web server allows remote attackers to determine the absolute path of the web root via long file names.

Votes:

   ACCEPT(3) Blake, Baker, Stracener
   MODIFY(1) Frech
   NOOP(2) Cole, Armstrong
Voter Comments:
 Frech> XF:falcon-server-long-filename


CAN-1999-0885

Phase: Modified (20000313-01)
Reference: BUGTRAQ:19991103 More Alibaba Web Server problems...
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-11-01&msg=01BF261F.928821E0.kerb@fnusa.com
Reference: BID:770
Reference: URL:http://www.securityfocus.com/bid/770
Reference: XF:alibaba-url-file-manipulation

Description:
Alibaba web server allows remote attackers to execute commands via a pipe character in a malformed URL.

Votes:

   ACCEPT(2) Baker, Stracener
   MODIFY(1) Frech
   NOOP(5) Christey, Blake, LeBlanc, Cole, Armstrong
Voter Comments:
 Christey> This candidate is unconfirmed by the vendor.
 Blake> Same as CAN-1999-0776.
 Frech> XF:alibaba-url-file-manipulation
 Christey> CD:SF-LOC and CD:SF-EXEC may say to merge this candidate with
   the problems described in:
   BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0
   URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html
   
   If so, then ADDREF BID:1485 as well.
 Christey> Include the names of the affected CGI's, including tst.bat,
   get32.exe, alibaba.pl, etc.


CAN-1999-0910

Phase: Proposed (19991208)
Reference: MS:MS99-035
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-035.asp
Reference: BID:625
Reference: URL:http://www.securityfocus.com/bid/625

Description:
Microsoft Site Server and Commercial Internet System (MCIS) do not set an expiration for a cookie, which could then be cached by a proxy and inadvertently used by a different user.

Votes:

   ACCEPT(3) Prosser, Ozancin, Wall
   MODIFY(2) Frech, Stracener
   REJECT(1) Cole
Voter Comments:
 Frech> XF:siteserver-cis-cookie-cache
 Cole> Whether cookies are a vulnerbality is a debate for another time, the
   question here is whether the
   expiration feature is a vulnerability and I do not think it is
   because the underlying concerns for this
   are present even without this feature.  The expiration feature does
   not add any new vulenrabilities
   that are not already present with cookies.
 Stracener> Add Ref: MSKB Q238647


CAN-1999-0911

Phase: Proposed (19991214)
Reference: BUGTRAQ:19990827 ProFTPD
Reference: BUGTRAQ:19990907 ProFTP-1.2.0pre4 buffer overflow -- once more
Reference: FREEBSD:FreeBSD-SA-99:03
Reference: BID:612
Reference: URL:http://www.securityfocus.com/bid/612

Description:
Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CWD commands that create nested directories.

Votes:

   ACCEPT(5) Blake, Prosser, Baker, Cole, Stracener
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:proftpd-long-dir-bo(3399)
 Christey> Not absolutely sure if this isn't the same as Palmetto
   (CVE-1999-0368), which describes a similar type of overflow.
   
   NETBSD:NetBSD-SA1999-003 may refer to CVE-1999-0368:
   ADDREF URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA1999-003.txt.asc
 Christey> ADDREF CIAC:J-068
   Include version numbers; too many wu-ftp/etc. problems
   were published in summer/fall 1999


CAN-1999-0913

Phase: Proposed (19991214)
Reference: BUGTRAQ:19990804 NSW Dragon Fire gets drowned
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93383593909438&w=2
Reference: BID:564
Reference: URL:http://www.securityfocus.com/bid/564

Description:
dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.

Votes:

   ACCEPT(2) Blake, Stracener
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Cole, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Christey> Some voters should use ABSTAIN.  
 Frech> XF:dragon-fire-ids-metachar(3834)
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]


CAN-1999-0919

Phase: Modified (20020226-02)
Reference: BUGTRAQ:19980510 Security Vulnerability in Motorola CableRouters
Reference: URL:http://www.netspace.org/cgi-bin/wa?A2=ind9805B&L=bugtraq&P=R1621
Reference: XF:motorola-cable-crash(2004)
Reference: URL:http://xforce.iss.net/static/2004.php

Description:
A memory leak in a Motorola CableRouter allows remote attackers to conduct a denial of service via a large number of telnet connections.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(7) Christey, Ozancin, LeBlanc, Wall, Landfield, Armstrong, Stracener
   REVIEWING(1) Levy
Voter Comments:
 Christey> This candidate is unconfirmed by the vendor.
 Frech> XF:motorola-cable-crash
 Christey> This has enough votes, but not the "confidence" yet (until we
   resolve the question of the amount of verification needed
   for CVE).


CAN-1999-0923

Phase: Proposed (20010214)
Reference: ALLAIRE:ASB99-02
Reference: URL:http://www.allaire.com/handlers/index.cfm?ID=8739&Method=Full

Description:
Sample runnable code snippets in ColdFusion Server 4.0 allow remote attackers to read files, conduct a denial of service, or use the server as a proxy for other HTTP calls.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:coldfusion-source-display(1741)
   XF:coldfusion-syntax-checker(1742)
   XF:coldfusion-file-existence(1743)
   XF:coldfusion-sourcewindow(1744)
 Christey> List all affected runnable code snippets to facilitate
   search, which may include:
   viewexample.cfm (though could that be part of CVE-1999-0922?)


CAN-1999-0925

Phase: Modified (20020829-01)
Reference: BUGTRAQ:19980903 Web servers / possible DOS Attack / mime header flooding
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90486243124867&w=2

Description:
UnityMail allows remote attackers to conduct a denial of service via a large number of MIME headers.

Votes:

   ACCEPT(2) Baker, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Frech> XF:unitymail-web-dos(1630)
 Christey> BID:1760
   URL:http://www.securityfocus.com/bid/1760
 Christey> Affected version is 2.0
   Change date of Bugtraq post - it was 1998.


CAN-1999-0926

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990903 Web servers / possible DOS Attack / mime header flooding
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/1998_3/0742.html

Description:
Apache allows remote attackers to conduct a denial of service via a large number of MIME headers.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> BID:1760
   URL:http://www.securityfocus.com/bid/1760
 Frech> XF:unitymail-web-dos(1630)


CAN-1999-0929

Phase: Interim (19991229)
Reference: BUGTRAQ:19990616 Novell NetWare webservers DoS

Description:
Novell NetWare with Novell-HTTP-Server or YAWN web servers allows remote attackers to conduct a denial of service via a large number of HTTP GET requests.

Votes:

   ACCEPT(4) Blake, Cole, Armstrong, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:novell-webserver-dos(2287)


CAN-1999-0941

Phase: Proposed (19991222)
Reference: BUGTRAQ:19980728 mutt x.x
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526154&w=2

Description:
Mutt mail client allows a remote attacker to execute commands via shell metacharacters.

Votes:

   ACCEPT(1) Stracener
   NOOP(1) Christey
   REJECT(1) Frech
   REVIEWING(1) Levy
Voter Comments:
 Frech> References are vague, but seem to be identical to CAN-1999-0940
   (XF:mutt-text-enriched-mime-bo). According to the references, the malformed
   messages consist of metacharacters. In addition, -0941's reference and
   -0940's SuSE reference both refer to fixes in 1.0pre3 release. Will
   reconsider vote if other clearer references are forthcoming.
 Christey> Modify to mention that the metachar's are in the Content-Type header.
   http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526154&w=2


CAN-1999-0944

Phase: Proposed (19991222)
Reference: BUGTRAQ:19991024 password leak in IBM WebSphere / HTTP Server / ikeyman

Description:
IBM WebSphere ikeyman tool uses weak encryption to store a password for a key database that is used for SSL connections.

Votes:

   ACCEPT(2) Stracener, Baker
   MODIFY(1) Frech
   NOOP(2) Christey, Bollinger
   REVIEWING(1) Levy
Voter Comments:
 Frech> XF:websphere-database-pwd-accessible
 Christey> ADDREF BID:1763
   URL:http://www.securityfocus.com/bid/1763


CAN-1999-0948

Phase: Proposed (19991222)
Reference: BID:757
Reference: URL:http://www.securityfocus.com/bid/757
Reference: BUGTRAQ:19991102 Some holes for Win/UNIX softwares

Description:
Buffer overflow in uum program for Canna input system allows local users to gain root privileges.

Votes:

   ACCEPT(2) Stracener, Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> CAN-1999-0948 and CAN-1999-0949 are extremely similar.
   uum (0948) is exploitable through a different set of options
   than canuum (0949).  If it's the same generic option parsing
   routine used by both programs, then CD:SF-CODEBASE says to
   merge them.  But if it's not, then CD:SF-LOC and CD:SF-EXEC
   says to split them.  However, this is a prime example of
   how SF-EXEC might be modified - uum and canuum are clearly
   part of the same package, so in the absence of clear
   information, maybe we should merge them.
 Frech> XF:canna-uum-bo


CAN-1999-0949

Phase: Proposed (19991222)
Reference: BID:757
Reference: URL:http://www.securityfocus.com/bid/757
Reference: BUGTRAQ:19991102 Some holes for Win/UNIX softwares

Description:
Buffer overflow in canuum program for Canna input system allows local users to gain root privileges.

Votes:

   ACCEPT(2) Stracener, Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> CAN-1999-0948 and CAN-1999-0949 are extremely similar.
   uum (0948) is exploitable through a different set of options
   than canuum (0949).  If it's the same generic option parsing
   routine used by both programs, then CD:SF-CODEBASE says to
   merge them.  But if it's not, then CD:SF-LOC and CD:SF-EXEC
   says to split them.  However, this is a prime example of
   how SF-EXEC might be modified - uum and canuum are clearly
   part of the same package, so in the absence of clear
   information, maybe we should merge them.
   
   Also review BID:758 and BID:757 - may need to change the BID
   here.
 Frech> XF:canna-uum-bo
 Christey> CHANGEREF BID:757 BID:758


CAN-1999-0952

Phase: Proposed (19991222)
Reference: BUGTRAQ:19990126 Buffer overflow in Solaris 2.6/2.7 /usr/bin/lpstat
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91759216618637&w=2

Description:
Buffer overflow in Solaris lpstat via class argument allows local users to gain root access.

Votes:

   ACCEPT(3) Stracener, Baker, Ozancin
   MODIFY(2) Frech, Dik
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:solaris-lpstat-bo
 Christey> It is unclear from Casper Dik's followup whether this is
   exploitable or not.
 Dik> Sunbug 4129917
   (other reports in the same thread suggest that the then current patchd id
   fix the problem)
 Christey> Confirm with Casper Dik that the overflow is in the -c option,
   and if so, include it in the description to differentiate
   it from the lpstat -n buffer overflow.


CAN-1999-0970

Phase: Modified (20020226-01)
Reference: BUGTRAQ:19990605 Remote Exploit (Bug) in OmniHTTPd Web Server
Reference: URL:http://www.securityfocus.com/archive/1/14311
Reference: XF:omnihttpd-dos(2271)
Reference: URL:http://xforce.iss.net/static/2271.php
Reference: BID:1808
Reference: URL:http://www.securityfocus.com/bid/1808

Description:
The OmniHTTPD visadmin.exe program allows a remote attacker to conduct a denial of service via a malformed URL which causes a large number of temporary files to be created.

Votes:

   ACCEPT(3) Stracener, Blake, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Frech> XF:omnihttpd-dos
 Christey> Some sort of confirmation might be findable at:
   http://www.omnicron.ab.ca/httpd/docs/release.html
 Christey> See http://www.omnicron.ab.ca/index.html
   The August 16, 2000 news item says "This release fixes some
   security problems."  It's for version 2.07, but the discloser
   didn't say what version was available.
   
   Other security fixes are in the release notes at
   http://www.omnicron.ab.ca/httpd/docs/release.html Notes for
   Professional Version 1.01 say "Patched up two security weaknesses."
   Notes for version 2.07 say "Fixes dot-appending vulnerability."
   Professional Alpha 7 says "Revamped CGI launching and security,"
   Professional Alpha 4 says "Fixed SSI path mapping and security
   problems," Alpha 5 says "Security fixup."
   
   In other words, you can't tell whether they've fixed this bug
   or not.
 Christey> BID:1808
   URL:http://www.securityfocus.com/bid/1808


CAN-1999-0983

Phase: Proposed (19991214)
Reference: BUGTRAQ:19991109 Whois.cgi - ADVISORY.

Description:
Whois Internic Lookup program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

Votes:

   ACCEPT(3) Stracener, Blake, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> More examination is required to determine if CAN-1999-0983,
   CAN-1999-0984, or CAN-1999-0985 are the same codebase.
 Frech> XF:whois-internic-shell-meta
 Christey> ADDREF BID:2000
 Christey> The XF appears to be gone.  Perhaps it's this one:
   XF:http-cgi-whois-meta(3798)


CAN-1999-0984

Phase: Proposed (19991214)
Reference: BUGTRAQ:19991109 Whois.cgi - ADVISORY.

Description:
Matt's Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

Votes:

   ACCEPT(2) Stracener, Blake
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(1) Christey
Voter Comments:
 Cole> How is this different than the previous?
 Christey> More examination is required to determine if CAN-1999-0983,
   CAN-1999-0984, or CAN-1999-0985 are the same codebase.
 Frech> XF:matts-whois-meta
 Christey> ADDREF BID:2000
 Christey> XF reference is gone.  Replace with http-cgi-matts-whois-meta(3799) ?


CAN-1999-0985

Phase: Proposed (19991214)
Reference: BUGTRAQ:19991109 Whois.cgi - ADVISORY.

Description:
CC Whois program whois.cgi allows remote attackers to execute commands via shell metacharacters in the domain entry.

Votes:

   ACCEPT(2) Stracener, Blake
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(1) Christey
Voter Comments:
 Cole> I would combine all of these.
 Christey> More examination is required to determine if CAN-1999-0983,
   CAN-1999-0984, or CAN-1999-0985 are the same codebase.
 Frech> XF:cc-whois-meta
 Christey> ADDREF BID:2000
 Frech> Change cc-whois-meta(3800) to http-cgi-ccwhois(3747)
 Christey> Replace XF reference with XF:cc-whois-meta(3800) ?


CAN-1999-0988

Phase: Modified (20000121-01)
Reference: BUGTRAQ:19991204 UnixWare pkg* command exploits
Reference: BUGTRAQ:19991215 Recent postings about SCO UnixWare 7
Reference: BUGTRAQ:19991223 FYI, SCO Security patches available.
Reference: BUGTRAQ:19991220 SCO OpenServer Security Status

Description:
UnixWare pkgtrans allows local users to read arbitrary files via a symlink attack.

Votes:

   ACCEPT(2) Blake, Cole
   MODIFY(1) Frech
   RECAST(1) Stracener
   REVIEWING(1) Christey
Voter Comments:
 Stracener> The pkg* programs pkgtrans, pkginfo, pkgcat, pkginstall, and pkgparam
   can be used to mount etc/shadow printing attacks as a result of the
   "dacread" permission (cf. /etc/security/tcb/privs). The procedural
   differences between the individual exploits for each of these utilities
   are therefore inconsequential. CAN-1999-0988 should be merged with
   CAN-1999-0828. From the standpoint of maintaining consistency of the
   level of abstraction used in CVE, the co-existence of CANS
   1999-0988/1999-0828 present two choices: either merge 0988 with 0828, or
   split 0828 into 4 distinct candidates, keeping 0988 intact. Due to the
   very small differences (in principle) between the exploits subsumed by
   0828 and 0988 and the shared dacread permissions of the pkg* suite, I
   suggest a merge. Below is a summary of the data upon which my decision
   was based.
   utility         exploit
   --------      ---------------------------------- 
   pkgtrans  --> symlink + dacread permission prob
   pkginfo   --> truss (debugging utility) in conjunction with pkginfio -d
   etc/shadow. In this case, it captures the interaction between
   pkginfo                the shadow file. Once again: dacread.
   pkgcat    --> buffer overflow  + dacread permission prob
   pkginstall -> buffer overflow + dacread permission prob
   pkgparam --> -f etc/shadow (works because of dacread).
 Christey> This is a tough one.  While there are few procedural
   differences, one could view "assignment of an improper
   permission" as a "class" of problems along the lines of
   buffer overflows and the like.  Just like some programs
   were fine until they got turned into CGI scripts, this
   could be an emerging pattern which should be given
   consideration.  Consider the Eyedog and scriptlet.typelib
   ActiveX utilities being marked as safe for scripting
   (CAN-1999-0668 and 0669).
   
   ftp://ftp.sco.com/SSE/security_bulletins/SB-99.28a loosely
   alludes to this problem; the README for patch SSE053
   effectively confirms it.
 Frech> XF:unixware-pkgtrans-symlink


CAN-1999-0990

Phase: Interim (19991229)
Reference: BUGTRAQ:19991205 gdm thing

Description:
Error messages generated by gdm with the VerboseAuth setting allows an attacker to identify valid users on a system.

Votes:

   ACCEPT(3) Stracener, Blake, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:verbose-auth-identify-user(3804)


CAN-1999-0993

Phase: Proposed (19991222)
Reference: NTBUGTRAQ:19991213 Changing ACL's in Exchange Server

Description:
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.

Votes:

   ACCEPT(2) Stracener, Wall
   MODIFY(1) Frech
   NOOP(1) Cole
   REJECT(1) LeBlanc
Voter Comments:
 Frech> XF:exchange-acl-changes(3916)
 LeBlanc> Not a vulnerability


CAN-1999-1002

Phase: Modified (20030619-01)
Reference: MISC:http://www.rstcorp.com/news/bad-crypto.html
Reference: BUGTRAQ:19991216 Reinventing the wheel (aka "Decoding Netscape Mail passwords")
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94536309217214&w=2
Reference: BUGTRAQ:19991220 Netscape password scrambling
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94570673523998&w=2

Description:
Netscape Navigator uses weak encryption for storing a user's Netscape mail password.

Votes:

   ACCEPT(4) Baker, Wall, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:netscape-mail-encryption(3921)
 Christey> CHANGEREF make the RCA URL a "MISC" reference


CAN-1999-1003

Phase: Proposed (19991222)
Reference: BUGTRAQ:19991214 Local / Remote D.o.S Attack in War FTP Daemon 1.70 Vulnerability
Reference: BUGTRAQ:19991216 Statement: Local / Remote D.o.S Attack in War FTP Daemon 1.70

Description:
War FTP Daemon 1.70 allows remote attackers to cause a denial of service by flooding it with connections.

Votes:

   ACCEPT(3) Baker, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:warftp-connection-flood


CAN-1999-1006

Phase: Proposed (19991222)
Reference: BUGTRAQ:19991219 Groupewise Web Interface
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94571433731824&w=2

Description:
Groupwise web server GWWEB.EXE allows remote attackers to determine the real path of the web server via the HELP parameter.

Votes:

   ACCEPT(4) Prosser, Baker, Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:groupwise-web-path
 Prosser> Pretty well confirmed by testing with responses to BugTraq list.
   
   additional ref:  BugTraq ID 879  http://www.securityfocus.com/bid/879
 Christey> A later discovery almost 2 years later is at:
   BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell
   GroupWise Web Access Path Disclosure Vulnerability
   http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2
   CD:SF-LOC might suggest merging these together.


CAN-1999-1009

Phase: Proposed (19991222)
Reference: BUGTRAQ:19991213 Privacy hole in Go Express Search

Description:
The Disney Go Express Search allows remote attackers to access and modify search information for users by connecting to an HTTP server on the user's system.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Balinsky, Wall, Cole, Stracener
Voter Comments:
 Frech> XF:disney-search-info(3955)
 Balinsky> The go.express.com web site does not mention the existence of the Express web server mentioned in the advisory. There appears to be no way of verifying this.


CAN-1999-1012

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990504 AS/400
Reference: URL:http://www.securityfocus.com/archive/1/13527
Reference: BID:173
Reference: URL:http://www.securityfocus.com/bid/173

Description:
SMTP component of Lotus Domino 4.6.1 on AS/400, and possibly other operating systems, allows a remote attacker to crash the mail server via a long string.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> (Task 1770)
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:lotus-domino-smtp-dos(8790)


CAN-1999-1013

Phase: Proposed (20010912)
Reference: BID:673
Reference: URL:http://www.securityfocus.com/bid/673
Reference: BUGTRAQ:19990923 named-xfer hole on AIX (fwd)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93837026726954&w=2

Description:
named-xfer in AIX 4.1.5 and 4.2.1 allows members of the system group to overwrite system files to gain root access via the -f parameter and a malformed zone file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:aix-named-xfer-root-access(3308)


CAN-1999-1015

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980408 AppleShare IP Mail Server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=89200657216213&w=2
Reference: BID:61
Reference: URL:http://www.securityfocus.com/bid/61

Description:
Buffer overflow in Apple AppleShare Mail Server 5.0.3 on MacOS 8.1 and earlier allows a remote attacker to cause a denial of service (crash) via a long HELO command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:smtp-helo-bo(886)


CAN-1999-1016

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990827 HTML code to crash IE5 and Outlook Express 5
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93578772920970&w=2
Reference: BID:606
Reference: URL:http://www.securityfocus.com/bid/606

Description:
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or HTML emails to cause a denial of service (100% CPU consumption) via large HTML form fields such as text inputs in a table cell

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
Voter Comments:
 Frech> XF:ms-html-table-form-dos(3246)
 Frech> XF:ms-html-table-form-dos(3246)
 Christey> Add period to the end of the description.


CAN-1999-1017

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990728 Seattle Labs EMURL Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93316253431588&w=2
Reference: BID:544
Reference: URL:http://www.securityfocus.com/bid/544

Description:
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> (Task 2281)
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:emurl-attachment-execution(8794)


CAN-1999-1018

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990727 Linux 2.2.10 ipchains Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93312523904591&w=2
Reference: BID:543
Reference: URL:http://www.securityfocus.com/bid/543

Description:
IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:linux-ipchains-bypass-filter(6516)
 Frech> XF:linux-ipchains-bypass-filter(6516)


CAN-1999-1020

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980918 NMRC Advisory - Default NDS Rights
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90613355902262&w=2
Reference: BID:484
Reference: URL:http://www.securityfocus.com/bid/484
Reference: XF:novell-nds(1364)
Reference: URL:http://xforce.iss.net/static/1364.php

Description:
The installation of Novell Netware NDS 5.99 provides an unauthenticated client with Read access for the tree, which allows remote attackers to access sensitive information such as users, groups, and readable objects via CX.EXE and NLIST.EXE.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1022

Phase: Proposed (20010912)
Reference: BUGTRAQ:19941002
Reference: URL:http://www.securityfocus.com/archive/1/930
Reference: XF:sgi-serialports(2111)
Reference: URL:http://xforce.iss.net/static/2111.php
Reference: BID:464
Reference: URL:http://www.securityfocus.com/bid/464

Description:
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Foat, Christey
Voter Comments:
 Christey> Note: CAN-1999-1310 is a duplicate of this candidate.
   CAN-1999-1310 will be REJECTed; this is the proper CAN to use.
   
   CIAC:F-01
   URL:http://ciac.llnl.gov/ciac/bulletins/f-01.shtml
   SGI:19941001-01-P
   URL:ftp://patches.sgi.com/support/free/security/advisories/19941001-01-P
   MISC:http://www.netsys.com/firewalls/firewalls-9410/0019.html


CAN-1999-1023

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990610 Sun Useradd program expiration date bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92904175406756&w=2
Reference: BID:426
Reference: URL:http://www.securityfocus.com/bid/426

Description:
useradd in Solaris 7.0 does not properly interpret certain date formats as specified in the "-e" (expiration date) argument, which could allow users to login after their accounts have expired.

Votes:

   ACCEPT(1) Dik
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Dik> sun bug: 4222400
 Frech> XF:solaris-useradd-expired-accounts(8375)
   CONFIRM:(2.6)110883-01, (2.6_x86) 110884-01, (7)110869-01,
   (7_x86) 110870-01


CAN-1999-1024

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990616 tcpdump 3.4 bug?
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92955903802773&w=2
Reference: BUGTRAQ:19990617 Re: tcpdump 3.4 bug?
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92963447601748&w=2
Reference: BUGTRAQ:19990620 Re: tcpdump 3.4 bug? (final)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92989907627051&w=2
Reference: BID:313
Reference: URL:http://www.securityfocus.com/bid/313

Description:
ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length header, which causes an infinite loop and core dump when tcpdump prints the packet.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:tcpdump-ipprint-dos(8373)


CAN-1999-1025

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981012 Annoying Solaris/CDE/NIS+ bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90831127921062&w=2
Reference: SUNBUG:4115685
Reference: URL:http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F106027&zone_32=411568%2A%20
Reference: BID:294
Reference: URL:http://www.securityfocus.com/bid/294

Description:
CDE screen lock program (screenlock) on Solaris 2.6 does not properly lock an unprivileged user's console session when the host is an NIS+ client, which allows others with physical access to login with any string.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solaris-cde-nisplus-lock(7473)
 Dik> sun bug: 4115685


CAN-1999-1026

Phase: Proposed (20010912)
Reference: BUGTRAQ:19961220 Solaris 2.5 x86 aspppd (semi-exploitable-hole)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420343&w=2
Reference: BID:292
Reference: URL:http://www.securityfocus.com/bid/292

Description:
aspppd on Solaris 2.5 x86 allows local users to modify arbitrary files and gain root privileges via a symlink attack on the /tmp/.asppp.fifo file.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:sun-aspppd-tmp-symlink(7173)


CAN-1999-1029

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990513 - J.J.F. / Hackers Team warns for SSHD 2.x brute force password hacking
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92663402004280&w=2
Reference: BID:277
Reference: URL:http://www.securityfocus.com/bid/277
Reference: XF:ssh2-bruteforce(2193)
Reference: URL:http://xforce.iss.net/static/2193.php

Description:
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1030

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990519 Denial of Service in Counter.exe version 2.70
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92713790426690&w=2
Reference: NTBUGTRAQ:19990519 Denial of Service in Counter.exe version 2.70
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92707671717292&w=2
Reference: BID:267
Reference: URL:http://www.securityfocus.com/bid/267

Description:
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via an HTTP request that ends in %0A (newline), which causes a malformed entry in the counter log that produces an access violation.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:http-cgi-counter-long(2196)
 Frech> XF:http-cgi-counter-long(2196)


CAN-1999-1031

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990519 Denial of Service in Counter.exe version 2.70
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92713790426690&w=2
Reference: NTBUGTRAQ:19990519 Denial of Service in Counter.exe version 2.70
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92707671717292&w=2
Reference: BID:267
Reference: URL:http://www.securityfocus.com/bid/267

Description:
counter.exe 2.70 allows a remote attacker to cause a denial of service (hang) via a long argument.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:http-cgi-counter-long(2196)
 Frech> XF:http-cgi-counter-long(2196)


CAN-1999-1033

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990511 Outlook Express Win98 bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92647407427342&w=2
Reference: BUGTRAQ:19990512 Outlook Express Win98 bug, addition.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92663402004275&w=2
Reference: BID:252
Reference: URL:http://www.securityfocus.com/bid/252

Description:
Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause Outlook to re-enter POP3 command mode and cause the POP3 session to hang.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> (Task 2241)
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:outlook-pop3-dot-dos(8926)


CAN-1999-1036

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980626 vulnerability in satan, cops & tiger
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125976&w=2

Description:
COPS 1.04 allows local users to overwrite or create arbitrary files via a symlink attack on temporary files in (1) res_diff, (2) ca.src, and (3) mail.chk.

Votes:

   ACCEPT(1) Foat
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:cops-temp-file-symlink(7325)


CAN-1999-1038

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980626 vulnerability in satan, cops & tiger
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125976&w=2

Description:
Tiger 2.2.3 allows local users to overwrite arbitrary files via a symlink attack on various temporary files in Tiger's default working directory, as defined by the WORKDIR variable.

Votes:

   ACCEPT(1) Foat
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:tiger-workdir-symlink(7326)


CAN-1999-1039

Phase: Proposed (20010912)
Reference: SGI:19980502-01-P3030
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030

Description:
Vulnerability in (1) diskalign and (2) diskperf in IRIX 6.4 patches 2291 and 2848 allow a local user to create root-owned files leading to a root compromise.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   REJECT(1) Frech

CAN-1999-1040

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980408 SGI O2 ipx security issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=89217373930054&w=2
Reference: SGI:19980501-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19980501-01-P2869
Reference: CIAC:I-055
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/i-055.shtml

Description:
Vulnerabilities in (1) ipxchk and (2) ipxlink in NetWare Client 1.0 on IRIX 6.3 and 6.4 allows local users to gain root access via a modified IFS environmental variable.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   NOOP(1) Christey
   REJECT(1) Frech
Voter Comments:
 Christey> This candidate and CAN-1999-1501 are duplicates.  However,
   CAN-1999-1501 will be REJECTed in favor of this candidate.
   Add the following references:
   BID:70
   URL:http://www.securityfocus.com/bid/70
   BID:71
   URL:http://www.securityfocus.com/bid/71
   XF:irix-ipxchk-ipxlink-ifs-commands(7365)
   URL:http://xforce.iss.net/static/7365.php


CAN-1999-1041

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980827 SCO mscreen vul.
Reference: URL:http://www.securityfocus.com/archive/1/10420
Reference: BUGTRAQ:19980926 Root exploit for SCO OpenServer.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90686250717719&w=2
Reference: SCO:SB-98.05a
Reference: URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-98.05a
Reference: CERT:VB-98.10
Reference: URL:http://www.cert.org/vendor_bulletins/VB-98.10.sco.mscreen

Description:
Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a long TERM environmental variable and (2) a long entry in the .mscreenrc file.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:sco-openserver-mscreen-bo(1379)
 Christey> Possible dupe with CAN-1999-1185.


CAN-1999-1042

Phase: Proposed (20010912)
Reference: CISCO:19980813 CRM Temporary File Vulnerability
Reference: URL:http://www.cisco.com/warp/public/770/crmtmp-pub.shtml

Description:
Cisco Resource Manager (CRM) 1.0 and 1.1 creates world-readable log files and temporary files, which may expose sensitive information, to local users such as user IDs, passwords and SNMP community strings.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
   REJECT(3) Balinsky, Armstrong, Christey
Voter Comments:
 Frech> XF:cisco-crm-file-vuln(1575)
 Armstrong> I think that this is the same as Can-1999-1126
 Balinsky> This is the same as CAN-1999-1126. Merge them.
 Christey> DUPE CAN-1999-1126, as noted by others.
   This candidate will be rejected.  CAN-1999-1126 will be
   promoted.


CAN-1999-1043

Phase: Proposed (20010912)
Reference: MS:MS98-007
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms98-007.asp

Description:
Microsoft Exchange Server 5.5 and 5.0 does not properly handle (1) malformed NNTP data, or (2) malformed SMTP data, which allows remote attackers to cause a denial of service (application error).

Votes:

   ACCEPT(3) Wall, Foat, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:exchange-dos(1223)


CAN-1999-1046

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990302 Multiple IMail Vulnerabilites
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92038879607336&w=2
Reference: BID:504
Reference: URL:http://www.securityfocus.com/bid/504
Reference: XF:imail-imonitor-overflow(1897)
Reference: URL:http://xforce.iss.net/static/1897.php

Description:
Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1049

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990222 Severe Security Hole in ARCserve NT agents (fwd)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91972006211238&w=2

Description:
ARCserve NT agents use weak encryption (XOR) for passwords, which allows remote attackers to sniff the authentication request to port 6050 and decrypt the password.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:arcserve-agent-passwords(1822)


CAN-1999-1050

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991112 FormHandler.cgi
Reference: URL:http://www.securityfocus.com/archive/1/34600
Reference: BUGTRAQ:19991116 Re: FormHandler.cgi
Reference: URL:http://www.securityfocus.com/archive/1/34939
Reference: BID:798
Reference: URL:http://www.securityfocus.com/bid/798
Reference: BID:799
Reference: URL:http://www.securityfocus.com/bid/799
Reference: XF:formhandler-cgi-absolute-path(3550)
Reference: URL:http://xforce.iss.net/static/3550.php

Description:
Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachment parameter, or (2) by specifying the filename as a template.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> Abstraction and definition issue: CD:SF-LOC suggests combining
   issues of the same type.  Some people refer to "directory
   traversal" and just mean .. problems; but there are other
   issues (specifying an absolute pathname, using C: drive
   letters, doing encodings) that, to my way of thinking, are
   "different."  Perhaps this should be split.
   
   My brain hurts too much right now.  There are a couple
   problems with the references and descriptions of CAN-1999-1050
   and CAN-1999-1051.  I'm interpreting the underlying nature
   of the problem(s) a little differently than others are.
   Some of it may be due to differing definitions or thoughts
   about what "directory traversal vulnerabilities" are.


CAN-1999-1051

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991116 Re: FormHandler.cgi
Reference: URL:http://www.securityfocus.com/archive/1/34939

Description:
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:formhandler-cgi-reply-message(7782)
 Christey> I view one of these as a configuration issue: FormHandler.cgi
   *could* be configured to limit hard-coded pathnames to a single
   directory which, while being an information leak, would still be
   "reasonably secure."  But by default, it's just not configured that
   way.
   
   My brain hurts too much right now.  There are a couple
   problems with the references and descriptions of CAN-1999-1050
   and CAN-1999-1051.  I'm interpreting the underlying nature
   of the problem(s) a little differently than others are.
   Some of it may be due to differing definitions or thoughts
   about what "directory traversal vulnerabilities" are.


CAN-1999-1052

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990824 Front Page form_results
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93582550911564&w=2

Description:
Microsoft FrontPage stores form results in a default location in /_private/form_results.txt, which is world-readable and accessible in the document root, which allows remote attackers to read possibly sensitive information submitted by other users.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:frontpage-formresults-world-readable(8362)


CAN-1999-1053

Phase: Proposed (20010912)
Reference: VULN-DEV:19990913 Guestbook perl script (long)
Reference: URL:http://www.securityfocus.com/archive/82/27296
Reference: VULN-DEV:19990916 Re: Guestbook perl script (error fix)
Reference: URL:http://www.securityfocus.com/archive/82/27560
Reference: BUGTRAQ:19991105 Guestbook.pl, sloppy SSI handling in Apache? (VD#2)
Reference: URL:http://www.securityfocus.com/archive/1/33674
Reference: BID:776
Reference: URL:http://www.securityfocus.com/bid/776

Description:
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl is run on Apache 1.3.9 and possibly other versions, since Apache allows other closing sequences besides "-->".

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:guestbook-cgi-command-execution(7783)


CAN-1999-1054

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980925 Globetrotter FlexLM 'lmdown' bogosity
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90675672323825&w=2

Description:
The default configuration of FLEXlm license manager 6.0d, and possibly other versions, allows remote attackers to shut down the server via the lmdown command.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Foat

CAN-1999-1056

Phase: Proposed (20010912)
Reference: CERT:CA-1992-18
Reference: URL:http://www.cert.org/advisories/CA-1992-18.html

Description:
Vulnerability in VMS 5.0 through 5.4-2 allows local users to gain privileges via the Monitor utility.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
   REJECT(1) Christey
Voter Comments:
 Frech> XF:vms-monitor-gain-privileges(7136)
 Christey> DUPE CAN-1999-1395
   This CAN is being rejected in favor of CAN-1999-1395 because
   CAN-1999-1395 has more references.


CAN-1999-1058

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94337185023159&w=2
Reference: BUGTRAQ:19991122 Remote DoS Attack in Vermillion FTP Daemon (VFTPD) v1.23 Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94329968617085&w=2
Reference: XF:vermillion-ftp-cwd-overflow(3543)
Reference: URL:http://xforce.iss.net/static/3543.php
Reference: BID:818
Reference: URL:http://www.securityfocus.com/bid/818

Description:
Buffer overflow in Vermillion FTP Daemon VFTPD 1.23 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via several long CWD commands.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1060

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990217 Tetrix 1.13.16 is Vulnerable
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91937090211855&w=2
Reference: BID:340
Reference: URL:http://www.securityfocus.com/bid/340

Description:
Buffer overflow in Tetrix TetriNet daemon 1.13.16 allows remote attackers to cause a denial of service and possibly execute arbitrary commands by connecting to port 31457 from a host with a long DNS hostname.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:tetrinet-dns-hostname-bo(7500)


CAN-1999-1061

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971004 HP Laserjet 4M Plus DirectJet Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602248518480&w=2
Reference: XF:laserjet-unpassworded(1876)
Reference: URL:http://xforce.iss.net/static/1876.php

Description:
HP Laserjet printers with JetDirect cards, when configured with TCP/IP, can be configured without a password, which allows remote attackers to connect to the printer and change its IP address or disable logging.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(1) Foat
Voter Comments:
 Frech> CONFIRM:http://www.hp.com/cposupport/printers/support_doc/bpl
   02914.html


CAN-1999-1062

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971004 HP Laserjet 4M Plus DirectJet Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602248518480&w=2
Reference: XF:laserjet-unpassworded(1876)
Reference: URL:http://xforce.iss.net/static/1876.php

Description:
HP Laserjet printers with JetDirect cards, when configured with TCP/IP, allow remote attackers to bypass print filters by directly sending PostScript documents to TCP ports 9099 and 9100.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> DELREF:XF:laserjet-unpassworded(1876)
   ADDREF:XF:hp-printer-flood(1818)


CAN-1999-1063

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990601 whois_raw.cgi problem
Reference: URL:http://www.securityfocus.com/archive/1/14019
Reference: BID:304
Reference: URL:http://www.securityfocus.com/bid/304
Reference: XF:http-cgi-cdomain(2251)
Reference: URL:http://xforce.iss.net/static/2251.php

Description:
CDomain whois_raw.cgi whois CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the fqdn parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1064

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990822
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93555317429630&w=2
Reference: BUGTRAQ:19990824 Re: WindowMaker bugs (was sub:none )
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93582070508957&w=2
Reference: BID:596
Reference: URL:http://www.securityfocus.com/bid/596

Description:
Multiple buffer overflows in WindowMaker 0.52 through 0.60.0 allow attackers to cause a denial of service and possibly execute arbitrary commands by executing WindowMaker with a long program name (argv[0]).

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:windowmaker-bo(3249)
 Frech> XF:windowmaker-bo(3249)


CAN-1999-1065

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991104 Palm Hotsync vulnerable to DoS attack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94175465525422&w=2

Description:
Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:palm-hotsync-bo(7785)


CAN-1999-1066

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991222 Quake "smurf" - Quake War Utils
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94589559631535&w=2

Description:
Quake 1 server responds to an initial UDP game connection request with a large amount of traffic, which allows remote attackers to use the server as an amplifier in a "Smurf" style attack on another host, by spoofing the connection request.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Christey
Voter Comments:
 Christey> This is apparently a problem with the connection protocol.
   See BUGTRAQ:19980522 NetQuake Protocol problem resulting in smurf like effect.
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925989&w=2
 Frech> XF:quake-udp-connection-dos(7862)


CAN-1999-1067

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970507 Re: SGI Security Advisory 19970501-01-A - Vulnerability in webdist.cgi
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420919&w=2
Reference: XF:sgi-machineinfo

Description:
SGI MachineInfo CGI program, installed by default on some web servers, prints potentially sensitive system status information, which could be used by remote attackers for information gathering activities.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> I'd be a lot more confident in this vote if there was a more
   concrete reference strongly associating webdist.cgi and machineinfo.


CAN-1999-1068

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970723 DoS against Oracle Webserver 2.1 with PL/SQL stored procedures
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602661419366&w=2

Description:
Oracle Webserver 2.1, when serving PL/SQL stored procedures, allows remote attackers to cause a denial of service via a long HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:oracle-webserver-dos(1812)


CAN-1999-1069

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971108 Security bug in iCat Suite version 3.0
Reference: URL:http://www.securityfocus.com/archive/1/7943
Reference: BID:2126
Reference: URL:http://www.securityfocus.com/bid/2126
Reference: XF:icat-carbo-server-vuln(1620)
Reference: URL:http://xforce.iss.net/static/1620.php

Description:
Directory traversal vulnerability in carbo.dll in iCat Carbo Server 3.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the icatcommand parameter.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(1) Foat
Voter Comments:
 Frech> iCat's site at http://www.icat.com/ is shut down, and no
   further support seems to be available.


CAN-1999-1070

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980725 Annex DoS
Reference: URL:http://www.securityfocus.com/archive/1/10021

Description:
Buffer overflow in ping CGI program in Xylogics Annex terminal service allows remote attackers to cause a denial of service via a long query parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:annex-ping-crash(2090)


CAN-1999-1071

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981130 Security bugs in Excite for Web Servers 1.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91248445931140&w=2
Reference: XF:excite-world-write(1417)
Reference: URL:http://xforce.iss.net/static/1417.php

Description:
Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1072

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981130 Security bugs in Excite for Web Servers 1.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91248445931140&w=2

Description:
Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1073

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981130 Security bugs in Excite for Web Servers 1.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91248445931140&w=2

Description:
Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1075

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980318 AIX 4.1.5 DoS attack (aka "Port 1025 problem")
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=89025820612530&w=2

Description:
inetd in AIX 4.1.5 dynamically assigns a port N when starting ttdbserver (ToolTalk server), but also inadvertently listens on port N-1 without passing control to ttdbserver, which allows remote attackers to cause a denial of service via a large number of connections to port N-1, which are not properly closed by inetd.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:aix-ttdbserver(813)
   CONFIRM:APAR IX70400


CAN-1999-1076

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991026 Mac OS 9 Idle Lock Bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94096348604173&w=2
Reference: BID:745
Reference: URL:http://www.securityfocus.com/bid/745

Description:
Idle locking function in MacOS 9 allows local users to bypass the password protection of idled sessions by selecting the "Log Out" option and selecting a "Cancel" option in the dialog box for an application that attempts to verify that the user wants to log out, which returns the attacker into the locked session.

Votes:

   ACCEPT(2) Foat, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:macos-idle-screenlock-bypass(7794)


CAN-1999-1077

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991101 Re: Mac OS 9 Idle Lock Bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94149318124548&w=2
Reference: BID:756
Reference: URL:http://www.securityfocus.com/bid/756

Description:
Idle locking function in MacOS 9 allows local attackers to bypass the password protection of idled sessions via the programmer's switch or CMD-PWR keyboard sequence, which brings up a debugger that the attacker can use to disable the lock.

Votes:

   ACCEPT(2) Foat, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:macos-debug-screenlock-access(3426)


CAN-1999-1078

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990729 WS_FTP Pro 6.0 Weak Password Encryption Vulnerability
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9907&L=ntbugtraq&D=0&P=10370&F=P
Reference: BID:547
Reference: URL:http://www.securityfocus.com/bid/547

Description:
WS_FTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:wsftp-weak-password-encryption(8349)


CAN-1999-1079

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990506 AIX Security Fixes Update
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92601792420088&w=2
Reference: BUGTRAQ:19990825 AIX security summary
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93587956513233&w=2
Reference: AIXAPAR:IX80470
Reference: URL:http://www-1.ibm.com/servlet/support/manager?rs=0&rt=0&org=apars&doc=08E0B1A1B85472A1852567C90031BB36
Reference: BID:439
Reference: URL:http://www.securityfocus.com/bid/439

Description:
Vulnerability in ptrace in AIX 4.3 allows local users to gain privileges by attaching to a setgid program.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:aix-ptrace-setgid(7487)


CAN-1999-1081

Phase: Proposed (20010912)
Reference: MISC:http://www.w3.org/Security/Faq/wwwsf8.html#Q87
Reference: MISC:http://www.roxanne.org/faqs/www-secure/wwwsf4.html#Q35
Reference: XF:http-nov-files(2054)
Reference: URL:http://xforce.iss.net/static/2054.php

Description:
Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(1) Foat

CAN-1999-1082

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991008 Jana webserver exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93941794201059&w=2
Reference: BID:699
Reference: URL:http://www.securityfocus.com/bid/699

Description:
Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:jana-server-directory-traversal(6513)


CAN-1999-1083

Phase: Proposed (20010912)
Reference: BUGTRAQ:20000502 Security Bug in Jana HTTP Server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95730430727064&w=2
Reference: BID:699
Reference: URL:http://www.securityfocus.com/bid/699

Description:
Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:jana-server-directory-traversal(6513)


CAN-1999-1084

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19980622 Yet another "get yourself admin rights exploit":
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=90222453431604&w=2
Reference: MSKB:Q103861
Reference: URL:http://support.microsoft.com/support/kb/articles/q103/8/61.asp
Reference: MS:MS00-008
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-008.asp
Reference: CIAC:K-029
Reference: URL:http://www.ciac.org/ciac/bulletins/k-029.shtml
Reference: BID:1044
Reference: URL:http://www.securityfocus.com/bid/1044

Description:
The "AEDebug" registry key is installed with insecure permissions, which allows local users to modify the key to specify a Trojan Horse debugger which is automatically executed on a system crash.

Votes:

   ACCEPT(3) Wall, Foat, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:nt-registry-permissions(4111)


CAN-1999-1086

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990715 NMRC Advisory: Netware 5 Client Hijacking
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93214475111651&w=2
Reference: BID:528
Reference: URL:http://www.securityfocus.com/bid/528

Description:
Novell 5 and earlier, when running over IPX with a packet signature level less than 3, allows remote attackers to gain administrator privileges by spoofing the MAC address in IPC fragmented packets that make NetWare Core Protocol (NCP) calls.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:netware-ipx-session-spoof(2350)


CAN-1999-1088

Phase: Proposed (20010912)
Reference: HP:HPSBUX9701-050
Reference: CIAC:H-21
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-21.shtml
Reference: XF:hp-chsh(2012)
Reference: URL:http://xforce.iss.net/static/2012.php

Description:
Vulnerability in chsh command in HP-UX 9.X through 10.20 allows local users to gain privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1089

Phase: Proposed (20010912)
Reference: BUGTRAQ:19961209 the HP Bug of the Week!
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420285&w=2
Reference: HP:HPSBUX9701-049
Reference: CIAC:H-21
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-21.shtml
Reference: CIAC:H-16
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-16.shtml
Reference: AUSCERT:AA-96.18
Reference: XF:hp-chfn(2008)

Description:
Buffer overflow in chfn command in HP-UX 9.X through 10.20 allows local users to gain privileges via a long command line argument.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1091

Phase: Proposed (20010912)
Reference: BUGTRAQ:19960903 [BUG] Vulnerability in TIN
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419835&w=2
Reference: BUGTRAQ:19960903 Re: BoS: [BUG] Vulnerability in TIN
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419839&w=2
Reference: BUGTRAQ:19970329 symlink bug in tin/rtin
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420726&w=2
Reference: XF:tin-tmpfile(431)
Reference: URL:http://xforce.iss.net/static/431.php

Description:
UNIX news readers tin and rtin create the /tmp/.tin_log file with insecure permissions and follow symlinks, which allows attackers to modify the permissions of files writable by the user via a symlink attack.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1092

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991117 default permissions for tin
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94286179032648&w=2

Description:
tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:tin-insecure-permissions(7796)
   Confirmed in changelog for 1.4.1
   http://ftp.kreonet.re.kr/pub/tools/news/tin/v1.4/CHANGES


CAN-1999-1095

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971006 KSR[T] Advisory #3: updatedb / crontabs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87619953510834&w=2
Reference: BUGTRAQ:19980303 updatedb stuff
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88890116304676&w=2
Reference: BUGTRAQ:19980303 updatedb: sort patch
Reference: BUGTRAQ:19980302 overwrite any file with updatedb
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88886870129518&w=2

Description:
sort creates temporary files and follows symbolic links, which allows local users to modify arbitrary files that are writable by the user running sort, as observed in updatedb and other programs that use sort.

Votes:

   MODIFY(1) Frech
   NOOP(3) Foat, Cole, Christey
Voter Comments:
 Frech> XF:sort-tmp-file-symlink(7182)
 Christey> This issue clearly has a long history.
   CALDERA:CSSA-2002-SCO.21
   URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0018.html
   CALDERA:CSSA-2002-SCO.2
   URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q1/0002.html
   (There are 2 Caldera advisories because one is for Open UNIX
   and UnixWare, and the other is for OpenServer)
   
   XF:openserver-sort-symlink(9218)
   URL:http://www.iss.net/security_center/static/9218.php


CAN-1999-1096

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980516 kde exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925954&w=2
Reference: BUGTRAQ:19980517 simple kde exploit fix
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925959&w=2
Reference: XF:kde-klock-home-bo(1644)
Reference: URL:http://xforce.iss.net/static/1644.php

Description:
Buffer overflow in kscreensaver in KDE klock allows local users to gain root privileges via a long HOME environmental variable.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1097

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990504 Microsoft Netmeeting Hole
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92586457816446&w=2
Reference: XF:netmeeting-clipboard(2187)
Reference: URL:http://xforce.iss.net/static/2187.php

Description:
Microsoft NetMeeting 2.1 allows one client to read the contents of another client's clipboard via a CTRL-C in the chat box when the box is empty.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1101

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990219 Yet Another password storing problem (was: Re: Possible Netscape Crypto Security Flaw)
Reference: URL:http://www.securityfocus.com/archive/1/12618

Description:
Kabsoftware Lydia utility uses weak encryption to store user passwords in the lydia.ini file, which allows local users to easily decrypt the passwords and gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:lydia-ini-passwords(7501)
   ADDREF:http://www.kabsoftware.com/lydia_history.txt (Version
   History for Lydia, V3.3 - 11/24/00)


CAN-1999-1106

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980429 Security hole in kppp
Reference: URL:http://www.securityfocus.com/archive/1/9121
Reference: XF:kde-kppp-account-bo(1643)
Reference: URL:http://xforce.iss.net/static/1643.php
Reference: BID:92
Reference: URL:http://www.securityfocus.com/bid/92

Description:
Buffer overflow in kppp in KDE allows local users to gain root access via a long -c (account_name) command line argument.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1107

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981118 Multiple KDE security vulnerabilities (root compromise)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91141486301691&w=2
Reference: XF:kde-kppp-path-bo(1650)
Reference: URL:http://xforce.iss.net/static/1650.php

Description:
Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1108

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981118 Multiple KDE security vulnerabilities (root compromise)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91141486301691&w=2
Reference: XF:kde-kppp-path-bo(1650)
Reference: URL:http://xforce.iss.net/static/1650.php

Description:
Buffer overflow in kppp in KDE allows local users to gain root access via a long PATH environmental variable.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Foat
   REJECT(1) Frech
Voter Comments:
 Frech> Has exactly the same attributes as CAN-1999-1107.


CAN-1999-1110

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991114 IE 5.0 and Windows Media Player ActiveX object allow checking the existence of local files and directories
Reference: URL:http://www.securityfocus.com/archive/1/34675
Reference: BID:793
Reference: URL:http://www.securityfocus.com/bid/793

Description:
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:ie-mediaplayer-activex(7800)


CAN-1999-1112

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991109 Irfan view 3.07 buffer overflow
Reference: URL:http://www.securityfocus.com/archive/1/34066
Reference: MISC:http://stud4.tuwien.ac.at/~e9227474/main2.html
Reference: XF:irfan-view32-bo(3549)
Reference: URL:http://xforce.iss.net/static/3549.php
Reference: BID:781
Reference: URL:http://www.securityfocus.com/bid/781

Description:
Buffer overflow in IrfanView32 3.07 and earlier allows attackers to execute arbitrary commands via a long string after the "8BPS" image type in a Photo Shop image header.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1113

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980414 MacOS based buffer overflows...
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=89258194718577&w=2
Reference: BID:75
Reference: URL:http://www.securityfocus.com/bid/75

Description:
Buffer overflow in Eudora Internet Mail Server (EIMS) 2.01 and earlier on MacOS systems allows remote attackers to cause a denial of service via a long USER command to port 106.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:eudora-ims-user-dos(7300) 


CAN-1999-1123

Phase: Proposed (20010912)
Reference: CERT:CA-1991-07
Reference: URL:http://www.cert.org/advisories/CA-1991-07.html
Reference: SUN:00107
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/107&type=0&nav=sec.sba
Reference: BID:21
Reference: URL:http://www.securityfocus.com/bid/21
Reference: BID:22
Reference: URL:http://www.securityfocus.com/bid/22
Reference: XF:sun-sourcetapes(582)
Reference: URL:http://xforce.iss.net/static/582.php

Description:
The installation of Sun Source (sunsrc) tapes allows local users to gain root privileges via setuid root programs (1) makeinstall or (2) winstall.

Votes:

   ACCEPT(5) Frech, Foat, Cole, Dik, Stracener
   NOOP(1) Wall
Voter Comments:
 Dik> sun bug: 1059621


CAN-1999-1124

Phase: Proposed (20010912)
Reference: MISC:http://packetstorm.securify.com/mag/phrack/phrack54/P54-08

Description:
HTTP Client application in ColdFusion allows remote attackers to bypass access restrictions for web pages on other ports by providing the target page to the mainframeset.cfm application, which requests the page from the server, making it look like the request is coming from the local host.

Votes:

   ACCEPT(2) Wall, Cole
   NOOP(1) Foat

CAN-1999-1125

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970919 Instresting practises of Oracle [Oracle Webserver]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602880019796&w=2

Description:
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:oracle-webserver-gain-root(7174)


CAN-1999-1126

Phase: Proposed (20010912)
Reference: CISCO:19980813 CRM Temporary File Vulnerability
Reference: URL:http://www.cisco.com/warp/public/770/crmtmp-pub.shtml
Reference: CIAC:I-086
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/i-086.shtml
Reference: XF:cisco-crm-file-vuln(1575)
Reference: URL:http://xforce.iss.net/static/1575.php

Description:
Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug.log, (3) dbi_debug.log, and (4) temporary files whose names begin with "DPR_".

Votes:

   ACCEPT(5) Frech, Foat, Cole, Armstrong, Stracener
   NOOP(1) Wall
   REJECT(1) Balinsky
Voter Comments:
 Balinsky> Duplicate of CAN-1999-1042


CAN-1999-1128

Phase: Proposed (20010912)
Reference: MISC:http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html
Reference: MISC:http://members.tripod.com/~unibyte/iebug3.htm

Description:
Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Christey, Foat
Voter Comments:
 Frech> XF:http-ie-exec(462)
 Christey> DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/ie3.html
   ADDREF MISC:http://focus.silversand.net/vulner/allbug/ie3.html


CAN-1999-1129

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990901 VLAN Security
Reference: URL:http://www.securityfocus.com/archive/1/26008
Reference: MISC:http://www.cisco.com/univercd/cc/td/doc/product/lan/28201900/1928v8x/eescg8x/aleakyv.htm
Reference: XF:cisco-catalyst-vlan-frames(3294)
Reference: URL:http://xforce.iss.net/static/3294.php
Reference: BID:615
Reference: URL:http://www.securityfocus.com/bid/615

Description:
Cisco Catalyst 2900 Virtual LAN (VLAN) switches allow remote attackers to inject 802.1q frames into another VLAN by forging the VLAN identifier in the trunking tag.

Votes:

   ACCEPT(2) Frech, Foat
   NOOP(2) Wall, Cole
Voter Comments:
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-1999-1130

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990730 Netscape Enterprise Server yeilds source of JHTML
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93346448121208&w=2
Reference: NTBUGTRAQ:19990730 Netscape Enterprise Server yeilds source of JHTML
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93337389603117&w=2
Reference: BID:559
Reference: URL:http://www.securityfocus.com/bid/559

Description:
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attackers to read the source of JHTML files by specifying a search command using the HTML-tocrec-demo1.pat pattern file.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:netscape-enterprise-view-jhtml(8352)


CAN-1999-1133

Phase: Modified (20020217-01)
Reference: HP:HPSBUX9709-069
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602880019776&w=2
Reference: XF:hp-vue-dt(499)
Reference: URL:http://xforce.iss.net/static/499.php

Description:
HP-UX 9.x and 10.x running X windows may allow local attackers to gain privileges via (1) vuefile, (2) vuepad, (3) dtfile, or (4) dtpad, which do not authenticate users.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener
   NOOP(1) Christey
Voter Comments:
 Christey> CHANGEREF:  chaneg XF reference to XF:hp-vue-dt(499)


CAN-1999-1134

Phase: Modified (20020217-01)
Reference: HP:HPSBUX9404-008
Reference: URL:http://packetstorm.securify.com/advisories/hpalert/008
Reference: CIAC:E-23
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/e-23.shtml
Reference: XF:hp-vue(2284)
Reference: URL:http://www.iss.net/security_center/static/2284.php

Description:
Vulnerability in Vue 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4038, PHSS_4055, and PHSS_4066.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:hp-vue(2284)
   Packetstorm URL is dead. Try another archive.


CAN-1999-1135

Phase: Proposed (20010912)
Reference: HP:HPSBUX9504-027
Reference: URL:http://packetstorm.securify.com/advisories/hpalert/027
Reference: XF:hp-vue(2284)
Reference: URL:http://xforce.iss.net/static/2284.php

Description:
Vulnerability in VUE 3.0 in HP 9.x allows local users to gain root privileges, as fixed by PHSS_4994 and PHSS_5438.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1141

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970515 MicroSolved finds hole in Ascom Timeplex Router Security
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420981&w=2
Reference: XF:ascom-timeplex-debug(1824)
Reference: URL:http://xforce.iss.net/static/1824.php

Description:
Ascom Timeplex router allows remote attackers to obtain sensitive information or conduct unauthorized activities by entering debug mode through a sequence of CTRL-D characters.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1149

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980716 S.A.F.E.R. Security Bulletin 980708.DOS.1.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525993&w=2
Reference: XF:csm-proxy-dos(1422)
Reference: URL:http://xforce.iss.net/static/1422.php

Description:
Buffer overflow in CSM Proxy 4.1 allows remote attackers to cause a denial of service (crash) via a long string to the FTP port.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1150

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980630 Livingston Portmaster - ISN generation is loosy!
Reference: URL:http://www.securityfocus.com/archive/1/9723
Reference: XF:portmaster-fixed-isn(1882)
Reference: URL:http://xforce.iss.net/static/1882.php

Description:
Livingston Portmaster routers running ComOS use the same initial sequence number (ISN) for TCP connections, which allows remote attackers to conduct spoofing and hijack TCP sessions.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1151

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980603 Compaq/Microcom 6000 DoS + more
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90296493106214&w=2
Reference: XF:microcom-dos(2089)
Reference: URL:http://xforce.iss.net/static/2089.php

Description:
Compaq/Microcom 6000 Access Integrator does not cause a session timeout after prompting for a username or password, which allows remote attackers to cause a denial of service by connecting to the integrator without providing a username or password.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1152

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980603 Compaq/Microcom 6000 DoS + more
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90296493106214&w=2

Description:
Compaq/Microcom 6000 Access Integrator does not disconnect a client after a certain number of failed login attempts, which allows remote attackers to guess usernames or passwords via a brute force attack.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:microcom-brute-force(7301)


CAN-1999-1153

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981109 Several new CGI vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/11175
Reference: XF:cgi-perl-mail-programs(1400)
Reference: URL:http://xforce.iss.net/static/1400.php

Description:
HAMcards Postcard CGI script 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1154

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981109 Several new CGI vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/11175
Reference: MISC:http://lakeweb.com/scripts/
Reference: XF:cgi-perl-mail-programs(1400)
Reference: URL:http://xforce.iss.net/static/1400.php

Description:
LakeWeb Filemail CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> I confirmed this problem via visual inspection of the
   source code in http://www.lakeweb.com/scripts/filemail.zip
   Line 82 has an insufficient check for shell metacharacters
   that doesn't exclude semicolons.  Line 129 is the 
   call where the metacharacters are injected.
   
   Need to add "filemail.pl" to the description.


CAN-1999-1155

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981109 Several new CGI vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/11175
Reference: MISC:http://lakeweb.com/scripts/
Reference: XF:cgi-perl-mail-programs(1400)
Reference: URL:http://xforce.iss.net/static/1400.php

Description:
LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1158

Phase: Proposed (20010912)
Reference: AUSCERT:AA-97.09
Reference: URL:ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.09.Solaris.passwd.buffer.overrun.vul
Reference: SUN:00139
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/139&type=0&nav=sec.sba

Description:
Buffer overflow in (1) pluggable authentication module (PAM) on Solaris 2.5.1 and 2.5 and (2) unix_scheme in Solaris 2.4 and 2.3 allows local users to gain root privileges via programs that use these modules such as passwd, yppasswd, and nispasswd.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solaris-pam-bo(7432)
 Dik> sun bug: 4018347


CAN-1999-1164

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990625 Outlook denial of service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93041631215856&w=2

Description:
Microsoft Outlook client allows remote attackers to cause a denial of service by sending multiple email messages with the same X-UIDL headers, which causes Outlook to hang.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:outlook-xuidl-dos(8356)


CAN-1999-1165

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990721 old gnu finger bugs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93268249021561&w=2
Reference: BUGTRAQ:19950317 GNU finger 1.37 executes ~/.fingerrc with gid root
Reference: URL:http://www.securityfocus.com/archive/1/2478
Reference: BID:535
Reference: URL:http://www.securityfocus.com/bid/535

Description:
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:gnu-finger-privilege-dropping(7175)


CAN-1999-1166

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990711 Linux 2.0.37 segment limit bug
Reference: URL:http://www.securityfocus.com/archive/1/18156
Reference: BID:523
Reference: URL:http://www.securityfocus.com/bid/523

Description:
Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by accessing and modifying kernel memory.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> (Task 2253)
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:linux-segment-limit-privileges(11202)


CAN-1999-1168

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990220 ISS install.iss security hole
Reference: URL:http://www.securityfocus.com/archive/1/12640

Description:
install.iss installation script for Internet Security Scanner (ISS) for Linux, version 5.3, allows local users to change the permissions of arbitrary files via a symlink attack on a temporary file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:iss-temp-files(1793)
   ADDREF:http://www.securityfocus.com/archive/1/12679


CAN-1999-1169

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990204 NOBO denial of service
Reference: URL:http://www.securityfocus.com/archive/1/12284

Description:
nobo 1.2 allows remote attackers to cause a denial of service (crash) via a series of large UDP packets.

Votes:

   ACCEPT(1) Foat
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:nobo-udp-packet-dos(7502)
   ADDREF:http://www.securityfocus.com/archive/1/12378
   ADDREF:http://web.cip.com.br/nobo/mudancas_en.html


CAN-1999-1170

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990204 WS FTP Server Remote DoS Attack
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91816507920544&w=2
Reference: BID:218
Reference: URL:http://www.securityfocus.com/bid/218

Description:
IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:imail-registry(1725)


CAN-1999-1171

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990204 WS FTP Server Remote DoS Attack
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91816507920544&w=2
Reference: BID:218
Reference: URL:http://www.securityfocus.com/bid/218

Description:
IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:wsftp-registry(1726)


CAN-1999-1172

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990114 security hole in Maximizer
Reference: URL:http://www.securityfocus.com/archive/1/11947

Description:
By design, Maximizer Enterprise 4 calendar and address book program allows arbitrary users to modify the calendar of other users when the calendar is being shared.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> The discloser does not provide enough details to fully
   understand what the problem is.  This makes it difficult
   because if Maximizer has a concept of "users" and it is
   designed to allow any user to modify any other user's data,
   then this would not be a vulnerability or exposure, unless
   that "cross-user" capability could be used to violate system
   integrity, data confidentiality, or the like.  There are some
   features of Maximizer 6.0 that, if abused, could allow someone
   to do some bad things.  For example, an attacker could modify
   the email addresses for contacts to redirect sales to
   locations besides the customer.  There's also a capability of
   assigning priorities and alarms, which could be susceptible to
   an "inconvenience attack" at the very least, as well as
   tie-ins to e-commerce capabilities.
   
   The critical question becomes: "how is this data shared" in
   the first place?  If it's through a network share or other
   distribution method besides transferring the complete database
   between sites, then this may be accessible to any attacker who
   can mimic a Maximizer client (if there is such a thing as a
   client), and this could be a vulnerability or exposure
   according to the CVE definition.
   
   However, since the Maximizer functionality is unknown to me
   and not readily apparent from product documentation, it's hard
   to know what to do about this one.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:maximizer-enterprise-calendar-modification(7590)


CAN-1999-1173

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981218 wordperfect 8 for linux security
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91404045014047&w=2

Description:
Corel Word Perfect 8 for Linux creates a temporary working directory with world-writable permissions, which allows local users to (1) modify Word Perfect behavior by modifying files in the working directory, or (2) modify files of other users via a symlink attack.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1174

Phase: Proposed (20010912)
Reference: MISC:http://www.counterpane.com/crypto-gram-9812.html#doghouse

Description:
ZIP drive for Iomega ZIP-100 disks allows attackers with physical access to the drive to bypass password protection by inserting a known disk with a known password, waiting for the ZIP drive to power down, manually replacing the known disk with the target disk, and using the known password to access the target disk.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Foat

CAN-1999-1176

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980110 Cidentd
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88466930416716&w=2
Reference: BUGTRAQ:19980911 Re: security problems with jidentd
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90554230925545&w=2
Reference: MISC:http://spisa.act.uji.es/spi/progs/codigo/www.hack.co.za/exploits/daemon/ident/cidentd.c

Description:
Buffer overflow in cidentd ident daemon allows local users to gain root privileges via a long line in the .authlie script.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:cidentd-authlie-bo(7327)


CAN-1999-1178

Phase: Proposed (20010912)
Reference: XF:sambar-dump-env(3223)
Reference: URL:http://xforce.iss.net/static/3223.php
Reference: BUGTRAQ:19980610 Sambar Server Beta BUG..
Reference: URL:http://www.securityfocus.com/archive/1/9505

Description:
Sambar Server 4.1 beta allows remote attackers to obtain sensitive information about the server via an HTTP request for the dumpenv.pl script.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1179

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980515 May SysAdmin man.sh security hole
Reference: URL:http://www.securityfocus.com/archive/1/9330

Description:
Vulnerability in man.sh CGI script, included in May 1998 issue of SysAdmin Magazine, allows remote attackers to execute arbitrary commands.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:mansh-execute-commands(7328)


CAN-1999-1180

Phase: Proposed (20010912)
Reference: MISC:http://oliver.efri.hr/~crv/security/bugs/NT/buffer.html
Reference: BUGTRAQ:19990216 Website Pro v2.0 (NT) Configuration Issues
Reference: URL:http://www.tryc.on.ca/archives/bugtraq/1999_1/0612.html

Description:
O'Reilly WebSite 1.1e and Website Pro 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in an argument to (1) args.cmd or (2) args.bat.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(3) Christey, Foat, Cole
Voter Comments:
 Christey> DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/buffer.html
   ADDREF MISC:http://focus.silversand.net/vulner/allbug/buffer.html
 Frech> XF:website-pro-args-commands(7529)


CAN-1999-1182

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970717 KSR[T] Advisory #2: ld.so
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602661419318&w=2
Reference: BUGTRAQ:19970722 ld.so vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602661419351&w=2
Reference: BUGTRAQ:19980204 An old ld-linux.so hole
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88661732807795&w=2

Description:
Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.

Votes:

   NOOP(2) Foat, Cole

CAN-1999-1183

Phase: Modified (20020217-01)
Reference: SGI:19980403-02-PX
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19980403-02-PX
Reference: SGI:19980403-01-PX
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19980403-01-PX
Reference: XF:sgi-mailcap(809)
Reference: URL:http://www.iss.net/security_center/static/809.php

Description:
System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:sgi-mailcap(809)


CAN-1999-1184

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970513
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420967&w=2
Reference: BUGTRAQ:19970514 Re: ELM overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420970&w=2

Description:
Buffer overflow in Elm 2.4 and earlier allows local users to gain privileges via a long TERM environmental variable.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:elm-term-bo(7183)


CAN-1999-1185

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980827 SCO mscreen vul.
Reference: BUGTRAQ:19980926 Root exploit for SCO OpenServer.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90686250717719&w=2
Reference: CERT:VB-98.10
Reference: SCO:98.05
Reference: XF:sco-openserver-mscreen-bo(1379)

Description:
Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> Possible dupe on CAN-1999-1041.
 Christey> Possible dupe with CAN-1999-1041.


CAN-1999-1186

Phase: Proposed (20010912)
Reference: BUGTRAQ:19960102 rxvt security hole
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418966&w=2

Description:
rxvt, when compiled with the PRINT_PIPE option in various Linux operating systems including Linux Slackware 3.0 and RedHat 2.1, allows local users to gain root privileges by specifying a malicious program using the -print-pipe command line parameter.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:rxvtpipe(425)


CAN-1999-1187

Phase: Proposed (20010912)
Reference: BUGTRAQ:19960826 [BUG] Vulnerability in PINE
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419803&w=2
Reference: XF:pine-tmpfile(416)
Reference: URL:http://xforce.iss.net/static/416.php

Description:
Pine before version 3.94 allows local users to gain privileges via a symlink attack on a lockfile that is created when a user receives new mail.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> CONFIRM:http://www.washington.edu/pine/changes.html


CAN-1999-1189

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991124 Netscape Communicator 4.7 - Navigator Overflows
Reference: URL:http://www.securityfocus.com/archive/1/36306
Reference: BUGTRAQ:19991127 Netscape Communicator 4.7 - Navigator Overflows
Reference: URL:http://www.securityfocus.com/archive/1/36608
Reference: BID:822
Reference: URL:http://www.securityfocus.com/bid/822

Description:
Buffer overflow in Netscape Navigator/Communicator 4.7 for Windows 95 and Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument after the ? character in a URL that references an .asp, .cgi, .html, or .pl file.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:netscape-long-argument-bo(7884)


CAN-1999-1190

Phase: Proposed (20010912)
Reference: MISC:http://www.securiteam.com/exploits/E-MailClub__FROM__remote_buffer_overflow.html
Reference: BID:801
Reference: URL:http://www.securityfocus.com/bid/801

Description:
Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:emailclub-pop3-from-bo(7873)


CAN-1999-1195

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990505 NAI AntiVirus Update Problem
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92587579032534&w=2
Reference: BUGTRAQ:19990505 NAI AntiVirus Update Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92588169005196&w=2
Reference: BID:169
Reference: URL:http://www.securityfocus.com/bid/169

Description:
NAI VirusScan NT 4.0.2 does not properly modify the scan.dat virus definition file during an update via FTP, but it reports that the update was successful, which could cause a system administrator to believe that the definitions have been updated correctly.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:virusscan-ftp-update(8387)


CAN-1999-1196

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990427 NT/Exceed D.O.S.
Reference: URL:http://www.securityfocus.com/archive/1/13451
Reference: BID:158
Reference: URL:http://www.securityfocus.com/bid/158

Description:
Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:exceed-xserver-dos(7530)


CAN-1999-1199

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980807 YA Apache DoS attack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90252779826784&w=2
Reference: BUGTRAQ:19980808 Debian Apache Security Update
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90276683825862&w=2
Reference: BUGTRAQ:19980810 Apache DoS Attack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90286768232093&w=2
Reference: BUGTRAQ:19980811 Apache 'sioux' DOS fix for TurboLinux
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90280517007869&w=2

Description:
Apache WWW server 1.3.1 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via a large number of MIME headers with the same name, aka the "sioux" vulnerability.

Votes:

   ACCEPT(2) Cox, Cole
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> CONFIRM:http://www.redhat.com/support/errata/rh51-errata-general.html#apache


CAN-1999-1200

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19980720 DOS in Vintra systems Mailserver software.
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=90222454131610&w=2
Reference: XF:vintra-mail-dos(1617)
Reference: URL:http://xforce.iss.net/static/1617.php

Description:
Vintra SMTP MailServer allows remote attackers to cause a denial of service via a malformed "EXPN *@" command.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1201

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990206 New Windows 9x Bug: TCP Chorusing
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91849617221319&w=2
Reference: BID:225
Reference: URL:http://www.securityfocus.com/bid/225

Description:
Windows 95 and Windows 98 systems, when configured with multiple TCP/IP stacks bound to the same MAC address, allow remote attackers to cause a denial of service (traffic amplification) via a certain ICMP echo (ping) packet, which causes all stacks to send a ping response, aka TCP Chorusing.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:win-multiple-ip-dos(7542)


CAN-1999-1202

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980703 Windows95 Proxy DoS Vulnerabilites
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525873&w=2
Reference: XF:startech-pop3-overflow(2088)
Reference: URL:http://xforce.iss.net/static/2088.php

Description:
StarTech (1) POP3 proxy server and (2) telnet server allows remote attackers to cause a denial of service via a long USER command.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1206

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990729 New ActiveX security problems in Windows 98 PCs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93336970231857&w=2
Reference: CONFIRM:http://www.systemsoft.com/l-2/l-3/support-systemwizard.htm
Reference: BID:555
Reference: URL:http://www.securityfocus.com/bid/555

Description:
SystemSoft SystemWizard package in HP Pavilion PC with Windows 98, and possibly other platforms and operating systems, installs two ActiveX controls that are marked as safe for scripting, which allows remote attackers to execute arbitrary commands via a malicious web page that references (1) the Launch control, or (2) the RegObj control.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
Voter Comments:
 Frech> XF:systemwizard-modify-registry(7080)
 Christey> CERT-VN:VU#22919
   URL:http://www.kb.cert.org/vuls/id/22919
   CERT-VN:VU#34453
   URL:http://www.kb.cert.org/vuls/id/34453


CAN-1999-1207

Phase: Proposed (20010912)
Reference: MISC:http://www.efri.hr/~crv/security/bugs/NT/netxtray.html
Reference: XF:netxray-bo(907)
Reference: URL:http://xforce.iss.net/static/907.php

Description:
Buffer overflow in web-admin tool in NetXRay 2.6 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1210

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971112 Digital Unix Security Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87936891504885&w=2
Reference: XF:dec-xterm(613)
Reference: URL:http://xforce.iss.net/static/613.php

Description:
xterm in Digital UNIX 4.0B *with* patch kit 5 allows local users to overwrite arbitrary files via a symlink attack on a core dump file, which is created when xterm is called with a DISPLAY environmental variable set to a display that xterm cannot access.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1211

Phase: Proposed (20010912)
Reference: CERT:CA-1991-02
Reference: URL:http://www.cert.org/advisories/CA-1991-02.html
Reference: XF:sun-intelnetd(574)
Reference: URL:http://xforce.iss.net/static/574.php

Description:
Vulnerability in in.telnetd in SunOS 4.1.1 and earlier allows local users to gain root privileges.

Votes:

   ACCEPT(5) Frech, Foat, Cole, Dik, Stracener
   NOOP(1) Wall
Voter Comments:
 Frech> CONFIRM:Sun Microsystems, Inc. Security Bulletin #00106 at
   http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/1
   06&type=0&nav=sec.sba
 Dik> sun bug:  1054669 1049886 1042370 1033809


CAN-1999-1212

Phase: Proposed (20010912)
Reference: CERT:CA-1991-02
Reference: URL:http://www.cert.org/advisories/CA-1991-02.html
Reference: XF:sun-intelnetd(574)
Reference: URL:http://xforce.iss.net/static/574.php

Description:
Vulnerability in in.rlogind in SunOS 4.0.3 and 4.0.3c allows local users to gain root privileges.

Votes:

   ACCEPT(5) Frech, Foat, Cole, Dik, Stracener
   NOOP(1) Wall
Voter Comments:
 Dik> sun bug:  1054669 1049886 1042370 1033809


CAN-1999-1213

Phase: Proposed (20010912)
Reference: HP:HPSBUX9710-070
Reference: URL:http://www2.dataguard.no/bugtraq/1997_4/0001.html
Reference: XF:hp-telnetdos(571)
Reference: URL:http://xforce.iss.net/static/571.php

Description:
Vulnerability in telnet service in HP-UX 10.30 allows attackers to cause a denial of service.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1216

Phase: Proposed (20010912)
Reference: CERT:CA-1993-07
Reference: URL:http://www.cert.org/advisories/CA-1993-07.html
Reference: CIAC:D-15
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/d-15.shtml
Reference: XF:cisco-sourceroute(541)
Reference: URL:http://xforce.iss.net/static/541.php

Description:
Cisco routers 9.17 and earlier allow remote attackers to bypass security restrictions via certain IP source routed packets that should normally be denied using the "no ip source-route" command.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener
   NOOP(1) Wall

CAN-1999-1217

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19970725 Re: NT security - why bother?
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=87602726319435&w=2
Reference: NTBUGTRAQ:19970723 NT security - why bother?
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=87602726319426&w=2
Reference: XF:nt-path(526)
Reference: URL:http://xforce.iss.net/static/526.php

Description:
The PATH in Windows NT includes the current working directory (.), which could allow local users to gain privileges by placing Trojan horse programs with the same name as commonly used system programs into certain directories.

Votes:

   ACCEPT(3) Frech, Foat, Cole
Voter Comments:
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-1999-1218

Phase: Proposed (20010912)
Reference: CERT:CA-1993-04
Reference: URL:http://www.cert.org/advisories/CA-1993-04.html
Reference: XF:amiga-finger(522)
Reference: URL:http://xforce.iss.net/static/522.php

Description:
Vulnerability in finger in Commodore Amiga UNIX 2.1p2a and earlier allows local users to read arbitrary files.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener
   NOOP(1) Wall

CAN-1999-1219

Phase: Proposed (20010912)
Reference: CERT:CA-1994-13
Reference: URL:http://www.cert.org/advisories/CA-1994-13.html
Reference: AUSCERT:AA-94.04a
Reference: CIAC:E-33
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/e-33.shtml
Reference: XF:sgi-prn-mgr(511)
Reference: URL:http://xforce.iss.net/static/511.php
Reference: BID:468
Reference: URL:http://www.securityfocus.com/bid/468

Description:
Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener
   NOOP(1) Wall

CAN-1999-1220

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970824 Vulnerability in Majordomo
Reference: URL:http://www.securityfocus.com/archive/1/7527
Reference: XF:majordomo-advertise(502)
Reference: URL:http://xforce.iss.net/static/502.php

Description:
Majordomo 1.94.3 and earlier allows remote attackers to execute arbitrary commands when the advertise or noadvertise directive is used in a configuration file, via shell metacharacters in the Reply-To header.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1221

Phase: Proposed (20010912)
Reference: BUGTRAQ:19961117 Digital Unix v3.x (v4.x?) security vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420141&w=2
Reference: XF:dgux-chpwd(399)
Reference: URL:http://xforce.iss.net/static/399.php

Description:
dxchpwd in Digital Unix (OSF/1) 3.x allows local users to modify arbitrary files via a symlink attack on the dxchpwd.log file.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1224

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971008 L0pht Advisory: IMAP4rev1 imapd server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87635124302928&w=2
Reference: XF:imapd-core(349)
Reference: URL:http://xforce.iss.net/static/349.php

Description:
IMAP 4.1 BETA, and possibly other versions, does not properly handle the SIGABRT (abort) signal, which allows local users to crash the server (imapd) via certain sequences of commands, which causes a core dump that may contain sensitive password information.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1225

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970824 Serious security flaw in rpc.mountd on several operating systems.
Reference: URL:http://www.securityfocus.com/archive/1/7526
Reference: XF:mountd-file-exists(347)
Reference: URL:http://xforce.iss.net/static/347.php

Description:
rpc.mountd on Linux, Ultrix, and possibly other operating systems, allows remote attackers to determine the existence of a file on the server by attempting to mount that file, which generates different error messages depending on whether the file exists or not.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1227

Phase: Proposed (20010912)
Reference: MISC:http://www.ethereal.com/lists/ethereal-dev/199907/msg00126.html
Reference: MISC:http://www.ethereal.com/lists/ethereal-dev/199907/msg00130.html
Reference: XF:ethereal-dev-capturec-root(3334)
Reference: URL:http://xforce.iss.net/static/3334.php

Description:
Ethereal allows local users to overwrite arbitrary files via a symlink attack on the packet capture file.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1228

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980927 1+2=3, +++ATH0=Old school DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90695973308453&w=2
Reference: MISC:http://www.macintouch.com/modemsecurity.html
Reference: XF:global-village-modem-dos(3320)
Reference: URL:http://xforce.iss.net/static/3320.php

Description:
Various modems that do not implement a guard time, or are configured with a guard time of 0, can allow remote attackers to execute arbitrary modem commands such as ATH, ATH0, etc., via a "+++" sequence that appears in ICMP packets, the subject of an e-mail message, IRC commands, and others.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1229

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980225 Quake 2 Linux 3.13 (and lower) allow users to read arbitrary files
Reference: URL:http://www.securityfocus.com/archive/1/8590
Reference: XF:linux-quake2(733)
Reference: URL:http://xforce.iss.net/static/733.php

Description:
Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1230

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971224 Quake II Remote Denial of Service
Reference: URL:http://www.securityfocus.com/archive/1/8282
Reference: XF:quake2-dos(698)
Reference: URL:http://xforce.iss.net/static/698.php

Description:
Quake 2 server allows remote attackers to cause a denial of service via a spoofed UDP packet with a source address of 127.0.0.1, which causes the server to attempt to connect to itself.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1231

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990609 ssh advirsory
Reference: URL:http://www.securityfocus.com/archive/1/14758
Reference: XF:ssh-leak(2276)
Reference: URL:http://xforce.iss.net/static/2276.php

Description:
ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1232

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970516 Irix and WWW
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420994&w=2
Reference: XF:sgi-day5datacopier(3316)
Reference: URL:http://xforce.iss.net/static/3316.php

Description:
day5datacopier in SGI IRIX 6.2 trusts the PATH environmental variable to find the "cp" program, which allows local users to execute arbitrary commands by modifying the PATH to point to a Trojan horse cp program.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1234

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991026 Re: LSA vulnerability on NT40 SP5
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94096671308565&w=2
Reference: XF:msrpc-samr-open-dos(3293)
Reference: URL:http://xforce.iss.net/static/3293.php

Description:
LSA (LSASS.EXE) in Windows NT 4.0 allows remote attackers to cause a denial of service via a NULL policy handle in a call to (1) SamrOpenDomain, (2) SamrEnumDomainUsers, and (3) SamrQueryDomainInfo.

Votes:

   ACCEPT(3) Frech, Wall, Cole
   NOOP(1) Foat

CAN-1999-1235

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990331 Minor Bug in IE5.0
Reference: URL:http://ntbugtraq.ntadvice.com/default.asp?pid=36&sid=1&A2=ind9904&L=NTBUGTRAQ&P=R179
Reference: NTBUGTRAQ:19990825 IE5 FTP password exposure & index.dat null ACL problem
Reference: URL:http://packetderm.cotse.com/mailing-lists/ntbugtraq/1999/0364.html
Reference: XF:nt-ie5-user-ftp-password(3289)
Reference: URL:http://xforce.iss.net/static/3289.php

Description:
Internet Explorer 5.0 records the username and password for FTP servers in the URL history, which could allow (1) local users to read the information from another user's index.dat, or (2) people who are physically observing ("shoulder surfing") another user to read the information from the status bar when the user moves the mouse over a link.

Votes:

   ACCEPT(4) Frech, Wall, Foat, Cole
Voter Comments:
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-1999-1236

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19991001 Vulnerabilities in the Internet Anywhere Mail Server
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9910&L=ntbugtraq&F=&S=&P=662
Reference: BID:731
Reference: URL:http://www.securityfocus.com/bid/731
Reference: XF:iams-passwords-plaintext(3285)
Reference: URL:http://xforce.iss.net/static/3285.php

Description:
Internet Anywhere Mail Server 2.3.1 stores passwords in plaintext in the msgboxes.dbf file, which could allow local users to gain privileges by extracting the passwords from msgboxes.dbf.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1237

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990606 Buffer overflows in smbval library
Reference: URL:http://www.securityfocus.com/archive/1/14384
Reference: XF:smbvalid-bo(2272)
Reference: URL:http://xforce.iss.net/static/2272.php

Description:
Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attackers to execute arbitrary commands via (1) a long username, (2) a long password, and (3) other unspecified methods.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1238

Phase: Proposed (20010912)
Reference: HP:HPSBUX9409-017
Reference: URL:http://www.securityfocus.com/advisories/1531
Reference: XF:hp-core-diag-fileset(2262)
Reference: URL:http://xforce.iss.net/static/2262.php

Description:
Vulnerability in CORE-DIAG fileset in HP message catalog in HP-UX 9.05 and earlier allows local users to gain privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1239

Phase: Proposed (20010912)
Reference: HP:HPSBUX9407-015
Reference: URL:http://www.securityfocus.com/advisories/1559
Reference: XF:hp-xauthority(2261)
Reference: URL:http://xforce.iss.net/static/2261.php

Description:
HP-UX 9.x does not properly enable the Xauthority mechanism in certain conditions, which could allow local users to access the X display even when they have not explicitly been authorized to do so.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1240

Phase: Proposed (20010912)
Reference: BUGTRAQ:19961126 Major Security Vulnerabilities in Remote CD Databases
Reference: URL:http://www.securityfocus.com/archive/1/5784
Reference: XF:cddbd-bo(2203)
Reference: URL:http://xforce.iss.net/static/2203.php

Description:
Buffer overflow in cddbd CD database server allows remote attackers to execute arbitrary commands via a long log message.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1241

Phase: Proposed (20010912)
Reference: MISC:http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html
Reference: XF:ie-filesystemobject(2173)
Reference: URL:http://xforce.iss.net/static/2173.php

Description:
Internet Explorer, with a security setting below Medium, allows remote attackers to execute arbitrary commands via a malicious web page that uses the FileSystemObject ActiveX object.

Votes:

   ACCEPT(3) Frech, Wall, Cole
   NOOP(2) Christey, Foat
Voter Comments:
 Christey> DELREF MISC:http://oliver.efri.hr/~crv/security/bugs/NT/activex4.html
   ADDREF MISC:http://focus.silversand.net/vulner/allbug/activex4.html
 Frech> Change MISC to http://www.securitybugware.org/NT/1018.html


CAN-1999-1242

Phase: Proposed (20010912)
Reference: HP:HPSBUX9402-003
Reference: URL:http://packetstormsecurity.org/advisories/hpalert/003
Reference: XF:hp-subnet-config(2162)
Reference: URL:http://xforce.iss.net/static/2162.php

Description:
Vulnerability in subnetconfig in HP-UX 9.01 and 9.0 allows local users to gain privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1244

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990415 FSA-99.04-IPFILTER-v3.2.10
Reference: URL:http://www.securityfocus.com/archive/1/13303
Reference: XF:ipfilter-temp-file(2087)
Reference: URL:http://xforce.iss.net/static/2087.php

Description:
IPFilter 3.2.3 through 3.2.10 allows local users to modify arbitrary files via a symlink attack on the saved output file.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1245

Phase: Proposed (20010912)
Reference: XF:ucd-snmpd-community(2086)
Reference: URL:http://xforce.iss.net/static/2086.php

Description:
vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> http://www.securityfocus.com/archive/1/13130


CAN-1999-1247

Phase: Proposed (20010912)
Reference: HP:HPSBUX9402-006
Reference: URL:http://packetstormsecurity.org/advisories/hpalert/006
Reference: XF:hp-dce9000(2061)
Reference: URL:http://xforce.iss.net/static/2061.php

Description:
Vulnerability in HP Camera component of HP DCE/9000 in HP-UX 9.x allows attackers to gain root privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1248

Phase: Proposed (20010912)
Reference: HP:HPSBUX9411-019
Reference: URL:http://packetstormsecurity.org/advisories/hpalert/019
Reference: XF:hp-supportwatch(2058)
Reference: URL:http://xforce.iss.net/static/2058.php

Description:
Vulnerability in Support Watch (aka SupportWatch) in HP-UX 8.0 through 9.0 allows local users to gain privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1250

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970819 Lasso CGI security hole (fwd)
Reference: URL:http://www.securityfocus.com/archive/1/7506
Reference: XF:http-cgi-lasso(2044)
Reference: URL:http://xforce.iss.net/static/2044.php

Description:
Vulnerability in CGI program in the Lasso application by Blue World, as used on WebSTAR and other servers, allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1251

Phase: Proposed (20010912)
Reference: HP:HPSBUX9612-043
Reference: URL:http://packetstormsecurity.org/advisories/hpalert/043
Reference: XF:hp-audio-panic(2010)
Reference: URL:http://xforce.iss.net/static/2010.php

Description:
Vulnerability in direct audio user space code on HP-UX 10.20 and 10.10 allows local users to cause a denial of service.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1252

Phase: Proposed (20010912)
Reference: CERT:VB-96.15
Reference: URL:http://www.cert.org/vendor_bulletins/VB-96.15.sco
Reference: SCO:96:002
Reference: URL:ftp://ftp.sco.COM/SSE/security_bulletins/SB.96:02a
Reference: XF:sco-system-call(1966)
Reference: URL:http://xforce.iss.net/static/1966.php

Description:
Vulnerability in a certain system call in SCO UnixWare 2.0.x and 2.1.0 allows local users to access arbitrary files and gain root privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener
   NOOP(1) Wall

CAN-1999-1253

Phase: Proposed (20010912)
Reference: CERT:VB-96.10
Reference: URL:http://www.cert.org/vendor_bulletins/VB-96.10.sco
Reference: SCO:96:001
Reference: URL:ftp://ftp.sco.com/SSE/security_bulletins/SB.96:01a
Reference: XF:sco-kernel(1965)
Reference: URL:http://xforce.iss.net/static/1965.php

Description:
Vulnerability in a kernel error handling routine in SCO OpenServer 5.0.2 and earlier, and SCO Internet FastStart 1.0, allows local users to gain root privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener
   NOOP(1) Wall

CAN-1999-1254

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990308 Winfreeze EXPLOIT Win9x/NT
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92099515709467&w=2
Reference: XF:win-redirects-freeze(1947)
Reference: URL:http://xforce.iss.net/static/1947.php

Description:
Windows 95, 98, and NT 4.0 allow remote attackers to cause a denial of service by spoofing ICMP redirect messages from a router, which causes Windows to change its routing tables.

Votes:

   ACCEPT(3) Frech, Wall, Cole
   MODIFY(1) Meunier
   NOOP(2) Christey, Foat
Voter Comments:
 Christey> Need to get feedback from MS on this.
 Christey> (prompted from Pascal Meunier) should this be treated
   as a general design issue with ICMP?  Or is it a specific
   implementation flaw that only affects Reliant?
 Meunier> The description is too narrow and incorrect.  Spoofed ICMP
   redirect messages can be used to setup man-in-the-middle attacks
   instead of a DoS.  There's no reason that this behavior would be
   limited to Windows, as it is specified by the standard.  As I said
   elsewhere, ICMP messages should not be acted upon without access
   controls.


CAN-1999-1255

Phase: Proposed (20010912)
Reference: MISC:http://www.rootshell.com/archive-j457nxiqi3gq59dv/199902/hyperseek.txt.html
Reference: XF:hyperseek-modify(1914)
Reference: URL:http://xforce.iss.net/static/1914.php

Description:
Hyperseek allows remote attackers to modify the hyperseek configuration by directly calling the admin.cgi program with an edit_file action parameter.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1256

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990304 Oracle Plaintext Password
Reference: URL:http://www.securityfocus.com/archive/1/12744
Reference: NTBUGTRAQ:19990304 Oracle Plaintext Password
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92056752115116&w=2
Reference: XF:oracle-passwords(1902)
Reference: URL:http://xforce.iss.net/static/1902.php

Description:
Oracle Database Assistant 1.0 in Oracle 8.0.3 Enterprise Edition stores the database master password in plaintext in the spoolmain.log file when a new database is created, which allows local users to obtain the password from that file.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1257

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971126 Xyplex terminal server bug
Reference: URL:http://www.securityfocus.com/archive/1/8134
Reference: XF:xyplex-controlz-login(1825)
Reference: URL:http://xforce.iss.net/static/1825.php
Reference: XF:xyplex-question-login(1826)
Reference: URL:http://xforce.iss.net/static/1826.php

Description:
Xyplex terminal server 6.0.1S1, and possibly other versions, allows remote attackers to bypass the password prompt by entering (1) a CTRL-Z character, or (2) a ? (question mark).

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1260

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990215 KSR[T] Advisory #10: mSQL ServerStats
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91910115718150&w=2
Reference: XF:msql-serverstats(1777)
Reference: URL:http://xforce.iss.net/static/1777.php

Description:
mSQL (Mini SQL) 2.0.6 allows remote attackers to obtain sensitive server information such as logged users, database names, and server version via the ServerStats query.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1261

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990211 Rainbow Six Buffer Overflow.....
Reference: URL:http://www.securityfocus.com/archive/1/12433
Reference: XF:rainbowsix-nick-bo(1772)
Reference: URL:http://xforce.iss.net/static/1772.php

Description:
Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1264

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990121 WebRamp M3 remote network access bug
Reference: URL:http://www.securityfocus.com/archive/1/12048
Reference: BUGTRAQ:19990203 WebRamp M3 Perceived Bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91815321510224&w=2
Reference: XF:webramp-remote-access(1670)
Reference: URL:http://xforce.iss.net/static/1670.php

Description:
WebRamp M3 router does not disable remote telnet or HTTP access to itself, even when access has been expliticly disabled.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1265

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980922 Re: WARNING! SMTP Denial of Service in SLmail ver 3.1
Reference: BUGTRAQ:19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90649892424117&w=2
Reference: NTBUGTRAQ:19980922 WARNING! SMTP Denial of Service in SLmail ver 3.1
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=90650438826447&w=2
Reference: XF:slmail-parens-overload(1664)
Reference: URL:http://xforce.iss.net/static/1664.php

Description:
SMTP server in SLmail 3.1 and earlier allows remote attackers to cause a denial of service via malformed commands whose arguments begin with a "(" (parenthesis) character, such as (1) SEND, (2) VRFY, (3) EXPN, (4) MAIL FROM, (5) RCPT TO.

Votes:

   ACCEPT(3) Frech, Foat, Cole
   NOOP(1) Wall

CAN-1999-1266

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970613 rshd gives away usernames
Reference: URL:http://www.securityfocus.com/archive/1/6978
Reference: XF:rsh-username-leaks(1660)
Reference: URL:http://xforce.iss.net/static/1660.php

Description:
rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1267

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970505 Hole in the KDE desktop
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420906&w=2
Reference: XF:kde-flawed-ipc(1646)
Reference: URL:http://xforce.iss.net/static/1646.php

Description:
KDE file manager (kfm) uses a TCP server for certain file operations, which allows remote attackers to modify arbitrary files by sending a copy command to the server.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1268

Phase: Proposed (20010912)
Reference: MISC:http://lists.kde.org/?l=kde-devel&m=91560433413263&w=2
Reference: XF:kde-konsole-hijack(1645)
Reference: URL:http://xforce.iss.net/static/1645.php

Description:
Vulnerability in KDE konsole allows local users to hijack or observe sessions of other users by accessing certain devices.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1269

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980206 serious security hole in KDE Beta 3
Reference: URL:http://www.securityfocus.com/archive/1/8506
Reference: XF:kde-kss-file-clobber(1641)
Reference: URL:http://xforce.iss.net/static/1641.php

Description:
Screen savers in KDE beta 3 allows local users to overwrite arbitrary files via a symlink attack on the .kss.pid file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1270

Phase: Proposed (20010912)
Reference: MISC:http://lists.kde.org/?l=kde-devel&m=90221974029738&w=2
Reference: XF:kde-kmail-passphrase-leak(1639)
Reference: URL:http://xforce.iss.net/static/1639.php

Description:
KMail in KDE 1.0 provides a PGP passphrase as a command line argument to other programs, which could allow local users to obtain the passphrase and compromise the PGP keys of other users by viewing the arguments via programs that list process information, such as ps.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1271

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980611 Unsecure passwords in Macromedia Dreamweaver
Reference: URL:http://www.securityfocus.com/archive/1/9511
Reference: XF:dreamweaver-weak-passwords(1636)
Reference: URL:http://xforce.iss.net/static/1636.php

Description:
Macromedia Dreamweaver uses weak encryption to store FTP passwords, which could allow local users to easily decrypt the passwords of other users.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1272

Phase: Proposed (20010912)
Reference: SGI:19980301-01-PX
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX
Reference: XF:irix-cdrom-confidence(1635)
Reference: URL:http://xforce.iss.net/static/1635.php

Description:
Buffer overflows in CDROM Confidence Test program (cdrom) allow local users to gain root privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1273

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980220 Simple way to bypass squid ACLs
Reference: URL:http://www.securityfocus.com/archive/1/8551
Reference: XF:squid-regexp-acl(1627)
Reference: URL:http://xforce.iss.net/static/1627.php

Description:
Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1274

Phase: Proposed (20010912)
Reference: BUGTRAQ:19971229 iPass RoamServer 3.1
Reference: URL:http://www.securityfocus.com/archive/1/8307
Reference: XF:ipass-temporary-files(1625)
Reference: URL:http://xforce.iss.net/static/1625.php

Description:
iPass RoamServer 3.1 creates temporary files with world-writable permissions.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1275

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970908 Password unsecurity in cc:Mail release 8
Reference: URL:http://www.securityfocus.com/archive/1/9478
Reference: XF:lotus-ccmail-passwords(1619)
Reference: URL:http://xforce.iss.net/static/1619.php

Description:
Lotus cc:Mail release 8 stores the postoffice password in plaintext in a hidden file which has insecure permissions, which allows local users to gain privileges.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1277

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19981224 BackWeb - Password issue (used by NAI for Corporate customer notification).
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91487886514546&w=2
Reference: XF:backweb-cleartext-passwords(1565)
Reference: URL:http://xforce.iss.net/static/1565.php

Description:
BackWeb client stores the username and password in cleartext for proxy authentication in the Communication registry key, which could allow other local users to gain privileges by reading the password.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1278

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981225 Re: Nlog v1.0 Released - Nmap 2.x log management / analyzing tool
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91470326629357&w=2
Reference: BUGTRAQ:19981226 Nlog 1.1b released - security holes fixed
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91471400632145&w=2
Reference: XF:http-cgi-nlog-netbios(1550)
Reference: URL:http://xforce.iss.net/static/1550.php
Reference: XF:http-cgi-nlog-metachars(1549)

Description:
nlog CGI scripts do not properly filter shell metacharacters from the IP address argument, which could allow remote attackers to execute certain commands via (1) nlog-smb.pl or (2) rpc-nlog.pl.

Votes:

   ACCEPT(3) Frech, Foat, Cole
   NOOP(1) Wall

CAN-1999-1280

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981203 Remote Tools w/Exceed v.6.0.1.0 fer 95
Reference: URL:http://www.securityfocus.com/archive/1/11512
Reference: XF:exceed-cleartext-passwords(1547)
Reference: URL:http://xforce.iss.net/static/1547.php

Description:
Hummingbird Exceed 6.0.1.0 inadvertently includes a DLL that was meant for development and testing, which logs user names and passwords in cleartext in the test.log file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1281

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981226 Breeze Network Server remote reboot and other bogosity.
Reference: URL:http://www.securityfocus.com/archive/1/11720
Reference: XF:breeze-remote-reboot(1544)
Reference: URL:http://xforce.iss.net/static/1544.php

Description:
Development version of Breeze Network Server allows remote attackers to cause the system to reboot by accessing the configbreeze CGI program.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> There have been no followups to indicate that this issue has
   been 
   resolved in the production version, and as a benefit to the doubt,
   this issue
   transcends EX-BETA until proven otherwise.


CAN-1999-1282

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981210 RealSystem passwords
Reference: URL:http://www.securityfocus.com/archive/1/11543
Reference: XF:realsystem-readable-conf-file(1542)
Reference: URL:http://xforce.iss.net/static/1542.php

Description:
RealSystem G2 server stores the administrator password in cleartext in a world-readable configuration file, which allows local users to gain privileges.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1283

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980814 URL exploit to crash Opera Browser
Reference: URL:http://www.securityfocus.com/archive/1/10320
Reference: XF:opera-slash-crash(1541)
Reference: URL:http://xforce.iss.net/static/1541.php

Description:
Opera 3.2.1 allows remote attackers to cause a denial of service (application crash) via a URL that contains an extra / in the http:// tag.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> Will go along with a REJECT if MITRE decides on
   EX-CLIENT-DOS.


CAN-1999-1285

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981227 [patch] fix for urandom read(2) not interruptible
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91495921611500&w=2
Reference: XF:linux-random-read-dos(1472)
Reference: URL:http://xforce.iss.net/static/1472.php

Description:
Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1286

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970509 Re: Irix: misc
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420927&w=2
Reference: XF:irix-addnetpr(1433)
Reference: URL:http://xforce.iss.net/static/1433.php

Description:
addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Christey, Foat, Cole
Voter Comments:
 Christey> CHANGE DESC: "via a symlink attack on the printers temporary file."
   Add 5.3 as another affected version.
   
   MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX
   SGI:19961203-02-PX may solve this problem, but the advisory is so
   vague that it is uncertain whether this was fixed or not. addnetpr is
   not specifically named in the advisory, which names netprint, which is
   not specified in the original Bugtraq post. In addition, the date on
   the advisory is one day earlier than that of the Bugtraq post, though
   that could be a difference in time zones. It seems plausible that the
   problem had already been patched (the researcher did say "There *was*
   [a] race condition") so maybe SGI released this advisory after the
   problem was publicized.
   
   ADDREF BID:330
   URL:http://www.securityfocus.com/bid/330
   
   Note: this is a dupe of CAN-1999-1410, but CAN-1999-1410 will
   be rejected in favor of CAN-1999-1286.


CAN-1999-1287

Phase: Proposed (20010912)
Reference: CONFIRM:http://www.statslab.cam.ac.uk/~sret1/analog/security.html
Reference: XF:analog-remote-file(1410)
Reference: URL:http://xforce.iss.net/static/1410.php

Description:
Vulnerability in Analog 3.0 and earlier allows remote attackers to read arbitrary files via the forms interface.

Votes:

   ACCEPT(4) Frech, Cole, Armstrong, Stracener
   NOOP(2) Wall, Foat
Voter Comments:
 CHANGE> [Foat changed vote from ACCEPT to NOOP]


CAN-1999-1289

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981111 WARNING: Another ICQ IP address vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/11233
Reference: XF:icq-ip-info(1398)
Reference: URL:http://xforce.iss.net/static/1398.php

Description:
ICQ 98 beta on Windows NT leaks the internal IP address of a client in the TCP data segment of an ICQ packet instead of the public address (e.g. through NAT), which provides remote attackers with potentially sensitive information about the client or the internal network configuration.

Votes:

   ACCEPT(3) Frech, Wall, Cole
   NOOP(1) Foat
Voter Comments:
 Frech> Override EX-BETA in this case, since ICQ is always in beta
   and is 
   widely run in production environments.


CAN-1999-1291

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981005 New Windows Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/10789
Reference: XF:nt-brkill(1383)
Reference: URL:http://xforce.iss.net/static/1383.php

Description:
TCP/IP implementation in Microsoft Windows 95, Windows NT 4.0, and possibly others, allows remote attackers to reset connections by forcing a reset (RST) via a PSH ACK or other means, obtaining the target's last sequence number from the resulting packet, then spoofing a reset to the target.

Votes:

   ACCEPT(3) Frech, Wall, Cole
   NOOP(2) Christey, Foat
Voter Comments:
 Christey> Need to get feedback from MS on this.


CAN-1999-1292

Phase: Proposed (20010912)
Reference: ISS:19980901 Remote Buffer Overflow in the Kolban Webcam32 Program
Reference: URL:http://xforce.iss.net/alerts/advise7.php
Reference: XF:webcam32-buffer-overflow(1366)
Reference: URL:http://xforce.iss.net/static/1366.php

Description:
Buffer overflow in web administration feature of Kolban Webcam32 4.8.3 and earlier allows remote attackers to execute arbitrary commands via a long URL.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1293

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980106 Apache security advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88413292830649&w=2
Reference: CONFIRM:http://www.apache.org/info/security_bulletin_1.2.5.html

Description:
mod_proxy in Apache 1.2.5 and earlier allows remote attackers to cause a denial of service via malformed FTP commands, which causes Apache to dump core.

Votes:

   ACCEPT(3) Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:apache-mod-proxy-dos(7249)
   CONFIRM reference no longer seems to exist. BugTraq message
   seems to be a confirmation/advisory, however.
 CHANGE> [Foat changed vote from ACCEPT to NOOP]


CAN-1999-1295

Phase: Modified (20020218-01)
Reference: CERT:VB-96.16
Reference: URL:http://www.cert.org/vendor_bulletins/VB-96.16.transarc
Reference: XF:dfs-login-groups(7154)
Reference: URL:http://xforce.iss.net/static/7154.php

Description:
Transarc DCE Distributed File System (DFS) 1.1 for Solaris 2.4 and 2.5 does not properly initialize the grouplist for users who belong to a large number of groups, which could allow those users to gain access to resources that are protected by DFS.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:dfs-login-groups(7154)


CAN-1999-1296

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970429 vulnerabilities in kerberos
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420878&w=2

Description:
Buffer overflow in Kerberos IV compatibility libraries as used in Kerberos V allows local users to gain root privileges via a long line in a kerberos configuration file, which can be specified via the KRB_CONF environmental variable.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:kerberos-config-file-bo(7184)


CAN-1999-1299

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970203 Linux rcp bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420509&w=2

Description:
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:rcp-nobody-file-overwrite(7187)


CAN-1999-1300

Phase: Proposed (20010912)
Reference: CIAC:B-31
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/b-31.shtml

Description:
Vulnerability in accton in Cray UNICOS 6.1 and 6.0 allows local users to read arbitrary files and modify system accounting configuration.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF: unicos-accton-read-files(7210)


CAN-1999-1302

Phase: Proposed (20010912)
Reference: CIAC:F-05
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml
Reference: SCO:94:001
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml

Description:
Vulnerability in pt_chmod in SCO UNIX 4.2 and earlier allows local users to gain root access.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:sco-pt_chmod(7586)


CAN-1999-1303

Phase: Proposed (20010912)
Reference: CIAC:F-05
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml
Reference: SCO:94:001
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml

Description:
Vulnerability in prwarn in SCO UNIX 4.2 and earlier allows local users to gain root access.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:sco-prwarn(7587)


CAN-1999-1304

Phase: Proposed (20010912)
Reference: CIAC:F-05
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml
Reference: SCO:94:001
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml

Description:
Vulnerability in login in SCO UNIX 4.2 and earlier allows local users to gain root access.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:sco-login(7588)


CAN-1999-1305

Phase: Proposed (20010912)
Reference: CIAC:F-05
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml
Reference: SCO:94:001
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-05.shtml

Description:
Vulnerability in "at" program in SCO UNIX 4.2 and earlier allows local users to gain root access.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:sco-at(7589)


CAN-1999-1306

Phase: Proposed (20010912)
Reference: CERT:CA-1992-20
Reference: URL:http://www.cert.org/advisories/CA-1992-20.html

Description:
Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:cisco-acl-established(1248)
   Possibly duplicate with CVE-1999-0162?
 Christey> Might be a duplicate of CVE-1999-0162, but CVE-1999-0162 was
   released in 1995, whereas this bug was released in 1992.


CAN-1999-1307

Phase: Proposed (20010912)
Reference: BUGTRAQ:19941209 Novell security advisory on sadc, urestore and the suid_exec feature
Reference: URL:http://www.dataguard.no/bugtraq/1994_4/0676.html
Reference: CIAC:F-06
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-06.shtml

Description:
Vulnerability in urestore in Novell UnixWare 1.1 allows local users to gain root privileges.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF;novell-unixware-urestore-root(7211)


CAN-1999-1308

Phase: Modified (20020218-01)
Reference: HP:HPSBUX9611-041
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-91.shtml
Reference: CIAC:H-09
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-09.shtml
Reference: CIAC:H-91
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-91.shtml
Reference: XF:hp-large-uid-gid(7594)
Reference: URL:http://www.iss.net/security_center/static/7594.php

Description:
Certain programs in HP-UX 10.20 do not properly handle large user IDs (UID) or group IDs (GID) over 60000, which could allow local users to gain privileges.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:hp-large-uid-gid(7594)


CAN-1999-1310

Phase: Proposed (20010912)
Reference: CIAC:F-01
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-01.shtml
Reference: SGI:19941001-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19941001-01-P
Reference: MISC:http://www.netsys.com/firewalls/firewalls-9410/0019.html

Description:
/usr/lib/vadmin/serial_ports in SGI IRIX 5.x and earlier trusts the PATH environmental variable to find the ls program, which allows local users to gain root access.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   REJECT(2) Christey, Frech
Voter Comments:
 Frech> DUPE CAN-1999-1022
 Christey> As noted by Andre Frech, this is a duplicate of CAN-1999-1022.
   The references from this candidate will be added to
   CAN-1999-1022.


CAN-1999-1311

Phase: Proposed (20010912)
Reference: HP:HPSBUX9701-046
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-21.shtml
Reference: CIAC:H-21
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/h-21.shtml

Description:
Vulnerability in dtlogin and dtsession in HP-UX 10.20 and 10.10 allows local users to bypass authentication and gain privileges.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:hp-dt-bypass-auth(7668)
   ACKNOWLEDGED-BY-VENDOR


CAN-1999-1312

Phase: Modified (20020218-01)
Reference: CERT:CA-1993-05
Reference: URL:http://www.cert.org/advisories/CA-1993-05.html
Reference: XF:openvms-local-privilege-elevation(7142)
Reference: URL:http://xforce.iss.net/static/7142.php

Description:
Vulnerability in DEC OpenVMS VAX 5.5-2 through 5.0, and OpenVMS AXP 1.0, allows local users to gain system privileges.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:openvms-local-privilege-elevation(7142)


CAN-1999-1313

Phase: Modified (20020218-01)
Reference: CIAC:G-24
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/g-24.shtml
Reference: FREEBSD:FreeBSD-SA-96:11
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:11.man.asc
Reference: XF:bsd-man-command-sequence(7348)
Reference: URL:http://xforce.iss.net/static/7348.php

Description:
Manual page reader (man) in FreeBSD 2.2 and earlier allows local users to gain privileges via a sequence of commands.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:bsd-man-command-sequence(7348)


CAN-1999-1314

Phase: Modified (20020218-01)
Reference: CIAC:G-24
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/g-24.shtml
Reference: FREEBSD:FreeBSD-SA-96:10
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/old/FreeBSD-SA-96:10.mount_union.asc
Reference: XF:unionfs-mount-ordering(7429)
Reference: URL:http://www.iss.net/security_center/static/7429.php

Description:
Vulnerability in union file system in FreeBSD 2.2 and earlier, and possibly other operating systems, allows local users to cause a denial of service (system reload) via a series of certain mount_union commands.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:unionfs-mount-ordering(7429)


CAN-1999-1315

Phase: Proposed (20010912)
Reference: CIAC:F-04
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/f-04.shtml

Description:
Vulnerabilities in DECnet/OSI for OpenVMS before 5.8 on DEC Alpha AXP and VAX/VMS systems allow local users to gain privileges or cause a denial of service.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:openvms-decnetosi-gain-privileges(7212)


CAN-1999-1319

Phase: Modified (20020218-01)
Reference: SGI:19960101-01-PX
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19960101-01-PX
Reference: XF:irix-object-server(7430)
Reference: URL:http://www.iss.net/security_center/static/7430.php

Description:
Vulnerability in object server program in SGI IRIX 5.2 through 6.1 allows remote attackers to gain root privileges in certain configurations.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:irix-object-server(7430)


CAN-1999-1322

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19981112 exchverify.log
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91096758513985&w=2
Reference: NTBUGTRAQ:19981117 Re: exchverify.log - update #1
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91133714919229&w=2
Reference: NTBUGTRAQ:19981125 Re: exchverify.log - update #2
Reference: NTBUGTRAQ:19981216 Arcserve Exchange Client security issue being fixed
Reference: NTBUGTRAQ:19990305 Cheyenne InocuLAN for Exchange plain text password still there
Reference: NTBUGTRAQ:19990426 ArcServe Exchange Client Security Issue still unresolved

Description:
The installation of 1ArcServe Backup and Inoculan AV client modules for Exchange create a log file, exchverify.log, which contains usernames and passwords in plaintext.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1323

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990409 NAV for MS Exchange & Internet Email Gateways
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92370067416739&w=2

Description:
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.

Votes:

   ACCEPT(1) Prosser
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:nav-admin-password(7543)
 Prosser> This has been since corrected in later releases.


CAN-1999-1334

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980129 KSR[T] Advisory #7: filter
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88609666024181&w=2
Reference: CONFIRM:http://www.redhat.com/support/errata/rh50-errata-general.html#elm

Description:
Multiple buffer overflows in filter command in Elm 2.4 allows attackers to execute arbitrary commands via (1) long From: headers, (2) long Reply-To: headers, or (3) via a long -f (filterfile) command line argument.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Armstrong
Voter Comments:
 Frech> XF:elm-filter-getfilterrules-bo(7214)
   XF:elm-filter2(711)


CAN-1999-1338

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990721 Delegate creates directories writable for anyone
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93259112204664&w=2

Description:
Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:delegate-dgroot-permissions(8438)


CAN-1999-1340

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991104 hylafax-4.0.2 local exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94173799532589&w=2
Reference: BID:765
Reference: URL:http://www.securityfocus.com/bid/765

Description:
Buffer overflow in faxalter in hylafax 4.0.2 allows local users to gain privileges via a long -m command line argument.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:hylafax-faxalter-gain-privs(3453)
   Proper spelling of the product is HylaFAX (see
   http://www.hylafax.org/)


CAN-1999-1342

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19991017 ICQ ActiveList Server Exploit...
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94042342010662&w=2

Description:
ICQ ActiveList Server allows remote attackers to cause a denial of service (crash) via malformed packets to the server's UDP port.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:icq-activelist-udp-dos(7877)


CAN-1999-1343

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991013 Xerox DocuColor 4 LP D.O.S
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93986405412867&w=2

Description:
HTTP server for Xerox DocuColor 4 LP allows remote attackers to cause a denial of service (hang) via a long URL that contains a large number of . characters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:xerox-docucolor4lp-dos(8041)


CAN-1999-1344

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991005 Auto_FTP v0.02 Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93923873006014&w=2

Description:
Auto_FTP.pl script in Auto_FTP 0.2 stores usernames and passwords in plaintext in the auto_ftp.conf configuration file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:autoftp-plaintext-password(8045)


CAN-1999-1345

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991005 Auto_FTP v0.02 Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93923873006014&w=2

Description:
Auto_FTP.pl script in Auto_FTP 0.2 uses the /tmp/ftp_tmp as a shared directory with insecure permissions, which allows local users to (1) send arbitrary files to the remote server by placing them in the directory, and (2) view files that are being transferred.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:autoftp-shared-directory(8047)


CAN-1999-1346

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991007 Problems with redhat 6 Xsession and pam.d/rlogin.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93942774609925&w=2

Description:
PAM configuration file for rlogin in Red Hat Linux 6.1 and earlier includes a less restrictive rule before a more restrictive one, which allows users to access the host via rlogin even if rlogin has been explicitly disabled using the /etc/nologin file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:pam-rlogin-bypass(8315)


CAN-1999-1347

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991007 Problems with redhat 6 Xsession and pam.d/rlogin.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93942774609925&w=2

Description:
Xsession in Red Hat Linux 6.1 and earlier can allow local users with restricted accounts to bypass execution of the .xsession file by starting kde, gnome or anotherlevel from kdm.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:xsession-bypass(8316)


CAN-1999-1348

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990630 linuxconf doesn't seem to deal correctly with /etc/pam.d/reboot
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93220073515880&w=2

Description:
Linuxconf on Red Hat Linux 6.0 and earlier does not properly disable PAM-based access to the shutdown command, which could allow local users to cause a denial of service.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:linuxconf-pam-shutdown-dos(8437)


CAN-1999-1349

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991006 Omni-NFS/X Enterprise (nfsd.exe) DOS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93923679004325&w=2

Description:
NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:xlink-nfsd-dos(8317)


CAN-1999-1350

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990929 Multiple Vendor ARCAD permission problems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93871933521519&w=2

Description:
ARCAD Systemhaus 0.078-5 installs critical programs and files with world-writeable permissions, which could allow local users to gain privileges by replacing a program with a Trojan horse.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:arcad-insecure-permissions(8318)


CAN-1999-1352

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990928 Re: [Fwd: Truth about ssh 1.2.27 vulnerabiltiy]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93855134409747&w=2

Description:
mknod in Linux 2.2 follows symbolic links, which could allow local users to overwrite files or gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:mknod-symlink(8319)


CAN-1999-1353

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990907 MsgCore mailserver stores passwords in clear text
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93698162708211&w=2

Description:
Nosque MsgCore 2.14 stores passwords in cleartext: (1) the administrator password in the AdmPasswd registry key, and (2) user passwords in the Userbase.dbf data file, which could allow local users to gain privielges.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:msgcore-plaintext-passwords(8271)
   BUGTRAQ Reference is actually NTBUGTRAQ.


CAN-1999-1354

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990830 SoftArc's FirstClass E-mail Client
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93637687305327&w=2
Reference: NTBUGTRAQ:19990909 SoftArc's FirstClass E-mail Client
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93698283309513&w=2

Description:
E-mail client in Softarc FirstClass Internet Server 5.506 and earlier stores usernames and passwords in cleartext in the files (1) home.fc for version 5.506, (2) network.fc for version 3.5, or (3) FCCLIENT.LOG when logging is enabled.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> (Task 1766)
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:firstclass-plaintext-account(9874)


CAN-1999-1355

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990817 Compaq PFCUser account
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93542118727732&w=2
Reference: NTBUGTRAQ:19990905 Case ID SSRT0620 - PFCUser account communication
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93654336516711&w=2
Reference: NTBUGTRAQ:19990915 (I) UPDATE - PFCUser Account,
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93759822430801&w=2
Reference: NTBUGTRAQ:19991105 UPDATE: SSRT0620 Compaq Foundation Agents v4.40B PFCUser issues
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94183795025294&w=2
Reference: CONFIRM:http://www.compaq.com/products/servers/management/advisory.html
Reference: XF:management-pfcuser(3231)
Reference: URL:http://xforce.iss.net/static/3231.php

Description:
BMC Patrol component, when installed with Compaq Insight Management Agent 4.23 and earlier, or Management Agents for Servers 4.40 and earlier, creates a PFCUser account with a default password and potentially dangerous privileges.

Votes:

   ACCEPT(5) Frech, Foat, Cole, Armstrong, Stracener
   NOOP(1) Wall

CAN-1999-1357

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991005 Time to update those CGIs again
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93915331626185&w=2

Description:
Netscape Communicator 4.04 through 4.7 (and possibly other versions) in various UNIX operating systems converts the 0x8b character to a "<" sign, and the 0x9b character to a ">" sign, which could allow remote attackers to attack other clients via cross-site scripting (CSS) in CGI programs that do not filter these characters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:netscape-cgi-filtering-css(8274)


CAN-1999-1361

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980509 coke.c
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925891&w=2

Description:
Windows NT 3.51 and 4.0 running WINS (Windows Internet Name Service) allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed packets, which causes the server to slow down and fill the event logs with error messages.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:winnt-wins-packet-flood-dos(7329)


CAN-1999-1364

Phase: Modified (20020218-01)
Reference: MSKB:Q142653
Reference: URL:http://support.microsoft.com/support/kb/articles/q142/6/53.asp
Reference: XF:nt-threadcontext-dos(7421)
Reference: URL:http://www.iss.net/security_center/static/7421.php

Description:
Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext.

Votes:

   ACCEPT(3) Wall, Foat, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:nt-threadcontext-dos(7421)


CAN-1999-1365

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990628 NT runs Explorer.exe, Taskmgr.exe etc. from wrong location
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93069418400856&w=2
Reference: NTBUGTRAQ:19990630 Update: NT runs explorer.exe, etc...
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93127894731200&w=2

Description:
Windows NT searches a user's home directory (%systemroot% by default) before other directories to find critical programs such as NDDEAGNT.EXE, EXPLORER.EXE, USERINIT.EXE or TASKMGR.EXE, which could allow local users to bypass access restrictions or gain privileges by placing a Trojan horse program into the root directory, which is writable by default.

Votes:

   ACCEPT(3) Wall, Foat, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:nt-login-default-folder(2336)
 CHANGE> [Foat changed vote from NOOP to ACCEPT]
 Frech> XF:nt-login-default-folder(2336)


CAN-1999-1366

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990515 Pegasus Mail weak encryption
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92714118829880&w=2

Description:
Pegasus e-mail client 3.0 and earlier uses weak encryption to store POP3 passwords in the pmail.ini file, which allows local users to easily decrypt the passwords and read e-mail.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:pegasus-weak-password-encryption(8430)


CAN-1999-1367

Phase: Proposed (20010912)
Reference: MISC:http://www.pcworld.com/news/article/0,aid,10842,00.asp

Description:
Internet Explorer 5.0 does not properly reset the username/password cache for Web sites that do not use standard cache controls, which could allow users on the same system to access restricted web sites that were visited by other users.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (Task 2283)


CAN-1999-1368

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990512 InoculateIT 4.53 Real-Time Exchange Scanner Flawed
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92652152723629&w=2
Reference: NTBUGTRAQ:20001116 InoculateIT AV Option for MS Exchange Server
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=97439568517355&w=2

Description:
AV Option for MS Exchange Server option for InoculateIT 4.53, and possibly other versions, only scans the Inbox folder tree of a Microsoft Exchange server, which could allow viruses to escape detection if a user's rules cause the message to be moved to a different mailbox.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:inoculate-message-redirect-bypass(5602)


CAN-1999-1369

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990414 Real Media Server stores passwords in plain text
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92411181619110&w=2

Description:
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:realserver-insecure-password(7544)


CAN-1999-1370

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990323 MSIE 5 installer disables screen saver
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92220197414799&w=2

Description:
The setup wizard (ie5setup.exe) for Internet Explorer 5.0 disables (1) the screen saver, which could leave the system open to users with physical access if a failure occurs during an unattended installation, and (2) the Task Scheduler Service, which might prevent the scheduled execution of security-critical programs.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:ie-ie5setup-disable-password(7545)


CAN-1999-1371

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990308 Solaris "/usr/bin/write" bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92100752221493&w=2
Reference: MISC:http://www.securiteam.com/exploits/5ZP0O1P35O.html

Description:
Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.

Votes:

   ACCEPT(2) Cole, Dik
   MODIFY(1) Frech
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Frech> XF:solaris-write-bo(7546)
 Christey> This appears to be a rediscovery of the problem for Solaris
   2.8:
   BUGTRAQ:20011114 /usr/bin/write (solaris2.x) Segmentation Fault
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100588255815773&w=2
 Dik> sun bug:  4218941


CAN-1999-1372

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990219 Plaintext Password in Tractive's Remote Manager Software
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91966339502073&w=2

Description:
Triactive Remote Manager with Basic authentication enabled stores the username and password in cleartext in registry keys, which could allow local users to gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:triactive-remote-basic-auth(7548)


CAN-1999-1373

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990105 Re: Network Scan Vulnerability [SUMMARY]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91651770130771&w=2

Description:
FORE PowerHub before 5.0.1 allows remote attackers to cause a denial of service (hang) via a TCP SYN scan with TCP/IP OS fingerprinting, e.g. via nmap.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:powerhub-nmap-dos(7556)


CAN-1999-1374

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990427 Re: Shopping Carts exposing CC data
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92523159819402&w=2

Description:
perlshop.cgi shopping cart program stores sensitive customer information in directories and files that are under the web root, which allows remote attackers to obtain that information via an HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:perlshop-cgi-obtain-information(7557)


CAN-1999-1375

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990211 Using FSO in ASP to view just about anything
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91877455626320&w=2
Reference: BID:230
Reference: URL:http://www.securityfocus.com/bid/230

Description:
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:iis-fso-read-files(7558)


CAN-1999-1376

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990114 MS IIS 4.0 Security Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91632724913080&w=2
Reference: BUGTRAQ:19990114 MS IIS 4.0 Security Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91638375309890&w=2

Description:
Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:frontpage-ext-fpcount-crash(5494)


CAN-1999-1377

Phase: Proposed (20010912)
Reference: MISC:http://pulhas.org/phrack/55/P55-07.html

Description:
Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:download-cgi-directory-traversal(8279)


CAN-1999-1378

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990917 improper chroot in dbmlparser.exe
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93250710625956&w=2

Description:
dbmlparser.exe CGI guestbook program does not perform a chroot operation properly, which allows remote attackers to read arbitrary files.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (Task 2284)


CAN-1999-1381

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981008 buffer overflow in dbadmin
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90786656409618&w=2

Description:
Buffer overflow in dbadmin CGI program 1.0.1 on Linux allows remote attackers to execute arbitrary commands.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1383

Phase: Proposed (20010912)
Reference: BUGTRAQ:19960913 tee see shell problems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419868&w=2
Reference: BUGTRAQ:19960919 Vulnerability in expansion of PS1 in bash & tcsh
Reference: URL:http://www.dataguard.no/bugtraq/1996_3/0503.html

Description:
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.

Votes:

   NOOP(2) Foat, Cole

CAN-1999-1387

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970402 Fatal bug in NT 4.0 server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420731&w=2
Reference: BUGTRAQ:19970403 Fatal bug in NT 4.0 server (more comments)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420732&w=2
Reference: BUGTRAQ:19970407 DUMP of NT system crash
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420741&w=2

Description:
Windows NT 4.0 SP2 allows remote attackers to cause a denial of service (crash), possibly via malformed inputs or packets, such as those generated by a Linux smbmount command that was compiled on the Linux 2.0.29 kernel but executed on Linux 2.0.25.

Votes:

   ACCEPT(1) Cole
   NOOP(1) Foat

CAN-1999-1388

Phase: Proposed (20010912)
Reference: BUGTRAQ:19940513 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994
Reference: URL:http://www2.dataguard.no/bugtraq/1994_2/0197.html
Reference: BUGTRAQ:19940514 [8lgm]-Advisory-7.UNIX.passwd.11-May-1994.NEWFIX
Reference: URL:http://www2.dataguard.no/bugtraq/1994_2/0207.html
Reference: BUGTRAQ:19941218 Sun Patch Id #102060-01
Reference: URL:http://www.dataguard.no/bugtraq/1994_4/0755.html

Description:
passwd in SunOS 4.1.x allows local users to overwrite arbitrary files via a symlink attack and the -F command line argument.

Votes:

   ACCEPT(1) Dik
   NOOP(2) Foat, Cole
Voter Comments:
 Dik> sun bug: 1171499


CAN-1999-1389

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980511 3Com/USR Total Control Chassis dialup port access filters
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925916&w=2
Reference: BID:99
Reference: URL:http://www.securityfocus.com/bid/99

Description:
US Robotics/3Com Total Control Chassis with Frame Relay between 3.6.22 and 3.7.24 does not properly enforce access filters when the "set host prompt" setting is made for a port, which allows attackers to bypass restrictions by providing the hostname twice at the "host: " prompt.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:3com-netserver-filter-bypass(7330)


CAN-1999-1390

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980428 [Debian 2.0] /usr/bin/suidexec gives root access
Reference: URL:http://darwin.bio.uci.edu/~mcoogan/bugtraq/msg00890.html
Reference: BID:94
Reference: URL:http://www.securityfocus.com/bid/94

Description:
suidexec in suidmanager 0.18 on Debian 2.0 allows local users to gain root privileges by specifying a malicious program on the command line.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:suidmanager-suidexec-root-privileges(7304)


CAN-1999-1391

Phase: Modified (20020218-01)
Reference: CERT:CA-1990-06
Reference: URL:http://www.cert.org/advisories/CA-1990-06.html
Reference: CIAC:B-01
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/b-01.shtml
Reference: BID:10
Reference: URL:http://www.securityfocus.com/bid/10
Reference: XF:nextstep-npd-root-access(7143)
Reference: URL:http://www.iss.net/security_center/static/7143.php

Description:
Vulnerability in NeXT 1.0a and 1.0 with publicly accessible printers allows local users to gain privileges via a combination of the npd program and weak directory permissions.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:nextstep-npd-root-access(7143)


CAN-1999-1392

Phase: Modified (20020218-01)
Reference: CERT:CA-1990-06
Reference: URL:http://www.cert.org/advisories/CA-1990-06.html
Reference: CIAC:B-01
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/b-01.shtml
Reference: BID:9
Reference: URL:http://www.securityfocus.com/bid/9
Reference: XF:nextstep-restore09-root-access(7144)
Reference: URL:http://www.iss.net/security_center/static/7144.php

Description:
Vulnerability in restore0.9 installation script in NeXT 1.0a and 1.0 allows local users to gain root privileges.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:nextstep-restore09-root-access(7144)


CAN-1999-1393

Phase: Proposed (20010912)
Reference: MISC:http://freaky.staticusers.net/macsec/data/powerbooksecurity-data.html
Reference: BID:532
Reference: URL:http://www.securityfocus.com/bid/532

Description:
Control Panel "Password Security" option for Apple Powerbooks allows attackers with physical access to the machine to bypass the security by booting it with an emergency startup disk and using a disk editor to modify the on/off toggle or password in the aaaaaaaAPWD file, which is normally inaccessible.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (Task 2285)


CAN-1999-1394

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990702 BSD-fileflags
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93094058620450&w=2
Reference: BID:510
Reference: URL:http://www.securityfocus.com/bid/510

Description:
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append-only flags for files by unmounting the file system and using a file system editor such as fsdb to directly modify the file through a device.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Foat
   REVIEWING(1) Frech
Voter Comments:
 Frech> (Task 2286)


CAN-1999-1395

Phase: Modified (20020218-01)
Reference: CERT:CA-1992-18
Reference: URL:http://www.cert.org/advisories/CA-1992-18.html
Reference: CERT:CA-92.16
Reference: URL:http://www.cert.org/advisories/CA-92.16.VMS.Monitor.vulnerability
Reference: BID:51
Reference: URL:http://www.securityfocus.com/bid/51
Reference: XF:vms-monitor-gain-privileges(7136)
Reference: URL:http://www.iss.net/security_center/static/7136.php

Description:
Vulnerability in Monitor utility (SYS$SHARE:SPISHR.EXE) in VMS 5.0 through 5.4-2 allows local users to gain privileges.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
Voter Comments:
 Frech> XF:vms-monitor-gain-privileges(7136)
   Duplicate of CAN-1999-1056? If not, indicate why in Analysis
   comments.
 Christey> Note that CAN-1999-1056
 Christey> CAN-1999-1056 is in fact a duplicate.  This candidate will
   be kept, and CAN-1999-1056 will be REJECTed, because this
   candidate has more references.


CAN-1999-1396

Phase: Modified (20020218-01)
Reference: CERT:CA-1992-15
Reference: URL:http://www.cert.org/advisories/CA-1992-15.html
Reference: BID:49
Reference: URL:http://www.securityfocus.com/bid/49
Reference: XF:sun-integer-multiplication-access(7150)
Reference: URL:http://www.iss.net/security_center/static/7150.php

Description:
Vulnerability in integer multiplication emulation code on SPARC architectures for SunOS 4.1 through 4.1.2 allows local users to gain root access or cause a denial of service (crash).

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:sun-integer-multiplication-access(7150)
 Dik> sun bug: 1069072 1071053


CAN-1999-1397

Phase: Modified (20020218-01)
Reference: BUGTRAQ:19990323 Index Server 2.0 and the Registry
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92242671024118&w=2
Reference: NTBUGTRAQ:19990323 Index Server 2.0 and the Registry
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92223293409756&w=2
Reference: BID:476
Reference: URL:http://www.securityfocus.com/bid/476
Reference: XF:iis-indexserver-reveal-path(7559)
Reference: URL:http://www.iss.net/security_center/static/7559.php

Description:
Index Server 2.0 on IIS 4.0 stores physical path information in the ContentIndex\Catalogs subkey of the AllowedPaths registry key, whose permissions allows local and remote users to obtain the physical paths of directories that are being indexed.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:iis-indexserver-reveal-path(7559)


CAN-1999-1398

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970507 Irix: misc
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420921&w=2
Reference: MISC:http://www.insecure.org/sploits/irix.xfsdump.html
Reference: BID:472
Reference: URL:http://www.securityfocus.com/bid/472

Description:
Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:irix-xfsdump-symlink(7193)


CAN-1999-1399

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970820 SpaceWare 7.3 v1.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602746719552&w=2
Reference: BID:471
Reference: URL:http://www.securityfocus.com/bid/471

Description:
spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:spaceware-hostname-command-execution(7194)


CAN-1999-1400

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990603 Huge Exploit in NT 4.0 SP5 Screensaver with Password Protection Enabled
Reference: URL:http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0007.html
Reference: NTBUGTRAQ:19990603 Re: Huge Exploit in NT 4.0 SP5 Screensaver with Password Protecti on Enabled.
Reference: URL:http://archives.indenial.com/hypermail/ntbugtraq/1999/June1999/0009.html
Reference: NTBUGTRAQ:19990604 Official response from The Economist re: 1999 Screen Saver
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92851653600852&w=2
Reference: BID:466
Reference: URL:http://www.securityfocus.com/bid/466

Description:
The Economist screen saver 1999 with the "Password Protected" option enabled allows users with physical access to the machine to bypass the screen saver and read files by running Internet Explorer while the screen is still locked.

Votes:

   ACCEPT(1) Wall
   NOOP(2) Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (Task 2287)
   CONFIRM NTBUGTRAQ:19990604 Official response from The
   Economist re: 1999 Screen Saver


CAN-1999-1401

Phase: Modified (20020218-01)
Reference: SGI:19961201-01-PX
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19961201-01-PX
Reference: BID:463
Reference: URL:http://www.securityfocus.com/bid/463
Reference: XF:irix-searchbook-permissions(7575)
Reference: URL:http://www.iss.net/security_center/static/7575.php

Description:
Vulnerability in Desktop searchbook program in IRIX 5.0.x through 6.2 sets insecure permissions for certain user files (iconbook and searchbook).

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:irix-searchbook-permissions(7575)


CAN-1999-1403

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt
Reference: URL:http://www.securityfocus.com/archive/1/10771
Reference: BID:382
Reference: URL:http://www.securityfocus.com/bid/382

Description:
IBM/Tivoli OPC Tracker Agent version 2 release 1 creates files, directories, and IPC message queues with insecure permissions (world-readable and world-writable), which could allow local users to disrupt operations and possibly gain privileges by modifying or deleting files.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1404

Phase: Proposed (20010912)
Reference: BUGTRAQ:19981002 Several potential security problems in IBM/Tivoli OPC Tracker Age nt
Reference: URL:http://www.securityfocus.com/archive/1/10771
Reference: BID:382
Reference: URL:http://www.securityfocus.com/bid/382

Description:
IBM/Tivoli OPC Tracker Agent version 2 release 1 allows remote attackers to cause a denial of service (resource exhaustion) via malformed data to the localtracker client port (5011), which prevents the connection from being closed properly.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1405

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990217 snap utility for AIX.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91936783009385&w=2
Reference: BUGTRAQ:19990220 Re: snap utility for AIX.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91954824614013&w=2
Reference: BID:375
Reference: URL:http://www.securityfocus.com/bid/375

Description:
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove or clear the directory when snap -a is executed, which could allow local users to access the shadowed password file by creating /tmp/ibmsupt/general/passwd before root runs snap -a.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:aix-snap-insecure-tmp(7560)


CAN-1999-1406

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980729 Crash a redhat 5.1 linux box
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526185&w=2
Reference: BUGTRAQ:19980730 FD's 0..2 and suid/sgid procs (Was: Crash a redhat 5.1 linux box)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526192&w=2
Reference: BID:372
Reference: URL:http://www.securityfocus.com/bid/372

Description:
dumpreg in Red Hat Linux 5.1 opens /dev/mem with O_RDWR access, which allows local users to cause a denial of service (crash) by redirecting fd 1 (stdout) to the kernel.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Foat

CAN-1999-1408

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970305 Bug in connect() for aix 4.1.4 ?
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420641&w=2
Reference: BID:352
Reference: URL:http://www.securityfocus.com/bid/352

Description:
Vulnerability in AIX 4.1.4 and HP-UX 10.01 and 9.05 allows local users to cause a denial of service (crash) by using a socket to connect to a port on the localhost, calling shutdown to clear the socket, then using the same socket to connect to a different port on localhost.

Votes:

   MODIFY(1) Frech
   NOOP(3) Christey, Foat, Cole
Voter Comments:
 Frech> XF: aix-hpux-connect-dos(7195)
 Christey> BUGTRAQ:19970307 Re: Bug in connect() ?
   URL:http://www.securityfocus.com/archive/1/Pine.HPP.3.92.970307195408.12139B-100000@wpax13.physik.uni-wuerzburg.de
   BUGTRAQ:19970311 Re: Bug in connect() for aix 4.1.4 ?
   URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=6419


CAN-1999-1410

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970509 Re: Irix: misc
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420927&w=2
Reference: MISC:ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX
Reference: BID:330
Reference: URL:http://www.securityfocus.com/bid/330

Description:
addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.

Votes:

   NOOP(2) Foat, Cole
   REJECT(2) Christey, Frech
Voter Comments:
 Christey> DUPE CAN-1999-1286
   Need to add these references to CAN-1999-1286


CAN-1999-1412

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990603 MacOS X system panic with CGI
Reference: URL:http://www.securityfocus.com/archive/1/14215
Reference: BID:306
Reference: URL:http://www.securityfocus.com/bid/306

Description:
A possible interaction between Apple MacOS X release 1.0 and Apache HTTP server allows remote attackers to cause a denial of service (crash) via a flood of HTTP GET requests to CGI programs, which generates a large number of processes.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (Task 2288)


CAN-1999-1413

Phase: Proposed (20010912)
Reference: BUGTRAQ:19960803 Exploiting Zolaris 2.4 ?? :)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167419549&w=2
Reference: BID:296
Reference: URL:http://www.securityfocus.com/bid/296

Description:
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.

Votes:

   MODIFY(2) Frech, Dik
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:solaris-coredump-symlink(7196)
 Dik> sun bug: 1208241
   
   Also applies to set-uid executables that have made real
   and effective uid identical


CAN-1999-1415

Phase: Proposed (20010912)
Reference: CERT:CA-91.13
Reference: URL:http://www.cert.org/advisories/CA-91.13.Ultrix.mail.vulnerability
Reference: BID:27
Reference: URL:http://www.securityfocus.com/bid/27

Description:
Vulnerability in /usr/bin/mail in DEC ULTRIX before 4.2 allows local users to gain privileges.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
Voter Comments:
 Frech> XF:bsd-binmail(515)
   CA-1991-13 was superseded by CA-1995-02.
 Christey> Is there overlap between CAN-1999-1415 and CAN-1999-1438?
   Both CERT advisories are vague.


CAN-1999-1416

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980823 Solaris ab2 web server is junk
Reference: URL:http://www.securityfocus.com/archive/1/10383
Reference: BID:253
Reference: URL:http://www.securityfocus.com/bid/253

Description:
AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large content-length.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1417

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980823 Solaris ab2 web server is junk
Reference: URL:http://www.securityfocus.com/archive/1/10383
Reference: BID:253
Reference: URL:http://www.securityfocus.com/bid/253

Description:
Format string vulnerability in AnswerBook2 (AB2) web server dwhttpd 3.1a4 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via encoded % characters in an HTTP request, which is improperly logged.

Votes:

   ACCEPT(1) Dik
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Dik> sun bug: 4218283


CAN-1999-1418

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990501 Update: security hole in the ICQ-Webserver
Reference: URL:http://www.securityfocus.com/archive/1/13508
Reference: BID:246
Reference: URL:http://www.securityfocus.com/bid/246

Description:
ICQ99 ICQ web server build 1701 with "Active Homepage" enabled generates allows remote attackers to determine the existence of files on the server by comparing server responses when a file exists ("404 Forbidden") versus when a file does not exist ("404 not found").

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF;icq-webserver-gain-information(8229)
   CONFIRM:http://online.securityfocus.com/archive/1/13655


CAN-1999-1420

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980720 N-Base Vulnerability Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526016&w=2
Reference: BUGTRAQ:19980722 N-Base Vulnerability Advisory Followup
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526065&w=2
Reference: BID:212
Reference: URL:http://www.securityfocus.com/bid/212

Description:
NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Foat

CAN-1999-1421

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980720 N-Base Vulnerability Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526016&w=2
Reference: BUGTRAQ:19980722 N-Base Vulnerability Advisory Followup
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526065&w=2
Reference: BID:212
Reference: URL:http://www.securityfocus.com/bid/212

Description:
NBase switches NH208 and NH215 run a TFTP server which allows remote attackers to send software updates to modify the switch or cause a denial of service (crash) by guessing the target filenames, which have default names.

Votes:

   ACCEPT(2) Foat, Cole
   NOOP(1) Wall

CAN-1999-1422

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990102 PATH variable in zip-slackware 2.0.35
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91540043023167&w=2
Reference: BID:211
Reference: URL:http://www.securityfocus.com/bid/211

Description:
The default configuration of Slackware 3.4, and possibly other versions, includes . (dot, the current directory) in the PATH environmental variable, which could allow local users to create Trojan horse programs that are inadvertently executed by other users.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:linux-path-execute-commands(7561)


CAN-1999-1424

Phase: Proposed (20010912)
Reference: SUN:00145
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/145
Reference: BID:208
Reference: URL:http://www.securityfocus.com/bid/208

Description:
Solaris Solstice AdminSuite (AdminSuite) 2.1 uses unsafe permissions when adding new users to the NIS+ password table, which allows local users to gain root access by modifying their password table entries.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solaris-adminsuite-nisplus-password(7467)
 Dik> sun bug:1237225


CAN-1999-1425

Phase: Proposed (20010912)
Reference: SUN:00145
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/145
Reference: BID:208
Reference: URL:http://www.securityfocus.com/bid/208

Description:
Solaris Solstice AdminSuite (AdminSuite) 2.1 incorrectly sets write permissions on source files for NIS maps, which could allow local users to gain privileges by modifying /etc/passwd.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solaris-adminsuite-password-map-permissions(7468)
 Dik> 1236787


CAN-1999-1426

Phase: Proposed (20010912)
Reference: SUN:00145
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/145
Reference: BID:208
Reference: URL:http://www.securityfocus.com/bid/208

Description:
Solaris Solstice AdminSuite (AdminSuite) 2.1 follows symbolic links when updating an NIS database, which allows local users to overwrite arbitrary files.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solaris-adminsuite-symlink(7469)
 Dik> sun bug: 1262888


CAN-1999-1427

Phase: Proposed (20010912)
Reference: SUN:00145
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/145
Reference: BID:208
Reference: URL:http://www.securityfocus.com/bid/208

Description:
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 create lock files insecurely, which allows local users to gain root privileges.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solaris-adminsuite-lock-file(7470)
 Dik> sun bug: 1262888


CAN-1999-1428

Phase: Proposed (20010912)
Reference: SUN:00145
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/145
Reference: BID:208
Reference: URL:http://www.securityfocus.com/bid/208

Description:
Solaris Solstice AdminSuite (AdminSuite) 2.1 and 2.2 allows local users to gain privileges via the save option in the Database Manager, which is running with setgid bin privileges.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solaris-adminsuite-database-manager(7471)
 Dik> sun bug: 4005611


CAN-1999-1429

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980105 Security flaw in either DIT TransferPro or Solaris
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88419633507543&w=2
Reference: BID:204
Reference: URL:http://www.securityfocus.com/bid/204

Description:
DIT TransferPro installs devices with world-readable and world-writable permissions, which could allow local users to damage disks through the ff device driver.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:transferpro-devices-insecure-permissions(7305)


CAN-1999-1430

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990102 security problem with Royal daVinci
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91540043723185&w=2
Reference: BID:185
Reference: URL:http://www.securityfocus.com/bid/185

Description:
PIM software for Royal daVinci does not properly password-protext access to data stored in the .mdb (Microsoft Access) file, which allows local users to read the data without a password by directly accessing the files with a different application, such as Access.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:davinci-pim-access-information(7562)


CAN-1999-1431

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990107 WinNT, ZAK and Office 97
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91576100022688&w=2
Reference: NTBUGTRAQ:19990109 WinNT, ZAK and Office 97
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91606260910008&w=2
Reference: BID:181
Reference: URL:http://www.securityfocus.com/bid/181

Description:
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:zak-bypass-restrictions(7563)


CAN-1999-1434

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980713 Slackware Shadow Insecurity
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525951&w=2
Reference: BID:155
Reference: URL:http://www.securityfocus.com/bid/155

Description:
login in Slackware Linux 3.2 through 3.5 does not properly check for an error when the /etc/group file is missing, which prevents it from dropping privileges, causing it to assign root privileges to any local user who logs on to the server.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1435

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980710 socks5 1.0r5 buffer overflow..
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525933&w=2
Reference: BID:154
Reference: URL:http://www.securityfocus.com/bid/154

Description:
Buffer overflow in libsocks5 library of Socks 5 (socks5) 1.0r5 allows local users to gain privileges via long environmental variables.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Foat

CAN-1999-1436

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980708 WWW Authorization Gateway
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104525905&w=2
Reference: BID:152
Reference: URL:http://www.securityfocus.com/bid/152

Description:
Ray Chan WWW Authorization Gateway 0.1 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the "user" parameter.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1438

Phase: Proposed (20010912)
Reference: CERT:CA-1991-01
Reference: URL:http://www.cert.org/advisories/CA-91.01a.SunOS.mail.vulnerability
Reference: SUN:00105
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/105
Reference: BID:15
Reference: URL:http://www.securityfocus.com/bid/15

Description:
Vulnerability in /bin/mail in SunOS 4.1.1 and earlier allows local users to gain root privileges via certain command line arguments.

Votes:

   ACCEPT(4) Foat, Cole, Dik, Stracener
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
Voter Comments:
 Frech> XF:bsd-binmail(515)
 Dik> sun bug: 1047340
 Christey> Is there overlap between CAN-1999-1415 and CAN-1999-1438?
   Both CERT advisories are vague.


CAN-1999-1439

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980102 Symlink bug with GCC 2.7.2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88419592307388&w=2
Reference: BUGTRAQ:19980108 GCC Exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88524071002939&w=2
Reference: BUGTRAQ:19980115 GCC 2.7.? /tmp files
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88492937727193&w=2
Reference: BID:146
Reference: URL:http://www.securityfocus.com/bid/146

Description:
gcc 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary .i, .s, or .o files.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:gnu-gcc-tmp-symlink(7338)


CAN-1999-1440

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990101 Win32 ICQ 98a flaw
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91522424302962&w=2
Reference: BID:132
Reference: URL:http://www.securityfocus.com/bid/132

Description:
Win32 ICQ 98a 1.30, and possibly other versions, does not display the entire portion of long filenames, which could allow attackers to send an executable file with a long name that contains so many spaces that the .exe extension is not displayed, which could make the user believe that the file is safe to open from the client.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:icq-long-filename(7564)


CAN-1999-1441

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980630 Serious Linux 2.0.34 security problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103126047&w=2
Reference: BID:111
Reference: URL:http://www.securityfocus.com/bid/111

Description:
Linux 2.0.34 does not properly prevent users from sending SIGIO signals to arbitrary processes, which allows local users to cause a denial of service by sending SIGIO to processes that do not catch it.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:linux-sigio-dos(7339)


CAN-1999-1442

Phase: Proposed (20010912)
Reference: MISC:http://www.cs.helsinki.fi/linux/linux-kernel/Year-1998/1998-25/0816.html
Reference: MISC:http://uwsg.iu.edu/hypermail/linux/kernel/9805.3/0855.html
Reference: BID:105
Reference: URL:http://www.securityfocus.com/bid/105

Description:
Bug in AMD K6 processor on Linux 2.0.x and 2.1.x kernels allows local users to cause a denial of service (crash) via a particular sequence of instructions, possibly related to accessing addresses outside of segments.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:linux-k6-dos(7340)


CAN-1999-1443

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980602 Full Armor.... Fool Proof etc... bugs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125889&w=2
Reference: BUGTRAQ:19980609 Full Armor
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125869&w=2
Reference: BID:103
Reference: URL:http://www.securityfocus.com/bid/103

Description:
Micah Software Full Armor Network Configurator and Zero Administration allow local users with physical access to bypass the desktop protection by (1) using <CTRL><ALT><DEL> and kill the process using the task manager, (2) booting the system from a separate disk, or (3) interrupting certain processes that execute while the system is booting.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:full-armor-protection-bypass(7341)


CAN-1999-1444

Phase: Proposed (20010912)
Reference: MISC:http://catless.ncl.ac.uk/Risks/20.41.html#subj4

Description:
genkey utility in Alibaba 2.0 generates RSA key pairs with an exponent of 1, which results in transactions that are sent in cleartext.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (Task 2290)


CAN-1999-1445

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980202 imapd/ipop3d coredump in slackware 3.4
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=88637951600184&w=2

Description:
Vulnerability in imapd and ipop3d in Slackware 3.4 and 3.3 with shadowing enabled, and possibly other operating systems, allows remote attackers to cause a core dump via a short sequence of USER and PASS commands that do not provide valid usernames or passwords.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:linux-imapd-ipop3d-dos(7345)


CAN-1999-1446

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19970805 Re: Strange behavior regarding directory
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=87602837719654&w=2
Reference: NTBUGTRAQ:19970806 Re: Strange behavior regarding directory
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=87602837719655&w=2

Description:
Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:http-ie-record(524)
   In description, URL's should be URLs.


CAN-1999-1447

Phase: Modified (20020218-01)
Reference: BUGTRAQ:19980728 Object tag crashes Internet Explorer 4.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526169&w=2
Reference: BUGTRAQ:19980730 Re: Object tag crashes Internet Explorer 4.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526188&w=2

Description:
Internet Explorer 4.0 allows remote attackers to cause a denial of service (crash) via HTML code that contains a long CLASSID parameter in an OBJECT tag.

Votes:

   ACCEPT(2) Wall, Cole
   NOOP(2) Christey, Foat
Voter Comments:
 Christey> BUGTRAQ:19980730 Re: Object tag crashes Internet Explorer 4.0
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526188&w=2


CAN-1999-1448

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980729 Eudora exploit (was Microsoft Security Bulletin (MS98-008))
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221104526168&w=2

Description:
Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1449

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970519 /dev/tcx0 crashes SunOS 4.1.4 on Sparc 20's
Reference: URL:http://oamk.fi/~jukkao/bugtraq/before-971202/0498.html
Reference: MISC:http://www.insecure.org/sploits/sunos.dev.tcx0.write.wierd.shit.to.device.bug.html

Description:
SunOS 4.1.4 on a Sparc 20 machine allows local users to cause a denial of service (kernel panic) by reading from the /dev/tcx0 TCX device.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:sun-tcx-dos(7197)


CAN-1999-1450

Phase: Proposed (20010912)
Reference: SCO:SB-99.03b
Reference: URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-99.03b
Reference: SCO:SB-99.06b
Reference: URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-99.06b
Reference: SCO:SSE020
Reference: URL:ftp://ftp.sco.COM/SSE/sse020.ltr
Reference: SCO:SSE023

Description:
Vulnerability in (1) rlogin daemon rshd and (2) scheme on SCO UNIX OpenServer 5.0.5 and earlier, and SCO UnixWare 7.0.1 and earlier, allows remote attackers to gain privileges.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:sco-rshd(7466)
   Correct URLS are listed below:
   Reference: SCO:SSE020
   Reference:
   URL:ftp://stage.caldera.com/pub/security/sse/sse020/sse020.ltr
   Reference: SCO:SSE023
   Reference:
   URL:ftp://stage.caldera.com/pub/security/sse/sse023/sse023.ltr


CAN-1999-1451

Phase: Proposed (20010912)
Reference: MSKB:Q231368
Reference: URL:http://support.microsoft.com/support/kb/articles/q231/3/68.asp
Reference: MS:MS99-013
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-013.asp
Reference: XF:iis-samples-winmsdp(3271)
Reference: URL:http://xforce.iss.net/static/3271.php

Description:
The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(4) Frech, Wall, Foat, Cole

CAN-1999-1453

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990222 New IE4 vulnerability : the clipboard again.
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91979439932341&w=2
Reference: BID:215
Reference: URL:http://www.securityfocus.com/bid/215

Description:
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:webbrowser-activex-view-clipboard(7565)
   REMOVE:http://www.securityfocus.com/bid/215 This reference
   deals with the Forms vulnerability only.


CAN-1999-1454

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991004 Weakness In "The Matrix" Screensaver For Windows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93915027622690&w=2

Description:
Macromedia "The Matrix" screen saver on Windows 95 with the "Password protected" option enabled allows attackers with physical access to the machine to bypass the password prompt by pressing the ESC (Escape) key.

Votes:

   MODIFY(1) Frech
   NOOP(4) Christey, Wall, Foat, Cole
Voter Comments:
 Christey> Looks like there might have been a re-discovery, though the
   exploit is slightly different, and there is insufficient
   detail to be certain that this isn't for a different
   Matrix screen saver:
   BUGTRAQ:20010801 matrix screensvr(16 Bit CineMac Screen Saver Engine) - [input validation error?]
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99669949717618&w=2
   BID:3130
   URL:http://www.securityfocus.com/bid/3130
 Frech> XF:matrix-win95-password-bypass(8280)


CAN-1999-1457

Phase: Proposed (20010912)
Reference: SUSE:19991116 thttpd
Reference: URL:http://www.suse.de/de/support/security/suse_security_announce_30.txt

Description:
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   REJECT(1) Frech

CAN-1999-1458

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990125 Digital Unix 4.0 exploitable buffer overflows
Reference: URL:http://www.securityfocus.com/archive/1/12121
Reference: SCO:SSRT0583U
Reference: URL:http://ftp1.support.compaq.com/public/dunix/v4.0d/ssrt0583u.README
Reference: XF:du-at(3138)
Reference: URL:http://xforce.iss.net/static/3138.php

Description:
Buffer overflow in at program in Digital UNIX 4.0 allows local users to gain root privileges via a long command line argument.

Votes:

   ACCEPT(3) Frech, Foat, Cole
   NOOP(1) Stracener

CAN-1999-1459

Phase: Proposed (20010912)
Reference: ISS:19981102 BMC PATROL File Creation Vulnerability
Reference: URL:http://xforce.iss.net/alerts/advise10.php
Reference: XF:bmc-patrol-file-create(1388)
Reference: URL:http://xforce.iss.net/static/1388.php
Reference: BID:534
Reference: URL:http://www.securityfocus.com/bid/534

Description:
BMC PATROL Agent before 3.2.07 allows local users to gain root privileges via a symlink attack on a temporary file.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> The vendor has acknowledged this vulnerability via e-mail.  It
   has been fixed.
   
   NOTE: despite the fact that this candidate has been acknowledged
   and fixed by the vendor, it is affected by the CVE content
   decision CD:SF-LOC.  It cannot be accepted until the
   CD:SF-LOC guidelines have been finalized.


CAN-1999-1460

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990713 Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93198293132463&w=2
Reference: BUGTRAQ:19990801 Re: Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93372579004129&w=2
Reference: BID:525
Reference: URL:http://www.securityfocus.com/bid/525

Description:
BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying the target file as the second argument to the snmpmagt program.

Votes:

   MODIFY(1) Frech
   NOOP(4) Christey, Wall, Foat, Cole
Voter Comments:
 Frech> XF:patrol-snmp-file-creation(2347)
 Christey> The vendor has acknowledged this vulnerability via e-mail.  It
   has been fixed.
   
   NOTE: despite the fact that this candidate has been acknowledged
   and fixed by the vendor, it is affected by the CVE content
   decision CD:SF-LOC.  It cannot be accepted until the
   CD:SF-LOC guidelines have been finalized.


CAN-1999-1461

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970507 Irix: misc
Reference: URL:http://www.securityfocus.com/archive/1/6702
Reference: SGI:20001101-01-I
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20001101-01-I
Reference: BID:381
Reference: URL:http://www.securityfocus.com/bid/381

Description:
inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   REJECT(1) Frech
Voter Comments:
 Frech> Possible conflict with CVE-2000-0799.


CAN-1999-1462

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990426 FW: Security Notice: Big Brother 1.09b/c
Reference: URL:http://www.securityfocus.com/archive/1/13440
Reference: CONFIRM:http://bb4.com/README.CHANGES
Reference: BID:142
Reference: URL:http://www.securityfocus.com/bid/142
Reference: XF:http-cgi-bigbrother-bbhist(3755)
Reference: URL:http://xforce.iss.net/static/3755.php

Description:
Vulnerability in bb-hist.sh CGI History module in Big Brother 1.09b and 1.09c allows remote attacker to read portions of arbitrary files.

Votes:

   ACCEPT(5) Frech, Foat, Cole, Armstrong, Stracener
   NOOP(1) Wall

CAN-1999-1463

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970710 A New Fragmentation Attack
Reference: URL:http://www.securityfocus.com/archive/1/7219
Reference: XF:nt-frag(528)
Reference: URL:http://xforce.iss.net/static/528.php

Description:
Windows NT 4.0 before SP3 allows remote attackers to bypass firewall restrictions or cause a denial of service (crash) by sending improperly fragmented IP packets without the first fragment, which the TCP/IP stack incorrectly reassembles into a valid session.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(1) Foat
Voter Comments:
 Frech> This issue is also listed under CAN-1999-0226.


CAN-1999-1464

Phase: Proposed (20010912)
Reference: CISCO:19981105 Cisco IOS DFS Access List Leakage
Reference: URL:http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml
Reference: CIAC:J-016
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/j-016.shtml
Reference: XF:cisco-acl-leakage(1401)
Reference: URL:http://xforce.iss.net/static/1401.php

Description:
Vulnerability in Cisco IOS 11.1CC and 11.1CT with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled interface to an interface that does not have DFS enabled, as described by Cisco bug CSCdk35564.

Votes:

   ACCEPT(6) Frech, Balinsky, Foat, Cole, Armstrong, Stracener
   NOOP(1) Wall

CAN-1999-1465

Phase: Modified (20020228-01)
Reference: CISCO:19981105 Cisco IOS DFS Access List Leakage
Reference: URL:http://www.cisco.com/warp/public/770/iosdfsacl-pub.shtml
Reference: CIAC:J-016
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/j-016.shtml
Reference: XF:cisco-acl-leakage(1401)
Reference: URL:http://xforce.iss.net/static/1401.php

Description:
Vulnerability in Cisco IOS 11.1 through 11.3 with distributed fast switching (DFS) enabled allows remote attackers to bypass certain access control lists when the router switches traffic from a DFS-enabled input interface to an output interface with a logical subinterface, as described by Cisco bug CSCdk43862.

Votes:

   ACCEPT(6) Frech, Balinsky, Foat, Cole, Armstrong, Stracener
   NOOP(1) Wall

CAN-1999-1466

Phase: Proposed (20010912)
Reference: CERT:CA-1992-20
Reference: URL:http://www.cert.org/advisories/CA-1992-20.html
Reference: BID:53
Reference: URL:http://www.securityfocus.com/bid/53

Description:
Vulnerability in Cisco routers versions 8.2 through 9.1 allows remote attackers to bypass access control lists when extended IP access lists are used on certain interfaces, the IP route cache is enabled, and the access list uses the "established" keyword.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
Voter Comments:
 Frech> XF:cisco-acl-established(1248)
   Possible dupe with CVE-1999-0162.
 Christey> This is not a dupe with CVE-1999-0162.  The Cisco advisory
   referenced in CVE-1999-0162 says that affected Cisco versions
   are 10.0 through 10.3.  This CAN deals with versions 8.2
   through 9.1.  In addition, the date of release of
   CVE-1999-0162 is June 1995; this CAN was released December
   1992.  Both items include clear Cisco acknowledgement with
   details, so we should conclude that  they are separate
   problems, despite the vagueness of the reports.


CAN-1999-1467

Phase: Proposed (20010912)
Reference: CERT:CA-1989-07
Reference: URL:http://www.cert.org/advisories/CA-1989-07.html
Reference: BID:5
Reference: URL:http://www.securityfocus.com/bid/5
Reference: XF:sun-rcp(3165)
Reference: URL:http://xforce.iss.net/static/3165.php

Description:
Vulnerability in rcp on SunOS 4.0.x allows remote attackers from trusted hosts to execute arbitrary commands as root, possibly related to the configuration of the nobody user.

Votes:

   ACCEPT(5) Frech, Foat, Cole, Dik, Stracener
   NOOP(1) Wall
Voter Comments:
 Dik> sun bug: 1028958


CAN-1999-1469

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990930 mini-sql Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93871926821410&w=2

Description:
Buffer overflow in w3-auth CGI program in miniSQL package allows remote attackers to execute arbitrary commands via an HTTP request with (1) a long URL, or (2) a long User-Agent MIME header.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:msql-w3auth-bo(8301)


CAN-1999-1470

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990624 Eastman Software Work Management 3.21
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93034788412494&w=2
Reference: XF:eastman-cleartext-passwords(2303)
Reference: URL:http://xforce.iss.net/static/2303.php
Reference: BID:485
Reference: URL:http://www.securityfocus.com/bid/485

Description:
Eastman Work Management 3.21 stores passwords in cleartext in the COMMON and LOCATOR registry keys, which could allow local users to gain privileges.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1471

Phase: Modified (20020218-01)
Reference: CERT:CA-1989-01
Reference: URL:http://www.cert.org/advisories/CA-1989-01.html
Reference: BID:4
Reference: URL:http://www.securityfocus.com/bid/4
Reference: XF:bsd-passwd-bo(7152)
Reference: URL:http://www.iss.net/security_center/static/7152.php

Description:
Buffer overflow in passwd in BSD based operating systems 4.3 and earlier allows local users to gain root privileges by specifying a long shell or GECOS field.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:bsd-passwd-bo(7152)


CAN-1999-1474

Phase: Proposed (20010912)
Reference: CONFIRM:http://www.microsoft.com/windows/ie/security/powerpoint.asp
Reference: XF:nt-ppt-patch(179)
Reference: URL:http://xforce.iss.net/static/179.php

Description:
PowerPoint 95 and 97 allows remote attackers to cause an application to be run automatically without prompting the user, possibly through the slide show, when the document is opened in browsers such as Internet Explorer.

Votes:

   ACCEPT(6) Frech, Wall, Foat, Cole, Armstrong, Stracener
Voter Comments:
 Frech> Looks like CONFIRM URL is too old for Microsoft to keep
   (currently cached at
   http://www.google.com/search?q=cache:86loHcRhaL4:www.microsoft.com/ie/
   security/powerpoint.htm+%22PowerPoint+Browsing+Security+Issue%22&hl=en
   ). Same information is available at BugTraq at
   http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=6724


CAN-1999-1475

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991119 ProFTPd - mod_sqlpw.c
Reference: URL:http://www.securityfocus.com/archive/1/35483
Reference: BID:812
Reference: URL:http://www.securityfocus.com/bid/812

Description:
ProFTPd 1.2 compiled with the mod_sqlpw module records user passwords in the wtmp log file, which allows local users to obtain the passwords and gain privileges by reading wtmp, e.g. via the last command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:proftpd-modsqlpw-insecure-passwords(8332)


CAN-1999-1477

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990923 Linux GNOME exploit
Reference: URL:http://www.securityfocus.com/archive/1/28717
Reference: BID:663
Reference: URL:http://www.securityfocus.com/bid/663
Reference: XF:gnome-espeaker-local-bo(3349)
Reference: URL:http://xforce.iss.net/static/3349.php

Description:
Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in programs such as nethack.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1479

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980624 textcounter.pl SECURITY HOLE
Reference: URL:http://www.securityfocus.com/archive/1/9609
Reference: XF:http-cgi-textcounter(2052)
Reference: URL:http://xforce.iss.net/static/2052.php

Description:
The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1480

Phase: Proposed (20010912)
Reference: BID:429
Reference: URL:http://www.securityfocus.com/bid/429

Description:
(1) acledit and (2) aclput in AIX 4.3 allow local users to create or modify files via a symlink attack.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:aix-acledit-aclput-symlink(7346)
   CONFIRM:APAR IX79139


CAN-1999-1482

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990219 Security hole: "zgv"
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=1999-02-15&msg=Pine.LNX.3.96.990219175605.9622A-100000@ferret.lmh.ox.ac.uk

Description:
SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:zgv-privilege-leak(1798)


CAN-1999-1483

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970619 svgalib/zgv
Reference: URL:http://www.securityfocus.com/archive/1/7041

Description:
Buffer overflow in zgv in svgalib 1.2.10 and earlier allows local users to execute arbitrary code via a long HOME environment variable.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF;linux-svgalib-dos(3412)


CAN-1999-1484

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990924 Several ActiveX Buffer Overruns
Reference: URL:http://www.securityfocus.com/archive/1/28719
Reference: XF:msn-setup-bbs-activex-bo(3310)
Reference: URL:http://xforce.iss.net/static/3310.php
Reference: BID:668
Reference: URL:http://www.securityfocus.com/bid/668

Description:
Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1485

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990531 IRIX 6.5 nsd virtual filesystem vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/13999
Reference: XF:sgi-nsd-view(2246)
Reference: URL:http://xforce.iss.net/static/2246.php
Reference: XF:sgi-nsd-create(2247)
Reference: URL:http://xforce.iss.net/static/2247.php
Reference: BID:412
Reference: URL:http://www.securityfocus.com/bid/412

Description:
nsd in IRIX 6.5 through 6.5.2 exports a virtual filesystem on a UDP port, which allows remote attackers to view files and cause a possible denial of service by mounting the nsd virtual file system.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1486

Phase: Proposed (20010912)
Reference: BID:408
Reference: URL:http://www.securityfocus.com/bid/408
Reference: AIXAPAR:IX75554
Reference: AIXAPAR:IX76853
Reference: AIXAPAR:IX76330

Description:
sadc in IBM AIX 4.1 through 4.3 allows local users to overwrite files via a symlink attack.

Votes:

   ACCEPT(4) Bollinger, Foat, Cole, Stracener
   NOOP(1) Christey
Voter Comments:
 Christey> The description needs to be modified to mention the role of
   timex.  The one-line description for the IX75554
   APAR mentions timex instead of sadc, but the BID mentions
   sadc and not timex.  This apparent discrepancy is resolved
   by a README file for the fileset that is used by IX75554:
   
   CONFIRM:http://techsupport.services.ibm.com/aix/fixes/v4/os/bos.acct.4.3.1.0.info
   
   This clearly shows the relationship between timex and sadc.
 Bollinger> The one line abstract is somewhat misleading.  The timex
   command calls sadc with a filename and it's the sadc command that can
   be tricked into modifying files owned by the adm group.  Since sadc is
   only executable by group adm, a local attacker would need to use timex
   to exploit this.  (timex is setgid adm.)  So the vulnerability is
   really in sadc and that's where the fix was made.


CAN-1999-1487

Phase: Modified (20020218-01)
Reference: AIXAPAR:IX74599
Reference: URL:http://www-1.ibm.com/servlet/support/manager?rt=0&rs=0&org=apars&doc=41D8B61D1E1C4FAB852567C9002C546C
Reference: BID:405
Reference: URL:http://www.securityfocus.com/bid/405
Reference: XF:aix-digest(7477)
Reference: URL:http://www.iss.net/security_center/static/7477.php

Description:
Vulnerability in digest in AIX 4.3 allows printq users to gain root privileges by creating and/or modifing any file on the system.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:aix-digest(7477)


CAN-1999-1489

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970304 Linux SuperProbe exploit
Reference: URL:http://www.securityfocus.com/archive/1/6384
Reference: BID:364
Reference: URL:http://www.securityfocus.com/bid/364

Description:
Buffer overflow in TestChip function in XFree86 SuperProbe in Slackware Linux 3.1 allows local users to gain root privileges via a long -nopr argument.

Votes:

   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:xfree86-superprobe-testchip-bo(7198)


CAN-1999-1491

Phase: Proposed (20010912)
Reference: BUGTRAQ:19960202 abuse Red Hat 2.1 security hole
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167418994&w=2
Reference: BID:354
Reference: URL:http://www.securityfocus.com/bid/354

Description:
abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to execute arbitrary commands via a path that points to a Trojan horse program.

Votes:

   ACCEPT(1) Cole
   NOOP(1) Foat

CAN-1999-1492

Phase: Proposed (20010912)
Reference: SGI:19980502-01-P3030
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/19980502-01-P3030
Reference: XF:sgi-diskalign(2104)
Reference: URL:http://xforce.iss.net/static/2104.php
Reference: XF:sgi-diskperf(2103)
Reference: URL:http://xforce.iss.net/static/2103.php
Reference: BID:348
Reference: URL:http://www.securityfocus.com/bid/348

Description:
Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Stracener

CAN-1999-1493

Phase: Modified (20020308-01)
Reference: CERT:CA-1991-23
Reference: URL:http://www.cert.org/advisories/CA-1991-23.html
Reference: BID:34
Reference: URL:http://www.securityfocus.com/bid/34
Reference: XF:apollo-crp-root-access(7158)
Reference: URL:http://xforce.iss.net/static/7158.php

Description:
Vulnerability in crp in Hewlett Packard Apollo Domain OS SR10 through SR10.3 allows remote attackers to gain root privileges via insecure system calls, (1) pad_$dm_cmd and (2) pad_$def_pfk().

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:apollo-crp-root-access(7158)


CAN-1999-1495

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990218 xtvscreen and suse 6
Reference: URL:http://www.securityfocus.com/archive/1/12580
Reference: XF:xtvscreen-overwrite(1792)
Reference: URL:http://xforce.iss.net/static/1792.php
Reference: BID:325
Reference: URL:http://www.securityfocus.com/bid/325

Description:
xtvscreen in SuSE Linux 6.0 allows local users to overwrite arbitrary files via a symlink attack on the pic000.pnm file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1496

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990608 unneeded information in sudo
Reference: URL:http://www.securityfocus.com/archive/1/14665
Reference: BID:321
Reference: URL:http://www.securityfocus.com/bid/321
Reference: XF:sudo-file-exists(2277)
Reference: URL:http://xforce.iss.net/static/2277.php

Description:
Sudo 1.5 in Debian Linux 2.1 and Red Hat 6.0 allows local users to determine the existence of arbitrary files by attempting to execute the target filename as a program, which generates a different error message when the file does not exist.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1497

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991221 [w00giving '99 #11] IMail's password encryption scheme
Reference: URL:http://www.securityfocus.com/archive/1/39329
Reference: BID:880
Reference: URL:http://www.securityfocus.com/bid/880

Description:
Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to to read passwords for e-mail accounts.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:imail-passwords(1901)
   May be the same as CAN-2000-0019 on a different level of
   abstraction.


CAN-1999-1498

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980406 insecure tmp file creation
Reference: BID:82
Reference: URL:http://www.securityfocus.com/bid/82

Description:
Slackware Linux 3.4 pkgtool allows local attacker to read and write to arbitrary files via a symlink attack on the reply file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:linux-pkgtool-reply-symlink(7347) 


CAN-1999-1499

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980410 BIND 4.9.7 named follows symlinks, clobbers anything
Reference: URL:http://www.securityfocus.com/archive/1/8966
Reference: BID:80
Reference: URL:http://www.securityfocus.com/bid/80

Description:
named in ISC BIND 4.9 and 8.1 allows local users to destroy files via a symlink attack on (1) named_dump.db when root kills the process with a SIGINT, or (2) named.stats when SIGIOT is used.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REJECT(1) Foat
Voter Comments:
 Foat> The files get written to /var/named which the user does not have write 
   access.
 Frech> XF:bind-sigint-sigiot-symlink(7366)


CAN-1999-1500

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19991001 Vulnerabilities in the Internet Anywhere Mail Server
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93880357530599&w=2
Reference: BID:733
Reference: URL:http://www.securityfocus.com/bid/733

Description:
Internet Anywhere POP3 Mail Server 2.3.1 allows remote attackers to cause a denial of service (crash) via (1) LIST, (2) TOP, or (3) UIDL commands using letters as arguments.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:iams-pop3-command-dos(3283)


CAN-1999-1501

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980408 SGI O2 ipx security issue
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=19980408184855.12506@math.princeton.edu
Reference: BID:70
Reference: URL:http://www.securityfocus.com/bid/70
Reference: BID:71
Reference: URL:http://www.securityfocus.com/bid/71

Description:
(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REJECT(1) Christey
Voter Comments:
 Frech> XF:irix-ipxchk-ipxlink-ifs-commands(7365)
 Christey> DUPE CAN-1999-1040


CAN-1999-1502

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980408 QuakeI client: serious holes.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=89205623028934&w=2
Reference: BID:68
Reference: URL:http://www.securityfocus.com/bid/68
Reference: BID:69
Reference: URL:http://www.securityfocus.com/bid/69

Description:
Buffer overflows in Quake 1.9 client allows remote malicious servers to execute arbitrary commands via long (1) precache paths, (2) server name, (3) server address, or (4) argument to the map console command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:quake-precache-bo(7358)
   XF:quake-server-address-bo(7359)
   XF:quake-map-argument-bo(7360)


CAN-1999-1503

Phase: Proposed (20010912)
Reference: BID:63
Reference: URL:http://www.securityfocus.com/bid/63

Description:
Network Flight Recorder (NFR) 1.5 and 1.6 allows remote attackers to cause a denial of service in nfrd (crash) via a TCP packet with a null header and data field.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:nfr-tcp-packet-dos(7357)


CAN-1999-1504

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980408 Re: AppleShare IP Mail Server
Reference: URL:http://www.securityfocus.com/archive/1/8951
Reference: BID:62
Reference: URL:http://www.securityfocus.com/bid/62

Description:
Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:smtp-helo-bo(886)


CAN-1999-1505

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980407 QW vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=89200537415923&w=2
Reference: BID:60
Reference: URL:http://www.securityfocus.com/bid/60

Description:
Buffer overflow in QuakeWorld 2.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary commands via a long initial connect packet.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:quakeworld-connect-bo(7356)


CAN-1999-1506

Phase: Proposed (20010912)
Reference: CERT:CA-1990-01
Reference: URL:http://www.cert.org/advisories/CA-90.01.sun.sendmail.vulnerability
Reference: BID:6
Reference: URL:http://www.securityfocus.com/bid/6

Description:
Vulnerability in SMI Sendmail 4.0 and earlier, on SunOS up to 4.0.3, allows remote attackers to access user bin.

Votes:

   ACCEPT(3) Cole, Dik, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:sunos-sendmail-bin-access(7161)
 Dik> sun bug 1028173
 CHANGE> [Foat changed vote from ACCEPT to NOOP]


CAN-1999-1508

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991116 [Fwd: Printer Vulnerability: Tektronix PhaserLink Webserver gives Administrator Password]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94286041430870&w=2
Reference: BID:806
Reference: URL:http://www.securityfocus.com/bid/806

Description:
Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:tektronix-phaserlink-webserver-backdoor(6482)
   Possible dupe with CAN-2001-0484 and BID-2659.
 Christey> CAN-2001-0484 may be a duplicate.


CAN-1999-1509

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94177470915423&w=2
Reference: BUGTRAQ:19991104 Eserv 2.50 Web interface Server Directory Traversal Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94183041514522&w=2
Reference: BID:773
Reference: URL:http://www.securityfocus.com/bid/773
Reference: XF:eserv-fileread

Description:
Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> Normalize XF:eserv-fileread(3449)
   Normalize URL:http://xforce.iss.net/static/3449.php


CAN-1999-1510

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990517 Vulnerabilities in BisonWare FTP Server 3.5
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=92697301706956&w=2
Reference: XF:bisonware-command-bo(3234)
Reference: URL:http://xforce.iss.net/static/3234.php

Description:
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.

Votes:

   ACCEPT(3) Frech, Foat, Cole
   NOOP(1) Wall

CAN-1999-1511

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991110 Multiples Remotes DoS Attacks in Artisoft XtraMail v1.11 Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94226003804744&w=2
Reference: BID:791
Reference: URL:http://www.securityfocus.com/bid/791
Reference: XF:xtramail-pass-dos(3488)
Reference: URL:http://xforce.iss.net/static/3488.php

Description:
Buffer overflows in Xtramail 1.11 allow attackers to cause a denial of service (crash) and possibly execute arbitrary commands via (1) a long PASS command in the POP3 service, (2) a long HELO command in the SMTP service, or (3) a long user name in the Control Service.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1513

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990830 One more 3Com SNMP vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93616983223090&w=2

Description:
Management information base (MIB) for a 3Com SuperStack II hub running software version 2.10 contains an object identifier (.1.3.6.1.4.1.43.10.4.2) that is accessible by a read-only community string, but lists the entire table of community strings, which could allow attackers to conduct unauthorized activities.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (ACCEPT; Task 2355)


CAN-1999-1514

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94130292519646&w=2
Reference: BUGTRAQ:19990729 ExpressFS 2.x FTPServer remotely exploitable buffer overflow vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94121377716133&w=2
Reference: BID:749
Reference: URL:http://www.securityfocus.com/bid/749
Reference: XF:expressfs-command-bo(3401)
Reference: URL:http://xforce.iss.net/static/3401.php

Description:
Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> BugTraq reference date seems to be 19991029; see
   http://online.securityfocus.com/archive/1/33123


CAN-1999-1515

Phase: Proposed (20010912)
Reference: BID:613
Reference: URL:http://www.securityfocus.com/bid/613
Reference: XF:tfs-gateway-dos(3290)
Reference: URL:http://xforce.iss.net/static/3290.php

Description:
A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1516

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990902 [SECURITY] TenFour TFS SMTP 3.2 Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93677241318492&w=2

Description:
A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:tfs-gateway-dos(3290)


CAN-1999-1517

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991101 Amanda multiple vendor local root compromises
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94148942818975&w=2
Reference: BID:750
Reference: URL:http://www.securityfocus.com/bid/750

Description:
runtar in the Amanda backup system used in various UNIX operating systems executes tar with root privileges, which allows a user to overwrite or read arbitrary files by providing the target files to runtar.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:amanda-runtar(3402)


CAN-1999-1518

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990715 Shared memory DoS's
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93207728118694&w=2
Reference: BID:526
Reference: URL:http://www.securityfocus.com/bid/526
Reference: XF:bsd-shared-memory-dos(2351)
Reference: URL:http://xforce.iss.net/static/2351.php

Description:
Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service and bypass memory limits (e.g., as specified with rlimits) using mmap or shmget to allocate memory and cause page faults.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1519

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991117 Remote D.o.S Attack in G6 FTP Server v2.0 (beta 4/5) Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94286244700573&w=2
Reference: BID:805
Reference: URL:http://www.securityfocus.com/bid/805
Reference: XF:g6ftp-username-dos(3513)
Reference: URL:http://xforce.iss.net/static/3513.php

Description:
Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1520

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990511 [ALERT] Site Server 3.0 May Expose SQL IDs and PSWs
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92647407227303&w=2
Reference: BID:256
Reference: URL:http://www.securityfocus.com/bid/256
Reference: XF:siteserver-site-csc(2270)
Reference: URL:http://xforce.iss.net/static/2270.php

Description:
In Microsoft Site Server 3.0 a configuration problem exists in the Ad Server Sample directory (AdSamples) allowing an attacker to retrieve SITE.CSC, exposing sensitive SQL database information.

Votes:

   ACCEPT(3) Frech, Wall, Cole
   NOOP(1) Foat

CAN-1999-1521

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990912 Many kind of POP3/SMTP server softwares for Windows have buffer overflow bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93720402717560&w=2
Reference: BUGTRAQ:19990729 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94121824921783&w=2
Reference: BID:633
Reference: URL:http://www.securityfocus.com/bid/633
Reference: XF:cmail-command-bo(2240)
Reference: URL:http://xforce.iss.net/static/2240.php

Description:
Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command that may allow a remote attacker to execute arbitrary code on the server.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Christey, Wall, Foat, Cole
Voter Comments:
 Christey> Remove "attack" from description and slightly rewrite.
 Christey> ADDREF BUGTRAQ:19991029 Vulnerability in CMail SMTP Server Version 2.4: Remotely exploitable buffer
   URL:URL:http://www.securityfocus.com/archive/1/32573 
   ADDREF BUGTRAQ:19990616 C-Mail SMTP Server Remote Buffer Overflow Exploit
   URL:http://online.securityfocus.com/archive/1/15524
   
   Note: this last post exploits an overflow through VRFY
   instead of MAIL FROM.  However, CD:SF-LOC suggests merging two
   issues of the same type that are in the same versions.
   
   ADDREF BUGTRAQ:19990526 Multiple Web Interface Security Holes
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92774425211457&w=2


CAN-1999-1522

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991007 Roxen security alert
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93942579008408&w=2

Description:
Vulnerability in htmlparse.pike in Roxen Web Server 1.3.11 and earlier, possibly related to recursive parsing and referer tags in RXML.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:roxen-rxml-recursive-parsing(3372)


CAN-1999-1523

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991004
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93901161727373&w=2
Reference: BUGTRAQ:19991006 Re: Sample DOS against the Sambar HTTP-Server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93941351229256&w=2
Reference: XF:sambar-logging-bo(1672)
Reference: URL:http://xforce.iss.net/static/1672.php

Description:
Buffer overflow in Sambar Web Server 4.2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1524

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990807 Re: FlowPoint DSL router vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93424680430460&w=2

Description:
FlowPoint DSL router firmware versions prior to 3.0.8 allows a remote attacker to exploit a password recovery feature from the network and conduct brute force password guessing, instead of limiting the feature to the serial console port.

Votes:

   NOOP(3) Wall, Foat, Cole

CAN-1999-1525

Phase: Proposed (20010912)
Reference: BUGTRAQ:19970314 Shockwave Security Alert
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=87602167420670&w=2
Reference: XF:shockwave-internal-access(1585)
Reference: URL:http://xforce.iss.net/static/1585.php
Reference: XF:shockwave-file-read-vuln(1586)
Reference: URL:http://xforce.iss.net/static/1586.php
Reference: XF:http-ns-shockwave(460)
Reference: URL:http://xforce.iss.net/static/460.php

Description:
Macromedia Shockwave before 6.0 allows a malicious webmaster to read a user's mail box and possibly access internal web servers via the GetNextText command on a Shockwave movie.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1526

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990311 [Fwd: Shockwave 7 Security Hole]
Reference: URL:http://www.securityfocus.com/archive/1/12842
Reference: XF:shockwave-updater(1931)
Reference: URL:http://xforce.iss.net/static/1931.php

Description:
Auto-update feature of Macromedia Shockwave 7 transmits a user's password and hard disk information back to Macromedia.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Foat, Cole

CAN-1999-1527

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991123 NetBeans/ Forte' Java IDE HTTP vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94338883114254&w=2
Reference: BID:816
Reference: URL:http://www.securityfocus.com/bid/816

Description:
Internal HTTP server in Sun Netbeans Java IDE in Netbeans Developer 3.0 Beta and Forte Community Edition 1.0 Beta does not properly restrict access to IP addresses as specified in its configuration, which allows arbitrary remote attackers to access the server.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:sun-java-ide-http-access(8333)


CAN-1999-1528

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991114 MacOS 9 and the MacOS Netware Client
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94261444428430&w=2
Reference: BID:794
Reference: URL:http://www.securityfocus.com/bid/794

Description:
ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:macos-netware-nds-access(8339)


CAN-1999-1529

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94201512111092&w=2
Reference: NTBUGTRAQ:19991107 Interscan VirusWall NT 3.23/3.3 buffer overflow.
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94199707625818&w=2
Reference: BUGTRAQ:19991108 Re: Interscan VirusWall NT 3.23/3.3 buffer overflow.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94210427406568&w=2
Reference: BUGTRAQ:19991108 Patch for VirusWall 3.23.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94204166130782&w=2
Reference: NTBUGTRAQ:19991108 Patch for VirusWall 3.23.
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94208143007829&w=2
Reference: BUGTRAQ:20000417 New DOS on Interscan NT/3.32
Reference: URL:http://www.securityfocus.com/archive/1/55551
Reference: BID:787
Reference: URL:http://www.securityfocus.com/bid/787
Reference: XF:viruswall-helo-bo(3465)
Reference: URL:http://xforce.iss.net/static/3465.php

Description:
A buffer overflow exists in the HELO command in Trend Micro Interscan VirusWall SMTP gateway 3.23/3.3 for NT, which may allow an attacker to execute arbitrary code.

Votes:

   ACCEPT(2) Foat, Cole
   NOOP(1) Wall
   REJECT(1) Frech

CAN-1999-1532

Phase: Modified (20011126-01)
Reference: BUGTRAQ:19991029 message:Netscape Messaging Server RCPT TO vul.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94117465014255&w=2
Reference: BID:748
Reference: URL:http://www.securityfocus.com/bid/748

Description:
Netscape Messaging Server 3.54, 3.55, and 3.6 allows a remote attacker to cause a denial of service (memory exhaustion) via a series of long RCPT TO commands.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:netscape-messaging-rcptto-dos(8340)
   Description ends with a comma and not a period, possibly 
   indicating that the sentence is not complete,


CAN-1999-1533

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990926 DoS Exploit in Eicon Diehl LAN ISDN Modem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93846522511387&w=2
Reference: BID:665
Reference: URL:http://www.securityfocus.com/bid/665
Reference: XF:diva-lan-isdn-dos(3317)
Reference: URL:http://xforce.iss.net/static/3317.php

Description:
Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password argument to the login.htm file in its HTTP service.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1534

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990923 Multiple vendor Knox Arkiea local root/remote DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93837184228248&w=2
Reference: BID:661
Reference: URL:http://www.securityfocus.com/bid/661

Description:
Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root access via a long HOME environmental variable.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:arkiea-backup-home-bo(3322)


CAN-1999-1536

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990730 World writable root owned script in SalesBuilder (RedHat 6.0)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93347785827287&w=2
Reference: BID:560
Reference: URL:http://www.securityfocus.com/bid/560

Description:
.sbstart startup script in AcuShop Salesbuilder is world writable, which allows local users to gain privileges by appending commands to the file.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (ACCEPT; Task 2356)


CAN-1999-1537

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19990707 SSL and IIS.
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=93138827329577&w=2
Reference: BID:521
Reference: URL:http://www.securityfocus.com/bid/521
Reference: XF:ssl-iis-dos(2352)
Reference: URL:http://xforce.iss.net/static/2352.php

Description:
IIS 3.x and 4.x does not distinguish between pages requiring encryption and those that do not, which allows remote attackers to cause a denial of service (resource exhaustion) via SSL requests to the HTTPS port for normally unencrypted files, which will cause IIS to perform extra work to send the files over SSL.

Votes:

   ACCEPT(3) Frech, Wall, Cole
   NOOP(1) Foat

CAN-1999-1538

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990114 MS IIS 4.0 Security Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91638375309890&w=2
Reference: NTBUGTRAQ:19990114 MS IIS 4.0 Security Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=91632724913080&w=2
Reference: BID:189
Reference: URL:http://www.securityfocus.com/bid/189

Description:
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access to the local machine and allows an unauthorized user to gain access to sensitive server information, including the Administrator's password.

Votes:

   ACCEPT(1) Wall
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
Voter Comments:
 Frech> XF:iis-ismdll-info(7566)


CAN-1999-1539

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94225924803704&w=2
Reference: NTBUGTRAQ:19991110 Remote DoS Attack in QVT/Term 'Plus' 4.2d FTP Server Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94223972910670&w=2
Reference: BID:796
Reference: URL:http://www.securityfocus.com/bid/796
Reference: XF:qvtterm-login-dos(3491)
Reference: URL:http://xforce.iss.net/static/3491.php

Description:
Buffer overflow in FTP server in QPC Software's QVT/Term Plus versions 4.2d and 4.3 and QVT/Net 4.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long (1) user name or (2) password.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1540

Phase: Proposed (20010912)
Reference: L0PHT:19991004
Reference: URL:http://www.atstake.com/research/advisories/1999/shell-lock.txt
Reference: BUGTRAQ:19991005 Cactus Software's shell-lock
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93916168802365&w=2
Reference: XF:cactus-shell-lock-retrieve-shell-code(3356)
Reference: URL:http://xforce.iss.net/static/3356.php

Description:
shell-lock in Cactus Software Shell Lock uses weak encryption (trivial encoding) which allows attackers to easily decrypt and obtain the source code.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1541

Phase: Proposed (20010912)
Reference: L0PHT:19991004
Reference: URL:http://www.atstake.com/research/advisories/1999/shell-lock.txt
Reference: BUGTRAQ:19991005 Cactus Software's shell-lock
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93916168802365&w=2
Reference: XF:cactus-shell-lock-root-privs(3358)
Reference: URL:http://xforce.iss.net/static/3358.php

Description:
shell-lock in Cactus Software Shell Lock allows local users to read or modify decoded shell files before they are executed, via a symlink attack on a temporary file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1543

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990710 MacOS system encryption algorithm
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93188174906513&w=2
Reference: BUGTRAQ:19990914 MacOS system encryption algorithm 3
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93736667813924&w=2
Reference: BID:519
Reference: URL:http://www.securityfocus.com/bid/519

Description:
MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (ACCEPT; Task 2357)


CAN-1999-1544

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990124 Advisory: IIS FTP Exploit/DoS Attack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91722115016183&w=2

Description:
Buffer overflow in FTP server in Microsoft IIS 3.0 and 4.0 allows local and sometimes remote attackers to cause a denial of service via a long NLST (ls) command.

Votes:

   ACCEPT(1) Wall
   NOOP(2) Foat, Cole
   REJECT(1) Frech
Voter Comments:
 Frech> Dupe CAN-1999-0349


CAN-1999-1545

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990714
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93216103027827&w=2
Reference: BUGTRAQ:19990717 joe 2.8 makes world-readable DEADJOE
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93226771401036&w=2

Description:
Joe's Own Editor (joe) 2.8 sets the world-readable permission on its crash-save file, DEADJOE, which could allow local users to read files that were being edited by other users.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (ACCEPT; Task 2358)


CAN-1999-1546

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990129 TROJAN: netstation.navio-comm.rte 1.1.0.1
Reference: URL:http://www.securityfocus.com/archive/1/12217
Reference: XF:navionc-config-script(1724)
Reference: URL:http://xforce.iss.net/static/1724.php

Description:
netstation.navio-com.rte 1.1.0.1 configuration script for Navio NC on IBM AIX exports /tmp over NFS as world-readable and world-writable.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1547

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991125 Oracle Web Listener
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94359982417686&w=2
Reference: NTBUGTRAQ:19991125 Oracle Web Listener
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94390053530890&w=2
Reference: BID:841
Reference: URL:http://www.securityfocus.com/bid/841

Description:
Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equivalent.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:oracle-weblistener-bypass-restrictions(8355)


CAN-1999-1548

Phase: Proposed (20010912)
Reference: BINDVIEW:19991124 Cabletron SmartSwitch Router 8000 Firmware v2.x
Reference: URL:http://razor.bindview.com/publish/advisories/adv_Cabletron.html
Reference: BID:821
Reference: URL:http://www.securityfocus.com/bid/841

Description:
Cabletron SmartSwitch Router (SSR) 8000 firmware 2.x can only handle 200 ARP requests per second allowing a denial of service attack to succeed with a flood of ARP requests exceeding that limit.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:smartswitch-arp-flood-dos(7770)
   BID URL should be 821, not 841.


CAN-1999-1549

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991116 lynx 2.8.x - 'special URLs' anti-spoofing protection is weak
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94286509804526&w=2
Reference: BID:804
Reference: URL:http://www.securityfocus.com/bid/804

Description:
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:lynx-lynxurl-spoof(8342)


CAN-1999-1551

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990302 Multiple IMail Vulnerabilites
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92038879607336&w=2
Reference: BID:505
Reference: URL:http://www.securityfocus.com/bid/505
Reference: XF:imail-websvc-overflow(1898)
Reference: URL:http://xforce.iss.net/static/1898.php

Description:
Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1552

Phase: Proposed (20010912)
Reference: BUGTRAQ:19940720 xnews and XDM
Reference: URL:http://lists.insecure.org/lists/bugtraq/1994/Jul/0038.html
Reference: BID:358
Reference: URL:http://www.securityfocus.com/bid/358

Description:
dpsexec (DPS Server) when running under XDM in IBM AIX 3.2.5 and earlier does not properly check privileges, which allows local users to overwrite arbitrary files and gain privileges.

Votes:

   NOOP(2) Foat, Cole

CAN-1999-1553

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990301 [0z0n3] XCmail remotely exploitable vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/12730
Reference: BID:311
Reference: URL:http://www.securityfocus.com/bid/311
Reference: XF:xcmail-reply-overflow(1859)
Reference: URL:http://xforce.iss.net/static/1859.php

Description:
Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long subject line.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1554

Phase: Modified (20020218-01)
Reference: CERT:CA-1990-08
Reference: URL:http://www.cert.org/advisories/CA-1990-08.html
Reference: BID:13
Reference: URL:http://www.securityfocus.com/bid/13
Reference: XF:sgi-irix-reset(3164)
Reference: URL:http://www.iss.net/security_center/static/3164.php

Description:
/usr/sbin/Mail on SGI IRIX 3.3 and 3.3.1 does not properly set the group ID to the group ID of the user who started Mail, which allows local users to read the mail of other users.

Votes:

   ACCEPT(2) Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:sgi-irix-reset(3164)
 CHANGE> [Foat changed vote from ACCEPT to NOOP]


CAN-1999-1555

Phase: Proposed (20010912)
Reference: BUGTRAQ:19980611 Cheyenne Inoculan vulnerability on NT
Reference: URL:http://www.securityfocus.com/archive/1/9515
Reference: BID:106
Reference: XF:inoculan-bad-permissions(1536)
Reference: URL:http://xforce.iss.net/static/1536.php

Description:
Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan's antivirus update feature to install a Trojan horse dll.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> http://support.cai.com/Download/patches/inocnt.html


CAN-1999-1556

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19980629 MS SQL Server 6.5 stores password in unprotected registry keys
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=90222453431645&w=2
Reference: BID:109
Reference: URL:http://www.securityfocus.com/bid/109

Description:
Microsoft SQL Server 6.5 uses weak encryption for the password for the SQLExecutiveCmdExec account and stores it in an accessible portion of the registry, which could allow local users to gain privileges by reading andd decrypting the CmdExecAccount value.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   NOOP(2) Christey, Foat
Voter Comments:
 Frech> XF:mssql-sqlexecutivecmdexec-password(7354)
 Christey> Need to consult MS on this issue.


CAN-1999-1557

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990301 Multiple IMail Vulnerabilites
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92038879607336&w=2
Reference: XF:imail-imap-overflow(1895)
Reference: URL:http://xforce.iss.net/static/1895.php

Description:
Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Wall, Foat

CAN-1999-1558

Phase: Modified (20020218-01)
Reference: CIAC:I-071A
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/i-071a.shtml
Reference: CERT:VB-98.07
Reference: BID:161
Reference: URL:http://www.securityfocus.com/bid/161
Reference: XF:openvms-loginout-unauth-access(7151)
Reference: URL:http://www.iss.net/security_center/static/7151.php

Description:
Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.

Votes:

   ACCEPT(3) Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:openvms-loginout-unauth-access(7151)


CAN-1999-1559

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990331 Xylan OmniSwitch "features"
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92299263017061&w=2
Reference: XF:xylan-omniswitch-login(2064)
Reference: URL:http://xforce.iss.net/static/2064.php

Description:
Xylan OmniSwitch before 3.2.6 allows remote attackers to bypass the login prompt via a CTRL-D (control d) character, which locks other users out of the switch because it only supports one session at a time.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole

CAN-1999-1560

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990720 tiger vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93252050203589&w=2
Reference: XF:tiger-script-execute(2369)
Reference: URL:http://xforce.iss.net/static/2369.php

Description:
Vulnerability in a script in Texas A&M University (TAMU) Tiger allows local users to execute arbitrary commands as the Tiger user, usually root.

Votes:

   ACCEPT(3) Frech, Foat, Cole
   NOOP(1) Wall

CAN-1999-1561

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990820 Winamp SHOUTcast server: Gain Administrator Password
Reference: URL:http://www.securityfocus.com/archive/1/24852

Description:
Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain administrative privileges on the server.

Votes:

   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Frech> (ACCEPT; Task 2359)


CAN-1999-1562

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990905 gftp
Reference: URL:http://www.securityfocus.com/archive/1/26915

Description:
gFTP FTP client 1.13, and other versions before 2.0.0, records a password in plaintext in (1) the log window, or (2) in a log file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:gftp-plaintext-password(7319)


CAN-1999-1563

Phase: Proposed (20010912)
Reference: BUGTRAQ:19991014 NEUROCOM: Nashuatec printer, 3 vulnerabilities found
Reference: URL:http://www.securityfocus.com/archive/1/30849
Reference: BUGTRAQ:19991116 NEUROCOM: Nashuatec D445/435 vulnerabilities updated
Reference: URL:http://www.securityfocus.com/archive/1/35075

Description:
Nachuatec D435 and D445 printer allows remote attackers to cause a denial of service via ICMP redirect storm.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:icmp-redirect(285)


CAN-1999-1564

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990902 [ Kernel panic with FreeBSD-3.2-19990830-STABLE ]
Reference: URL:http://www.securityfocus.com/archive/1/26166

Description:
FreeBSD 3.2 and possibly other versions allows a local user to cause a denial of service (panic) with a large number accesses of an NFS v3 mounted directory from a large number of processes.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:freebsd-nfs-access-dos(8325)


CAN-1999-1566

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990508 iParty Daemon Vulnerability w/ Exploit Code (worse than thought?)
Reference: URL:http://www.securityfocus.com/archive/1/13600

Description:
Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:iparty-dos(1416)


CAN-1999-1567

Phase: Modified (20020218-01)
Reference: NTBUGTRAQ:19990308 Password and DOS Vulnerability with Testrack (bug tracking software)
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9903&L=NTBUGTRAQ&P=R1215
Reference: NTBUGTRAQ:19990616 Password and DOS Vulnerability with Testrack (bug tracking software)
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9906&L=NTBUGTRAQ&P=R1680
Reference: XF:testtrack-dos(1948)
Reference: URL:http://xforce.iss.net/static/1948.php

Description:
Seapine Software TestTrack server allows a remote attacker to cause a denial of service (high CPU) via (1) TestTrackWeb.exe and (2) ttcgi.exe by connecting to port 99 and disconnecting without sending any data.

Votes:

   ACCEPT(2) Foat, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:testtrack-dos(1948)


CAN-1999-1568

Phase: Proposed (20010912)
Reference: BUGTRAQ:19990223 NcFTPd remote buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91981352617720&w=2
Reference: BUGTRAQ:19990223 Comments on NcFTPd "theoretical root compromise"
Reference: URL:http://www.securityfocus.com/archive/1/12699
Reference: XF:ncftpd-port-bo(1833)
Reference: URL:http://xforce.iss.net/static/1833.php

Description:
Off-by-one error in NcFTPd FTP server before 2.4.1 allows a remote attacker to cause a denial of service (crash) via a long PORT command.

Votes:

   ACCEPT(3) Frech, Foat, Cole
   NOOP(1) Wall

CAN-1999-1569

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010716 Quake client and server denial-of-service
Reference: URL:http://www.securityfocus.com/archive/1/197268
Reference: BUGTRAQ:19981101 Quake problem?
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=91012172524181&w=2
Reference: BUGTRAQ:19980502 NetQuake Protocol problem resulting in smurf like effect.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=90221101925989&w=2
Reference: XF:quake-spoofed-client-dos(6871)
Reference: URL:http://xforce.iss.net/static/6871.php
Reference: BID:3051
Reference: URL:http://www.securityfocus.com/bid/3051

Description:
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconnection) via a flood of spoofed UDP connection packets, which exceeds the server's player limit.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
   REVIEWING(1) Green

CAN-1999-1570

Phase: Proposed (20020830)
Reference: VULN-DEV:20020509 Sar -o exploitation process info.
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=102098949103708&w=2
Reference: BUGTRAQ:19990909 19 SCO 5.0.5+Skunware98 buffer overflows
Reference: URL:http://online.securityfocus.com/archive/1/27074
Reference: CALDERA:CSSA-2002-SCO.17
Reference: URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2002-SCO.17/CSSA-2002-SCO.17.txt
Reference: BID:4089
Reference: URL:http://www.securityfocus.com/bid/4089
Reference: XF:openserver-sar-bo(8989)
Reference: URL:http://www.iss.net/security_center/static/8989.php

Description:
Buffer overflow in sar for OpenServer 5.0.5 allows local users to gain root privileges via a long -o parameter.

Votes:

   ACCEPT(4) Green, Frech, Cole, Armstrong
   NOOP(4) Christey, Cox, Wall, Foat
Voter Comments:
 Frech> It seems as if the BID-4089 assignment on this CAN name may be
   in error.
   BID-4089 (Multiple Vendor SNMP Request Handling Vulnerabilities) is
   already assigned to CAN-2002-0013. Also, this CVE issue seems to have
   nothing to do with SNMP.
 Christey> Agreed, this is the wrong BID.  SecurityFocus has assigned
   BID:643 to CAN-1999-1570, but there's a bit of an
   inconsistency.  BID:643 alludes to Bugtraq posts in 1999
   from Brock Tellier, mentioning overflows in sar via BOTH the
   -o and -f parameters.  However, they also link this issue to
   SCO advisory 99.17, although the advisory itself is too vague
   to *really* know what vulns they fixed.  And now the link
   to a potentially more detailed document (sse037.ltr)
   is broken.  So we don't have any independent reason for
   knowing whether SCO 99.17 (a) addresses any "sar"
   vulnerabilities, and (b) even if it does, whether it addresses
   *both* the -o and -f arguments originally claimed by Tellier.
   Finally, it seems rather curious that CSSA-2002-SCO.17
   talks about a -o overflow but does not mention -f.
   Sounds like an email to the security people at SCO
   is in order...
   
   OK.  Having consulted with SCO (who responded quickly), I
   looked even further into this issue.  There is now sufficient
   evidence that the -f overflow was fixed in 1999.  This
   means that a separate candidate should be created (by
   CD:SF-LOC), so the -f overflow is now covered by
   CAN-1999-1571.
   
   Need to DELREF BID:4089
 CHANGE> [Frech changed vote from NOOP to ACCEPT]


CAN-1999-1571

Phase: Assigned (20021008)
Reference: BUGTRAQ:19990909 19 SCO 5.0.5+Skunware98 buffer overflows
Reference: URL:http://online.securityfocus.com/archive/1/27074
Reference: BUGTRAQ:19990917 Re: recent SCO 5.0.x vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=93762097815861&w=2
Reference: BUGTRAQ:19991020 Re: recent SCO 5.0.x vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94053017801639&w=2
Reference: BUGTRAQ:19991105 SCO Security Bulletin 99.17
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94183363719024&w=2
Reference: MISC:http://online.securityfocus.com/advisories/1843
Reference: SCO:SB-99.17c
Reference: URL:ftp://stage.caldera.com/pub/security/sse/security_bulletins/SB-99.17c
Reference: CONFIRM:ftp://stage.caldera.com/pub/security/sse/sse037c/sse037c.ltr
Reference: BID:643
Reference: URL:http://online.securityfocus.com/bid/643
Reference: VULN-DEV:20020509 Sar -o exploitation process info.
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=102098949103708&w=2
Reference: XF:openserver-sar-bo(8989)
Reference: URL:http://www.iss.net/security_center/static/8989.php

Description:
Buffer overflow in sar for SCO OpenServer 5.0.0 through 5.0.5 may allow local users to gain root privileges via a long -f parameter, a different vulnerability than CAN-1999-1570.

Votes:







CAN-2000-0005

Phase: Modified (20000204-01)
Reference: BUGTRAQ:19991230 aserver.sh
Reference: BUGTRAQ:20000102 HPUX Aserver revisited.
Reference: HP:HPSBUX0001-108
Reference: XF:hp-aserver

Description:
HP-UX aserver program allows local users to gain privileges via a symlink attack.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(1) Frech
   RECAST(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Christey> BUGTRAQ:20000102 "HPUX Aserver revisited." indicates that two
   different versions of aserver have symlink problems, but with
   different files.  So CD:SF-LOC says we should split this.
 Frech> XF:hp-aserver
 Christey> BID:1928 and BID:1930?  Which one is being described in
   this candidate?
 Christey> BID:1930


CAN-2000-0008

Phase: Proposed (20000111)
Reference: BUGTRAQ:19991227 FTPPro insecuities

Description:
FTPPro allows local users to read sensitive information, which is stored in plain text.

Votes:

   ACCEPT(3) Armstrong, Stracener, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Levy
Voter Comments:
 Frech> XF:ftppro-plaintext-information
 Christey> ADDREF BID:1790
   ADDREF URL:http://www.securityfocus.com/bid/1790


CAN-2000-0016

Phase: Proposed (20000111)
Reference: NTBUGTRAQ:19991001 Vulnerabilities in the Internet Anywhere Mail Server
Reference: BUGTRAQ:19991227 Remote DoS/Access Attack in Internet Anywhere Mail Server(POP 3) v2.3.1
Reference: BID:730
Reference: URL:http://www.securityfocus.com/bid/730

Description:
Buffer overflow in Internet Anywhere POP3 Mail Server allows remote attackers to cause a denial of service or execute commands via a long username.

Votes:

   ACCEPT(4) Levy, Armstrong, Stracener, Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:iams-pop3-command-dos


CAN-2000-0017

Phase: Proposed (20000111)
Reference: BUGTRAQ:19991221 (Possible) Linuxconf Remote Buffer Overflow Vulnerability

Description:
Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.

Votes:

   NOOP(4) Armstrong, Stracener, Christey, Baker
   REJECT(2) Levy, Frech
Voter Comments:
 Christey> It's not certain whether this is exploitable or not.  An 
   expert (the linuxconf author?) wasn't able to duplicate the
   bug - see http://lwn.net/1999/1223/a/linuxconfresponse.html
   
   The original posting with example exploit was
   http://marc.theaimsgroup.com/?l=bugtraq&m=94580196627059&w=2
   
   However - GIAC and the Security Focus incidents list have
   consistently reported that scans are taking place for
   linuxconf, so do the hackers know more than we do?
 Frech> Unless vendor or other confirmation occurs, there has been no corroboration
   of this issue in public forums.
 CHANGE> [Armstrong changed vote from ACCEPT to NOOP]


CAN-2000-0019

Phase: Proposed (20000111)
Reference: BUGTRAQ:19991221 [w00giving '99 #11] IMail's password encryption scheme

Description:
IMail POP3 daemon uses weak encryption, which allows local users to read files.

Votes:

   ACCEPT(3) Armstrong, Stracener, Baker
   MODIFY(2) Levy, Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:imail-passwords
 Levy> BID 880
 Christey> BUGTRAQ:19990304 IMAIL password recovery is trivial.
   http://www.securityfocus.com/archive/1/12750
 Christey> Add version numbers (5.0 through 5.08)


CAN-2000-0021

Phase: Proposed (20000111)
Reference: BUGTRAQ:19991221 serious Lotus Domino HTTP denial of service
Reference: BUGTRAQ:19991227 Re: Lotus Domino HTTP denial of service attack

Description:
Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.

Votes:

   ACCEPT(3) Armstrong, Stracener, Baker
   MODIFY(2) Levy, Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:http-cgi-lotus-domino
 Levy> BID 881
 Christey> BID:881


CAN-2000-0028

Phase: Modified (20000626-01)
Reference: BUGTRAQ:19991222 IE 5.01 vulnerabilities in external.NavigateAndFind()
Reference: XF:ie-navigateandfind

Description:
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(2) Levy, Frech
   NOOP(1) Baker
   RECAST(1) LeBlanc
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:ie-navigateandfind
 Christey> May be a duplicate of CVE-2000-0465 according to my
   communications with Microsoft people.  CAN-2000-0266 may
   also be a variant.
 Levy> BID 887
 LeBlanc> duplicate


CAN-2000-0035

Phase: Proposed (20000111)
Reference: BUGTRAQ:19991228 majordomo local exploit
Reference: BUGTRAQ:20000113 Info on some security holes reported against SCO Unixware.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94780294009285&w=2
Reference: BID:902
Reference: URL:http://www.securityfocus.com/bid/902

Description:
resend command in Majordomo allows local users to gain privileges via shell metacharacters.

Votes:

   ACCEPT(3) Levy, Stracener, Baker
   MODIFY(2) Cox, Frech
   NOOP(1) Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:majordomo-local-resend
 Christey> The Bugtraq thread indicates that this problem may be
   due to misconfiguration, and may extend beyond just the
   resend command.
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]
 Christey> Include "wrapper" to facilitate search and matching?  (but
   double-check CAN-2000-0037).
   Add "1.94.4 and earlier" as the affected version number.
   ADDREF AUSCERT:AA-2000.01
   ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.01
 Cox> ADDREF REDHAT:RHSA-2000:005


CAN-2000-0038

Phase: Proposed (20000111)
Reference: BUGTRAQ:19991223 Multiple vulnerabilites in glFtpD (current versions)

Description:
glFtpD includes a default glftpd user account with a default password and a UID of 0.

Votes:

   ACCEPT(2) Armstrong, Stracener
   MODIFY(2) Levy, Frech
   NOOP(1) Baker
Voter Comments:
 Frech> XF:glftpd-default-account
 Levy> BID 881


CAN-2000-0046

Phase: Modified (20000204-01)
Reference: BID:929
Reference: URL:http://www.securityfocus.com/bid/929
Reference: BUGTRAQ:20000111 ICQ Buffer Overflow Exploit
Reference: XF:icq-url-bo

Description:
Buffer overflow in ICQ 99b 1.1.1.1 client allows remote attackers to execute commands via a malformed URL within an ICQ message.

Votes:

   ACCEPT(2) Williams, Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> ADDREF XF:icq-url-bo


CAN-2000-0047

Phase: Modified (20000202-01)
Reference: BUGTRAQ:20000117 Yahoo Pager/Messanger Buffer Overflow
Reference: XF:yahoo-messenger-pager-dos

Description:
Buffer overflow in Yahoo Pager/Messenger client allows remote attackers to cause a denial of service via a long URL within a message.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(1) Williams

CAN-2000-0049

Phase: Modified (20000204-01)
Reference: NTBUGTRAQ:20000107 Winamp buffer overflow advisory
Reference: BUGTRAQ:20000109 Buffer overflow with WinAmp 2.10
Reference: BID:925
Reference: URL:http://www.securityfocus.com/bid/925
Reference: XF:winamp-playlist-bo

Description:
Buffer overflow in Winamp client allows remote attackers to execute commands via a long entry in a .pls file.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:winamp-playlist-bo
 Christey> This may have been discovered earlier in:
   BUGTRAQ:19990512 Buffer overflow in WinAMP 2.x
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92662988700367&w=2
   See the following for possible confirmation:
   URL:http://www.winamp.com/getwinamp/newfeatures.jhtml
 Wall> This vulnerability has been seen in several versions of Winamp and part of ISS
   X-Force
   and SecuriTeam vulnerability checks.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]


CAN-2000-0054

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000104 Another search.cgi vulnerability
Reference: BID:921
Reference: URL:http://www.securityfocus.com/bid/921

Description:
search.cgi in the SolutionScripts Home Free package allows remote attackers to view directories via a .. (dot dot) attack.

Votes:

   MODIFY(1) Frech
Voter Comments:
 Frech> XF:http-cgi-homefree-search


CAN-2000-0055

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000106 [Hackerslab bug_paper] Solaris chkperm buffer overflow
Reference: BID:918
Reference: URL:http://www.securityfocus.com/bid/918

Description:
Buffer overflow in Solaris chkperm command allows local users to gain root access via a long -n option.

Votes:

   MODIFY(1) Frech
   NOOP(1) Dik
Voter Comments:
 Frech> XF:sol-chkperm-bo(3870)
 Dik> chkperm runs set-uid bin, so initially the access granted
   will be user bin, not root.  (Though bin access can easily be leveraged
   to root access, less so in Solaris 8+)
   Also, there is reason to believe this bug is not exploitable; the buffer
   overflown is declared in the stack in main(); yet, the program never
   returns from main() but calls exit instead so any damage to return addresses
   is never noticed.


CAN-2000-0058

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000105 Handspring Visor Network HotSync Security Hole
Reference: URL:http://www.security-express.com/archives/bugtraq/2000-01/0085.html
Reference: BID:920
Reference: URL:http://www.securityfocus.com/bid/920

Description:
Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.

Votes:

   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:handspring-visor-auth(3873)
   Consider removing the security-express.com reference, since it is identical
   to the BugTraq reference. The BugTraq reference is (hopefully) not going to
   disappear soon, and the security-express.com reference provides no new or
   additional information.
 Christey> URLs will begin to be included with candidates to support
   Board members' voting activities.  They will be converted to
   the generalized reference format when if candidate is
   ACCEPTed and becomes an official entry.
 Christey> The problem may not be a lack of authentication (as mentioned
   by the poster), but rather weak authentication (the apparent
   need to provide the same username).


CAN-2000-0059

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000103 PHP3 safe_mode and popen()
Reference: BID:911
Reference: URL:http://www.securityfocus.com/bid/911

Description:
PHP3 with safe_mode enabled does not properly filter shell metacharacters from commands that are executed by popen, which could allow remote attackers to execute commands.

Votes:

   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:php3-popen-execute(3900)
 Christey> CONFIRM:http://www.php.net/ChangeLog.php3
   Section dated January 11, 2000 says: "Fix safe-mode problem in
   popen() (Kristian)" 


CAN-2000-0061

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000107 IE 5 security vulnerablity - circumventing Cross-frame security policy and accessing the DOM of "old" documents.
Reference: BID:923
Reference: URL:http://www.securityfocus.com/bid/923

Description:
Internet Explorer 5 does not modify the security zone for a document that is being loaded into a window until after the document has been loaded, which could allow remote attackers to execute Javascript in a different security context while the document is loading.

Votes:

   MODIFY(2) LeBlanc, Frech
   REJECT(1) Christey
Voter Comments:
 Frech> XF:ie-cross-frame-docs(3901)
 LeBlanc> - I'd like to see a KB or bulletin referenced 
 Christey> This is a duplicate of CVE-2000-0156.  The FAQ at
   http://www.microsoft.com/technet/security/bulletin/fq00-009.asp.
   says "the vulnerability requires Active Scripting" and
   "it is possible, under very specific conditions, to violate IE's
   cross-domain security model."  Also says "the redirect is made, via
   the <IMG SRC> HTML tag"
   
   Need to copy these references over to CVE-2000-0156.


CAN-2000-0066

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000112 WebSitePro/2.3.18 is revealing Webdirectories

Description:
WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.

Votes:

   ACCEPT(2) Williams, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:website-pro-dir-path
 Christey> ADDREF BUGTRAQ:20000113 Re: WebSitePro/2.3.18 + 2.4.9 is revealing Webdirectories
   URL:http://www.securityfocus.com/archive/1/41798
   Also BID:932


CAN-2000-0067

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000112 CyberCash MCK 3.2.0.4: Large /tmp hole

Description:
CyberCash Merchant Connection Kit (MCK) allows local users to modify files via a symlink attack.

Votes:

   ACCEPT(2) Williams, Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:cybercash-mck-tmp(3823)


CAN-2000-0068

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000104 [rootshell] Security Bulletin #27
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94704437920965&w=2

Description:
daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.

Votes:

   MODIFY(1) Frech
Voter Comments:
 Frech> XF:intel-email-unauthenticate-users


CAN-2000-0069

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000104 Security problem with Solstice Backup/Legato Networker recover command

Description:
The recover program in Solstice Backup allows local users to restore sensitive files.

Votes:

   MODIFY(1) Frech
Voter Comments:
 Frech> XF:solstice-backup-restore-files(3904)


CAN-2000-0071

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000111 IIS still revealing paths for web directories
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94770020309953&w=2
Reference: BUGTRAQ:20000113 SV: IIS still revealing paths for web directories
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94780058006791&w=2

Description:
IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

Votes:

   ACCEPT(2) Levy, LeBlanc
   MODIFY(1) Frech
   REJECT(1) Christey
Voter Comments:
 Frech> XF:iis-ida-idq-paths
 Christey> Consider adding:
   ADDREF BID:1065
   BUGTRAQ:20000309 Enumerate Root Web Server Directory Vulnerability for IIS 4.0
   Are there really 2 different threads on the same problem?
   
   Also consider XF:iis-root-enum
   
   May also be a dupe of CAN-1999-0450 (BID:194)
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Appears to be a duplicate of CVE-2000-0098.  Confirm with
   Microsoft, and if it is a duplicate, then REJECT this
   candidate.
 CHANGE> [Christey changed vote from REVIEWING to REJECT]
 Christey> Confirmed duplicate by Microsoft.
 Christey> iis-ida-idq-paths(4346)	is obsolete; ensure
   http-indexserver-path(3890) is added to CVE-2000-0098.


CAN-2000-0074

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000111 PowerScripts PlusMail Vulnerablity

Description:
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Williams, Christey
Voter Comments:
 Frech> XF:plusmail-password-permissions
 Christey> Re-read the Bugtraq post to make sure the problem is described
   properly.  The advisory itself is vague as to the nature of
   the problem, and the exploit doesn't help clarify too much.
 Christey> Consider adding BID:2653


CAN-2000-0077

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000102 HPUX Aserver revisited.
Reference: HP:HPSBUX0001-108

Description:
The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the ps and grep commands.

Votes:

   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> ADDREF XF:hp-aserver
 Christey> The Bugtraq posting does not mention specific versions.
   Is October 1998 equivalent to HP-UX 10.x?
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> BID:1929
   Make sure not dupe's with CAN-2000-0005 and CAN-20000-0078.


CAN-2000-0078

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000102 HPUX Aserver revisited.
Reference: HP:HPSBUX0001-108

Description:
The June 1999 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate PATH which aserver uses to find the awk command.

Votes:

   ACCEPT(1) Prosser
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> ADDREF XF:hp-aserver
 Christey> The Bugtraq posting does not mention specific versions.
   Is June 1999 equivalent to HP-UX 10.x?
 Prosser> The HP Bulletin (already ref'd) just specifies 10.x and 11.x OS versions running on HP9000 700/800 series.  According to Tripp (bugtraq), the audio server doesn't run on a machine without Audio Hardware (logical).  So one has to assume from the bulletin that any 9000 with audio hardware that is running a 10.x or 11.x version of OS with either the 98 or 99 version of Aserver loaded will be vulnerable to either the exploit in CAN-1999-0005(the 98 version of Aserver) or CAN-2000-0078 (the 99 version)and should take appropriate action.  No patches out from HP as of 10/2/2000 so either remove the program or tighten the permissions considerably.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> BID:1929
   Make sure not dupe's with CAN-2000-0005 and CAN-20000-0077.


CAN-2000-0079

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000118 Re: IIS still revealing paths for web directories
Reference: BID:936
Reference: URL:http://www.securityfocus.com/bid/936

Description:
The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.

Votes:

   MODIFY(1) Frech
   NOOP(2) Williams, Christey
   RECAST(1) LeBlanc
Voter Comments:
 Frech> XF:w3c-httpd-reveal-paths
 LeBlanc> Title references IIS, vuln references W3C CERN httpd. Which
   one is broken?
 Christey> The mention of CERN httpd was buried in a followup on a
   description of an IIS problem, so this is the correct reference.


CAN-2000-0081

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000110 Yet another Hotmail security hole - injecting JavaScript using "j&#x41;vascript:"

Description:
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute the code by using hexadecimal codes to specify the javascript: protocol, e.g. j&#x41;vascript.

Votes:

   MODIFY(1) Frech
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:hotmail-vascript-java-injection


CAN-2000-0082

Phase: Proposed (20000125)
Reference: URL:http://net4tv.com/voice/story.cfm?StoryID=1823
Reference: MISC:http://www.wired.com/news/technology/0,1282,33420,00.html
Reference: BUGTRAQ:20000104 The WebTV Email Exploit

Description:
WebTV email client allows remote attackers to force the client to send email without the user's knowledge via HTML.

Votes:

   MODIFY(1) Frech
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> ADDREF XF:webtv-hijack-mail-forward


CAN-2000-0084

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000105 CuteFTP saved password 'encryption' weakness

Description:
CuteFTP uses weak encryption to store password information in its tree.dat file.

Votes:

   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:cuteftp-weak-encrypt(3910)
 Christey> BUGTRAQ:20010823 Re: Respondus v1.1.2 stores passwords using weak encryption
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99861651923668&w=2
   This followup to a different thread mentions the sm.dat file
   for the site manager.


CAN-2000-0085

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000103 Hotmail security hole - injecting JavaScript using <IMG LOWSRC="javascript:....">
Reference: BUGTRAQ:20000104 Yet another Hotmail security hole - injecting JavaScript in IE using <IMG DYNRC="javascript:....">

Description:
Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:hotmail-java-execute


CAN-2000-0086

Phase: Proposed (20000125)
Reference: BUGTRAQ:20000116 TB2 Pro sending NT passwords cleartext
Reference: BID:935
Reference: URL:http://www.securityfocus.com/bid/935

Description:
Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.

Votes:

   ACCEPT(2) Williams, Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:timbuktu-password-cleartext


CAN-2000-0093

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000122 NIS security advisory : password method downgrade
Reference: BUGTRAQ:20000121 Rh 6.1 initial root password encryption

Description:
An installation of Red Hat uses DES password encryption with crypt() for the initial password, instead of md5.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:linux-initial-password-encryption


CAN-2000-0096

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000126 Qpopper security bug
Reference: BID:948
Reference: URL:http://www.securityfocus.com/bid/948

Description:
Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:qpopper-list-bo


CAN-2000-0101

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The Make-a-Store OrderPage shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   NOOP(1) Christey
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> I would combine all of these shopping cart applications into one listing, 
   since they all have the same vulnerability being able to modify sensitive 
   purchase information via hidden form fields.  My concern is in cases like 
   this we used over 10 entries for basically the same vulnerability.  I could 
   think of cases were there could be 20+ applications with the same 
   vulnerability and in my opinion it could start to weaken the value of CVE 
   where there are 30 entries all referring to the same thing.  It is almost 
   like we are playing the vendor game where more is better.  I think we 
   should go after the quality over quantity aspect.
 Christey> I disagree with Eric here.  This vulnerability is a "type" of
   problem in the same way that a buffer overflow is a "type" of
   problem.  While the shopping cart application bugs were
   proposed mostly at the same time, they are all by different
   vendors.
   
   The raw numbers of applications with this problem can make it
   appear that CVE is artificially inflating the number of
   entries.   However, content decisions such as CD:SF-LOC
   (different lines of code) dictate that these should be
   separated.  It's not a "numbers game" but rather a principled
   and consistent approach to resolving problems with
   selecting a level of abstraction.
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0102

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The SalesCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0103

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The SmartCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0104

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The Shoptron shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0105

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000201 Outlook Express 5 vulnerability - Active Scripting may read email messages
Reference: BID:962
Reference: URL:http://www.securityfocus.com/bid/962

Description:
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that accesses a variable that references subsequent email messages that are read by the client.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> email-active-script-html
 Christey> Acknowledged via personal communication with Microsoft
   personnel, but I need to look through my email logs to recall
   whether they said that it is a duplicate of CAN-2000-0653
 CHANGE> [Christey changed vote from NOOP to REVIEWING]


CAN-2000-0106

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The EasyCart shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0108

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The Intellivend shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0109

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000201 Security issues with S&P ComStock multiCSP (Linux)

Description:
The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that have no passwords or easily guessable default passwords.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> ADDREF BUGTRAQ:20000324 Security issues with S&P ComStock multiCSP (Linux)
   http://marc.theaimsgroup.com/?l=bugtraq&m=95422382625409&w=2
   
   Note: this posting was a repeat of the February 1 post,
   saying that the problem still hadn't been fixed.
 Frech> XF:comstock-multicsp-passwords
 Christey> ADDREF BID:1080
   URL:http://www.securityfocus.com/vdb/bottom.html?vid=1080


CAN-2000-0110

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The WebSiteTool shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0114

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000203 2 MS Frontpage issues Cerberus Information Security Advisory (CISADV000203)

Description:
Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:iis-frontpage-info
 Christey> Acknowledged via personal communication with Microsoft
   personnel.
   
   May be the same as BID:1174 and/or BID:1433 (both mention
   FrontPage, but one mentions shtml.exe and another mentions
   shtml.dll)
 Christey> [note to self: review comments by Mark Burnett]
 CHANGE> [Christey changed vote from NOOP to REVIEWING]


CAN-2000-0115

Phase: Proposed (20000208)
Reference: NTBUGTRAQ:20000121 Strange behaviour IIS and RegExp

Description:
IIS allows local users to cause a denial of service via invalid regular expressions in a Visual Basic script in an ASP page.

Votes:

   ACCEPT(1) Cole
   REJECT(2) Frech, LeBlanc
   REVIEWING(1) Wall
Voter Comments:
 Frech> This reference to NTBugtraq has a message that ends with "Can anyone
   reproduce this?", and there are no followups. This makes for a weak
   reference. There are also no other references listed for this CAN.
 LeBlanc> - no follow-ups, no KB article, no fix
 CHANGE> [Frech changed vote from REVIEWING to REJECT]


CAN-2000-0118

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000130 RedHat 6.1 /and others/ PAM
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94935300520617&w=2

Description:
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.

Votes:

   ACCEPT(3) Levy, Cole, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> Is this the same issue as BugTraq Mailing List, Wed, 9 Jun 1999 14:07:27
   -0700 "vulnerability in su/PAM in redhat" at
   http://www.netspace.org/cgi-bin/wa?A2=ind9906b&L=bugtraq&F=&S=&P=5356 and
   "Solaris 2.5 /bin/su [was: vulnerability in su/PAM in redhat]" at
   http://www.netspace.org/cgi-bin/wa?A2=ind9906b&L=bugtraq&F=&S=&P=6051
   If so, then MODIFY XF:su-brute
 Christey> BID:320
   URL:http://www.securityfocus.com/vdb/bottom.html?vid=320
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:su-brute(2278)
   This issue involves more platforms than Red Hat. See BugTraq
   Mailing List, Thu Jun 10 1999 12:13:06, "Solaris 2.5 /bin/su [was:
   vulnerability in su/PAM in redhat]",
   http://www.securityfocus.com/archive/1/14854
 Christey> It does look like this is the same issue as the other Bugtraq
   post that explicitly mentions Red Hat and PAM.


CAN-2000-0119

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000130 Bypass Virus Checking
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94936267131123&w=2

Description:
The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the Windows Recycle Bin utility, which allows attackers to store malicious code without detection.

Votes:

   ACCEPT(2) Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> ADDREF BID:956
   
   A followup post on Feb 8 by Paul L Schmehl claims that this
   would not work, because the anti-virus checkers would
   activate if the user attempts to execute the program.
 Frech> XF:win-trojan-detection-bypass
   Much earlier possible reference at NTBugtraq Mailing List, Wed, 22 Dec 1999
   20:37:43 -0800, "Bypass Virus Checking under 95/98/NT" at
   http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9912&L=ntbugtraq&F=&S=&P=6030
 CHANGE> [Cole changed vote from REVIEWING to ACCEPT]
 Christey> NTBUGTRAQ:19991222 Bypass Virus Checking under 95/98/NT
   http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9912&L=ntbugtraq&F=&S=&P=6030


CAN-2000-0122

Phase: Proposed (20000208)
Reference: NTBUGTRAQ:20000203 2 MS Frontpage issues Cerberus Information Security Advisory (CISADV000203)
Reference: BID:964
Reference: URL:http://www.securityfocus.com/bid/964

Description:
Frontpage Server Extensions allows remote attackers to determine the physical path of a virtual directory via a GET request to the htimage.exe CGI program.

Votes:

   ACCEPT(3) LeBlanc, Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:ms-frontpage-get-htimage
 Christey> It appears that this was rediscovered in April 18, 2000:
   BUGTRAQ:20000418 More vulnerabilities in FP
   URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D38FCAC0C.869611C0%40hobbiton.org
   
   This in turn may match BID:1141
 Christey> According to Scott Culp of Microsoft, this was patched in MS:MS00-028.
 Christey> BID:1141 ??


CAN-2000-0123

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000203 Re: [xforce@iss.net: ISSalert: ISS E-Security Alert: Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications]

Description:
The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0124

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000203 surfCONTROL SuperScout v2.6.1.6 flaw
Reference: BID:965
Reference: URL:http://www.securityfocus.com/bid/965

Description:
surfCONTROL SuperScout does not properly asign a category to web sites with a . (dot) at the end, which may allow users to bypass web access restrictions.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Christey
   RECAST(1) Cole
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:surfcontrol-superscout-bypass-filter(4009)
 Christey> Fix typo: "asign"


CAN-2000-0125

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000203 RFP2K01 - "How I hacked Packetstorm" (wwwthreads advisory)
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.10002031027120.15921-100000@eight.wiretrip.net
Reference: BID:967
Reference: URL:http://www.securityfocus.com/bid/967

Description:
wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote attackers to gain privileges for wwwthreads forums.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:wwwthreads-sql-command-privs(4011)
 Christey> CONFIRM:http://www.wwwthreads.com/perl/showflat.pl?Cat=&Board=info&Number=9932&page=1&view=collapsed&sb=5


CAN-2000-0126

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000202 Alert: IIS 4 / IS 2 IDQ Cerberus Information Security Advisory (CISADV000202)
Reference: NTBUGTRAQ:20000202 Alert: IIS 4 / IS 2 IDQ Cerberus Information Security Advisory (CISADV000202)

Description:
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.

Votes:

   ACCEPT(3) LeBlanc, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:iis-dir-traversal-read
 Christey> This may be a variant of CVE-2000-0097 or CVE-2000-0098.
   MS:MS00-006 says that a new variant was announced on February 4,
   but that it only revealed the physical path.  The post related
   to this CAN is dated February 2, but it describes the impact
   as being able to read files.
   
   See http://marc.theaimsgroup.com/?l=bugtraq&m=94972759912790&w=2
 Christey> According to Mark Burnett: "CISADV000202 [described] idq.dll
   and involving .idq files...  IDQ files are vulnerable to a
   double-dot bug that allows files on the same partition as the
   web root to be viewed.... [This candidate] refers to the same
   MS00-006"
   
   ADDREF MS:MS00-006
   ADDREF BID:968 ?
 Frech> Change iis-dir-traversal-read(4014) to http-indexserver-view-files(4232)


CAN-2000-0129

Phase: Proposed (20000208)
Reference: NTBUGTRAQ:20000204 Local / Remote D.o.S Attack in Serv-U FTP-Server v2.5b for Win9x/WinNT Vulnerability
Reference: BUGTRAQ:20000204 Local / Remote D.o.S Attack in Serv-U FTP-Server v2.5b for Win9x/WinNT Vulnerability
Reference: NTBUGTRAQ:20000204 Windows Api SHGetPathFromIDList Buffer Overflow
Reference: BUGTRAQ:20000204 Windows Api SHGetPathFromIDList Buffer Overflow

Description:
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of service by performing a LIST command on a malformed .lnk file.

Votes:

   ACCEPT(3) Cole, Blake, Baker
   MODIFY(2) Frech, Levy
   NOOP(2) Ozancin, Armstrong
   RECAST(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:win-shortcut-api-bo
   The real problem seems to be with the Windows API call, not the Serv-U FTP
   app. As the "Windows Api SHGetPathFromIDList Buffer Overflow" reference
   states, [The bug can] "cause whatever handles the shortcuts to crash."
   As a suggestion, rephrase the description from Windows's context, and state
   that the Serv-U FTP server is an example of an app that exhibits this
   problem.
 Wall> Comment:  the original UssrLabs advisory does mention the SHGetPathFromIDList
   buffer overflow in a Windows API and that Serv-U FTP uses this API to cause the
   problem.  The problem does not exist on Windows 2000.  The solution seems to be
   in a new release of Serv-U FTP.
 Levy> BID 970
 Christey> 
   Reports indicate that while the vulnerable function was found in Serv-U FTP
   server, the function is actually from Microsoft, and as such may affect other
   applications.
   XF:win-shortcut-api-bo
   BID:970


CAN-2000-0132

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000201 `Microsoft VM for Java' allows reading local files using `getSystemResourceAsStream'.
Reference: BID:957
Reference: URL:http://www.securityfocus.com/bid/957

Description:
Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.

Votes:

   ACCEPT(2) Wall, Cole
   REJECT(3) Frech, LeBlanc, Christey
Voter Comments:
 Frech> How is this different from MITRE:CVE-2000-0162, other than the
   fact that it has an MS advisory that's vague on the reason but
   has the same outcome, and this one mentions the
   getSystemResourceAsStream function?
 Christey> This is a duplicate of CVE-2000-0162, as confirmed via David
   LeBlanc.  The descriptions of CAN-2000-0132 and CVE-2000-0162 were
   significantly different, as was the descriptive text of
   MS:MS00-011 and the original Bugtraq posting.  So this
   duplicate wasn't picked up before.   CVE-2000-0162 needs to be
   modified to include XF:virtual-machine-file-read as a
   reference.
 LeBlanc> Duplicate
 Christey> Ensure that CVE-2000-0162 uses msvm-java-file-read(4024) now,
   instead of virtual-machine-file-read(4577)
 Frech> If duplicate with CAN-2000-0098, shouldn't the references be
   moved over to the valid CVE number? Please advise.
 Christey> When CAN-2000-0132 is rejected, the references will be added
   to CVE-2000-0098.


CAN-2000-0133

Phase: Proposed (20000208)
Reference: BUGTRAQ:20000201 Tiny FTPd 0.52 beta3 Buffer Overflow
Reference: BID:961
Reference: URL:http://www.securityfocus.com/bid/961

Description:
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD, XRMD, APPE, SIZE, and RNFR commands.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:tinyftp-command-overflow(4000)


CAN-2000-0134

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The Check It Out shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0135

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The @Retail shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0136

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0137

Phase: Proposed (20000208)
Reference: ISS:20000201 Form Tampering Vulnerabilities in Several Web-Based Shopping Cart Applications

Description:
The CartIt shopping cart application allows remote users to modify sensitive purchase information via hidden form fields.

Votes:

   MODIFY(1) Frech
   RECAST(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Cole> See comments for CAN-2000-0101
 Frech> XF:shopping-cart-form-tampering


CAN-2000-0138

Phase: Modified (20000502-01)
Reference: CERT:CA-2000-01
Reference: CERT:IN-99-04
Reference: SUN:00193
Reference: ISS:20000209 Denial of Service Attack using the TFN2K and Stacheldraht programs
Reference: ISS:20000502 "mstream" Distributed Denial of Service Tool
Reference: URL:http://xforce.iss.net/alerts/advise48.php3
Reference: BUGTRAQ:19991206 Analysis of trin00
Reference: BUGTRAQ:19991206 Analysis of Tribe Flood Network
Reference: BUGTRAQ:19991229 Analysis of "stacheldraht"
Reference: BUGTRAQ:20000211 DDOS Attack Mitigation
Reference: BUGTRAQ:20000211 TFN2K - An Analysis
Reference: BUGTRAQ:20000211 A DDOS proposal.
Reference: BUGTRAQ:20000429 Re: Source code to mstream, a DDoS tool
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95715370208598&w=2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95722093124322&w=2

Description:
A system has a distributed denial of service (DDOS) attack master, agent, or zombie installed, such as (1) Trinoo, (2) Tribe Flood Network (TFN), (3) Tribe Flood Network 2000 (TFN2K), (4) stacheldraht, (5) mstream, or (6) shaft.

Votes:

   ACCEPT(2) Wall, Cole
   NOOP(4) Shostack, Levy, Dik, Christey
   RECAST(2) Ziese, Meunier
   REVIEWING(2) Bishop, Blake
Voter Comments:
 Christey> **********************************************************
   THIS CANDIDATE HAS GENERATED A LONG THREAD.  SEE THE 
   EDITORIAL BOARD ARCHIVES FOR DETAILS, BEGINNING AT
   
   http://cve.mitre.org/Board_Sponsors/archives/msg00590.html
   
   **********************************************************
 Ziese> 
   I suggest we I'd like to suggest that we consider not tying
   specifically to a DDOS tool.  Instead, since we are at at higher
   abstraction level, that we make the class include those master/slave
   tool combinations that are used for malicious purposes (i.e. DDOS,
   data exfiltration, or whatever the appropriate classes of effect are).
   
   My concern is that (1) we treat all distributed attacks at the same
   abstract level; not just the DDOS ones.  Second, if it is at a higher
   abstraction level then it seems right to unlimit it (by including
   master/slave combinations in general; not just the DDOS asect).
 Meunier> I think that trinoo etc... are very similar to smurf attacks
   (CVE-1999-0513 ) in the sense that a third party allows itself to be
   used.  Also, there is an  obvious solution that can only be done by
   that third party.
   
   As for the CVE entry, I am considering whether the common entry point
   could be reduced to "egress filtering has not been implemented or has
   been disabled, allowing the sending of spoofed IP packets".
   Incidentally, this would prevent the use of decoys in port scans,
   etc...  This single CVE entry would be very powerful. We could use
   the dot notation to list the DDoS tools and attacks that rely on the
   absence of egress filtering based on the argument that if you have
   egress filtering, nobody will bother to put or use DDoS tools on your
   computers.
   
   The weakness of this is that one could in theory still use DDoS tools
   even if you have egress filtering -- only they will be one shot guns,
   almost completely eliminating their appeal and effectiveness.  One
   use, and they will be blocked, tracked down and destroyed
   efficiently.
   
   Pascal
   
   P.S.: I am attracted by the idea of starting an internet (fire)wall
   of shame, for people who haven't implemented egress filtering.  It
   worked pretty well against sites allowing themselves to be used for
   smurf attacks (http://www.powertech.no/smurf/).  Why not use the same
   strategy for egress filtering?  Of course it's hard to know who is
   the source of IP spoofed  packets.  However the consistent detection
   of crud originating from a server is a sure sign that they haven't
   implemented egress filtering.  For example (my first candidate to
   this wall of shame), this weekend the Linux suse ftp server sent many
   packets with an illegal ip address as source, one reserved for local
   area networks, upon making an ftp connection (it may still be doing
   it, I haven't checked since -- the suse ftp admin mentioned that they
   were aware of it).  It was easy to figure out it was them by
   repeating the ftp connections and observing the 100% reproducibility
   and time correlation of the extraneous packets.  In addition, the
   suse servers kept sending me crud for *hours* after a failed attempt
   to download their PPC beta.
   
   The cost of egress filtering is easily justified.  The argument is
   similar to those relating to pollution, excepted that people don't
   try to break into your car if you have removed the catalytic
   converter.
 Bishop> I need to think about the exact meaning of MP. I suspect I
   will agree with the classification, on an operational basis
   (meaning I may want to revisit it), but I want to think on it
   some more.
 Blake> I don't agree with Pascal that this is a filtering problem analogous to
   smurf.  Rootkit is a better analogy.  The DDoS software doesn't exploit
   any unique vulnerability directly.  It's presence is entirely predicated
   on the existence of at least one other, easily exploited vulnerability.
   >From the perspective of the system owner, this is just one of several
   backdoors that could be installed.  Seems to me that the presence of a
   known backdoor package should be considered a vulnerability (or at least
   an exposure).
   
   I'm really torn on whether or not to split them out, though.  My
   inclination is to group master and slave by package; i.e., trinoo
   master/slave, tfn master/slave, etc.
   
 Wall> 
   Just to be consistent, you may add Trinoo (trin00) and does it matter
   if it is Tribal or Tribe?  The original internal c program says Tribe Flood
   Network.
 Meunier> What they have in common is the use of an amplification mechanism.
   They are broadcasting (multicasting) to a (virtual private) network,
   which then amplifies the messages.  In both cases, the amplification
   is done by the third party victim hosts.  The difference is just that
   the network is virtual instead of physical.
   
   
   Scott, you are assuming that the people who have the tools installed
   are unwilling.  Let's say theoretically speaking that there is an
   underground hacker group (or student association) who is hooked up to
   DSL lines (like in university residences) and who thinks that it
   would be "cool" to form an "army".  How about a popular civil
   movement protesting something, like the WTO last summer?  I think
   some people would voluntarily "enlist" their computers in a cause
   that would use DDoS attacks.  The rootkit analogy does not hold, yet
   the DDoS attacks could be just as effective.  However, if the
   university or ISPs implemented egress filtering, the DDoS attacks
   could be easily stopped because the people could be held accountable.
   The crux of the matter is the anonymity provided by IP spoofing.
   
   You are correct that in most cases, having a DDoS tool installed on
   your system is an exposure like rootkit.  Maybe that deserves a CVE
   entry.  However, I think that does not capture the nature of the
   DDoS, and that an entry about egress filtering is of utmost
   importance because it patches a fundamental vulnerability of IPv4.
 Blake> Excellent response, Pascal, thanks.  I hadn't thought of people
   volunteering, but that's certainly a plausible scenario.  Part of my
   motivation/thinking was a desire to stay away from making this into only
   yet another use for spoofed IP packets.  I wholeheartedly agree that
   egress filtering essential, but am reluctant to single out the recent DDoS
   events as the reason for it.
   
   I'd prefer to split out egress filtering as a seperate CVE entry (on the
   theory that not using egress filtering constitutes an exposure -- at least
   to liability), rather than tying it to these entries.
 Levy> I agree with Scott for no other reason that there needs to be a CVE
   ID so that IDS systems can report this things.
   
   Are we going to start handing out CVE ids for low level design faults?
   E.g. lack of encryption at the IPv4 packet level? lack of resource
   allocation protocols? the used of DES instead of Triple DES? etc
 Shostack> Both excellent points, however, I'd like to add that even if people
   volunteer to host the tools, Trinoo and company allow the controlling
   attacker to hide activities, which counts as an exposure under
   http://cve.mitre.org/About_CVE/About/definition.html
 Cole> Even with all of the debate i accept this one.
 Christey> With respect to inclusion of design flaws in CVE, review
   http://cve.mitre.org/Board_Sponsors/archives/msg00602.html
   
   Other design flaws that have already been added to CVE
   include Smurf (CVE-1999-0513), Fraggle (CVE-1999-0514)
   and TCP sequence number prediction (CVE-1999-0077), although
   this last one may need to be RECAST to a lower level of
   abstraction.
 CHANGE> [Meunier changed vote from REVIEWING to RECAST]
 Meunier> In the sense that this is like a rootkit, then it is a
   duplicate of CAN-1999-0660, "A hacker utility or Trojan Horse is
   installed on a system, e.g. NetBus, Back Orifice, Rootkit, etc..."
   
   It should be recast as CAN-1999-0660.1 DDoS tools
   Other dot notations could indicate different effects of the tools.
 Dik> There doesn't seem to be much to add to the
   discussion.


CAN-2000-0142

Phase: Proposed (20000216)
Reference: BUGTRAQ:20000211 Timbuktu Pro 2.0b650 DoS

Description:
The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.

Votes:

   ACCEPT(4) Bishop, LeBlanc, Cole, Blake
   MODIFY(2) Frech, Levy
   NOOP(1) Christey
Voter Comments:
 Frech> XF:timbuktu-auth-dos
 Levy> BID 984
 Christey> BUGTRAQ:20000412 Timbuktu DoS repaired by Netopia
   http://www.securityfocus.com/archive/1/54850
   BID:984


CAN-2000-0143

Phase: Interim (20001011)
Reference: BUGTRAQ:20000211 sshd and pop/ftponly users incorrect configuration
Reference: XF:ssh-redirect-tcp-connection

Description:
The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.

Votes:

   ACCEPT(3) LeBlanc, Cole, Blake
   MODIFY(1) Frech
   NOOP(1) Bishop
   REJECT(1) Levy
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:ssh-redirect-tcp-connection
 CHANGE> [Cole changed vote from REVIEWING to ACCEPT]
 Christey> Examine the thread at
   http://marc.theaimsgroup.com/?l=bugtraq&m=95055978131077&w=2
   to ensure that this problem is being characterized
   appropriately.
 Levy> SSH is working as designed. The fact that some of its interactions
   are not forseen by some is not a vulnerability.


CAN-2000-0147

Phase: Modified (20000321-01)
Reference: NAI:20000207 SNMPD default writable community string
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-02/0045.html
Reference: SCO:SB-00.04a
Reference: URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-00.04a
Reference: BID:973
Reference: URL:http://www.securityfocus.com/bid/973

Description:
snmpd in SCO OpenServer has an SNMP community string that is writable by default, which allows local attackers to modify the host's configuration.

Votes:

   ACCEPT(5) Bishop, Levy, Cole, Blake, Baker
   MODIFY(1) Frech
   NOOP(1) LeBlanc
Voter Comments:
 Frech> XF:sco-openserver-snmpd


CAN-2000-0151

Phase: Proposed (20000216)
Reference: SUSE:20000209 make-3.77-44
Reference: BID:981
Reference: URL:http://www.securityfocus.com/bid/981

Description:
GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.

Votes:

   ACCEPT(3) Bishop, Levy, Blake
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Cole
   REJECT(1) Christey
Voter Comments:
 Frech> XF:gnu-makefile-tmp-root
   (We have made assignment to two CANs. Requesting confirmation that this is
   not a duplicate of CAN-2000-0092: The BSD make program allows local users to
   modify files via a symlink attack when the -j option is being used.)
 Christey> To confirm Andre's question, this is being treated as
   different from CAN-2000-0092, based largely on the fact
   that the exploit is different.  I believe there was
   another reason for keeping these distinct, but that
   "deeper analysis" was not recorded :-(  While it's possible
   that this is the same bug from some common version of make,
   in the absence of other information we should probably
   keep these two split.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 CHANGE> [Christey changed vote from REVIEWING to REJECT]
 Christey> Taking a fresh look at the diff's for FreeBSD make:
   ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:01.make.asc
   And Debian make:
   http://security.debian.org/dists/slink/updates/source/make_3.77-5slink.diff.gz
   
   OK... now that I've hurt my brain looking at the code, while
   there are major differences in the surrounding code,
   ultimately both FreeBSD and Debian create an "outfile" file
   descriptor for the temporary file, within main() in main.c.
   In addition, child_execute_job() in job.c uses an outfile
   variable - for both sources.
   
   Perhaps FreeBSD reported the -j problem without seeing that it
   could come in from stdin as well, and/or Debian/etc. didn't realize
   that it was exploitable from job control, or maybe a combination of
   the two.  Regardless, the two problems are the same.
   
   Phew!  There goes a half-hour of my life that I'll never be
   able to get back...


CAN-2000-0153

Phase: Proposed (20000223)
Reference: BUGTRAQ:20000216 Doubledot bug in FrontPage FrontPage Personal Web Server.
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-15&msg=000801bf780a$9ad4b2e0$0100007f@localhost
Reference: BID:989
Reference: URL:http://www.securityfocus.com/bid/989

Description:
FrontPage Personal Web Server (PWS) allows remote attackers to read files via a .... (dot dot) attack.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
   REJECT(1) LeBlanc
Voter Comments:
 LeBlanc> I think this is the same as
   http://www.microsoft.com/technet/security/bulletin/ms99-010.asp
   If that is true, and you already have it logged, we don't want to have an
   entry for the same bug.
 Christey> MS:MS99-010 describes CVE-1999-0386.  Are there sufficient
   details to ensure that this is the same problem?
   
   See http://www.securityfocus.com/templates/archive.pike?list=1&msg=01bae51a$9ab232b0$0100007f@nordnode
   
 Frech> XF:pws-file-access
   (We currently have this issue assigned to this CAN and to CVE-1999-0386. I
   see that others have similar concerns that this is a duplicate; please
   confirm on current status of this candidate.)
 Christey> [note to self: review comments by Mark Burnett]


CAN-2000-0154

Phase: Modified (20000403-01)
Reference: NAI:20000215 ARCserve symlink vulnerability
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-15&msg=000101bf78af$94528870$4d2f45a1@jmagdych.na.nai.com
Reference: BID:988
Reference: URL:http://www.securityfocus.com/bid/988
Reference: MISC:http://www.sco.com/security/

Description:
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.

Votes:

   ACCEPT(1) Cole
   NOOP(2) LeBlanc, Wall
   REJECT(3) Frech, Levy, Christey
Voter Comments:
 Christey> DUPE CAN-2000-0224
 Frech> DUPE MITRE:CVE-2000-0224; XF:sco-openserver-arc-symlink
   Recommend moving BID reference to CVE-2000-0224.


CAN-2000-0155

Phase: Proposed (20000223)
Reference: BUGTRAQ:20000218 AUTORUN.INF Vulnerability
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-15&msg=000701bf79cd$fdb5a620$4c4342a6@mightye.org
Reference: BID:993
Reference: URL:http://www.securityfocus.com/bid/993

Description:
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:nt-autorun-notdefault
 Christey> Consider:
   http://support.microsoft.com/support/kb/articles/Q155/2/17.asp
   http://support.microsoft.com/support/kb/articles/Q136/2/14.asp


CAN-2000-0158

Phase: Modified (20000403-01)
Reference: NAI:20000215 Remote Vulnerability in the MMDF SMTP Daemon
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-15&msg=000001bf78af$6d0d47a0$4d2f45a1@jmagdych.na.nai.com
Reference: BUGTRAQ:20000218 MMDF
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-15&msg=200002181449.JAA03436@dragonfly.corp.home.net
Reference: SCO:SB-00.06a
Reference: URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-00.06a
Reference: BID:997
Reference: URL:http://www.securityfocus.com/bid/997

Description:
Buffer overflow in MMDF server allows remote attackers to gain privileges via a long MAIL FROM command to the SMTP daemon.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:sco-mmdf-bo


CAN-2000-0160

Phase: Modified (20000321-01)
Reference: BUGTRAQ:20000221 Microsoft signed software can be install software without prompting users
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-02-15&msg=20000221103938.T21312@securityfocus.com
Reference: XF:win-active-setup

Description:
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.

Votes:

   ACCEPT(3) Levy, LeBlanc, Wall
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> In a followup to Bugtraq, Juan Carlos Cuartango makes some
   clarifications, specifically that the code that is executed
   *must* be signed by Microsoft.
   
   See BUGTRAQ:20000222 MS signed softwrare privileges
   
   Microsoft sends some followups, including a statement that it
   will include notification.
   
   The question is, does this belong in CVE?  There is no known
   means of exploitation; on the other hand, it is related
   to privacy concerns.  Several posts to the Bugtraq list
   indicate that some people believe that unprompted installation
   is a significant concern.
 Frech> XF:win-active-setup
 Levy> BID 999
   
   I do consider this vulnerability as it allows a malicious web page
   to install *old* and *vulnerable* components signed by microsoft.
 LeBlanc> Fixed in MS00-042
 Christey> BID:999
   Also add XF:ie-active-setup-download ?


CAN-2000-0163

Phase: Proposed (20000223)
Reference: FREEBSD:FreeBSD-SA-00:03
Reference: URL:http://www.securityfocus.com/templates/advisory.html?id=2092
Reference: BID:996
Reference: URL:http://www.securityfocus.com/bid/996

Description:
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:asmon-ascpu-execute-commands
   (Not sims-slapd-logfiles)


CAN-2000-0167

Phase: Proposed (20000223)
Reference: NTBUGTRAQ:20000215 Crashing Inetinfo.exe by using a longfilename in the \mailroot\pickup directory
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0002&L=ntbugtraq&F=&S=&P=8800

Description:
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml extension in the pickup directory.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   REVIEWING(4) Levy, LeBlanc, Wall, Christey
Voter Comments:
 Frech> XF:iis-pickup-directory-dos
 Christey> BID:1819
   URL:http://www.securityfocus.com/bid/1819
 LeBlanc> Trying to get more info


CAN-2000-0173

Phase: Proposed (20000322)
Reference: SCO:SB-00.08a
Reference: URL:ftp://ftp.sco.com/SSE/security_bulletins/SB-00.08a

Description:
Vulnerability in the EELS system in SCO UnixWare 7.1.x allows remote attackers to cause a denial of service.

Votes:

   ACCEPT(2) Cole, Blake
   MODIFY(1) Frech
   NOOP(4) Ozancin, LeBlanc, Wall, Prosser
   REVIEWING(2) Levy, Christey
Voter Comments:
 Prosser> Although SCO is reporting the problem, there is too little info
   available to make an informed decision.  Unable to find anything
   anywhere on this.  It is an events logging system, so one would assume
   that there is a way to fill up the log and cause a system halt, but no
   way of confirming this with limited information.
 Christey> Perhaps we should create a content decision, say
   CD:VAGUE-ACK, which says whether it's reasonable to
   ACCEPT vendor-acknowledged problems that do not provide any
   salient details, as in this candidate as well as several
   others.
 Cole> I researched this a little more and you can change my NOOP to an
   ACCEPT
 Frech> XF:sco-eels-dos


CAN-2000-0176

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000228 Serv-U FTP-Server v2.4a showing real path
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-02/0417.html
Reference: BID:1016
Reference: URL:http://www.securityfocus.com/bid/1016

Description:
The default configuration of Serv-U 2.5d and earlier allows remote attackers to determine the real pathname of the server by requesting a URL for a directory or file that does not exist.

Votes:

   ACCEPT(4) Ozancin, Levy, Cole, Blake
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:servu-ftp-server-path(4060)


CAN-2000-0177

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000302 DNSTools v1.08 has no input validation
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-03/0000.html
Reference: BID:1028
Reference: URL:http://www.securityfocus.com/bid/1028

Description:
DNSTools CGI applications allow remote attackers to execute arbitrary commands via shell metacharacters.

Votes:

   ACCEPT(4) Ozancin, Levy, Cole, Blake
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:dnstools-invalid-input(4876)


CAN-2000-0187

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000227 EZ Shopper 3.0 shopping cart CGI remote command execution
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html
Reference: BID:1014
Reference: URL:http://www.securityfocus.com/bid/1014

Description:
EZShopper 3.0 loadpage.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(5) LeBlanc, Wall, Cole, Christey, Blake
Voter Comments:
 Christey> Since EZShopper is written in Perl, there is strong evidence
   that both the .. and metacharacter attack probably go
   through the same insecure open() call.  (Perl's open can
   either read a regular file, or read piped output from
   a command that is specified to the open).
 Frech> XF:ezshopper-loadpage-cgi(4044)


CAN-2000-0188

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000227 EZ Shopper 3.0 shopping cart CGI remote command execution
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-02/0356.html
Reference: BID:1014
Reference: URL:http://www.securityfocus.com/bid/1014

Description:
EZShopper 3.0 search.cgi CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack or execute commands via shell metacharacters.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(5) LeBlanc, Wall, Cole, Christey, Blake
Voter Comments:
 Christey> The exploit is different than CAN-2000-0187 by going through
   a different field in a different script, so maybe this should
   be kept separate, even though it's probably another open()
   call problem.
 Frech> XF:ezshopper-search-cgi(4045)


CAN-2000-0190

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000303 Aol Instant Messenger DoS vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-03/0016.html

Description:
AOL Instant Messenger (AIM) client allows remote attackers to cause a denial of service via a message with a malformed ASCII value.

Votes:

   ACCEPT(2) Cole, Blake
   MODIFY(1) Frech
   NOOP(2) Ozancin, LeBlanc
   REVIEWING(2) Levy, Wall
Voter Comments:
 Frech> XF:aolim-malformed-ascii-dos(4877)


CAN-2000-0197

Phase: Proposed (20000322)
Reference: NTBUGTRAQ:20000313 AT Jobs - Denial of serice/Privilege Elevation
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/current/0202.html
Reference: BID:1050
Reference: URL:http://www.securityfocus.com/bid/1050

Description:
The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.

Votes:

   ACCEPT(3) Levy, Cole, Baker
   MODIFY(1) Frech
   NOOP(2) Ozancin, Blake
   REJECT(1) LeBlanc
   REVIEWING(1) Wall
Voter Comments:
 LeBlanc> this is just bad security practice, not a vulnerability
 Frech> XF:nt-at-drive-mappings


CAN-2000-0198

Phase: Proposed (20000322)
Reference: NTBUGTRAQ:20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/current/0206.html
Reference: BUGTRAQ:20000314 Local / Remote Multiples Remote DoS Attacks in MERCUR v3.2* for Windows 98/NT Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/current/0137.html
Reference: BID:1051
Reference: URL:http://www.securityfocus.com/bid/1051

Description:
Buffer overflow in POP3 and IMAP servers in the MERCUR mail server suite allows remote attackers to cause a denial of service.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(4) LeBlanc, Wall, Cole, Blake
Voter Comments:
 Frech> XF:mercur-login-dos
   The following don't seem to be correct:
   Reference:
   URL:http://archives.neohapsis.com/archives/ntbugtraq/current/0206.html 
   Perhaps it is:
   http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0206.html
   Reference:
   URL:http://archives.neohapsis.com/archives/bugtraq/current/0137.html
   Perhaps it is:
   http://archives.neohapsis.com/archives/bugtraq/2000-03/0137.html


CAN-2000-0199

Phase: Proposed (20000322)
Reference: ISS:20000314 Vulnerability in Microsoft SQL Server 7.0 Encryption Used to Store Administrative Login ID
Reference: BID:1055
Reference: URL:http://www.securityfocus.com/bid/1055

Description:
When a new SQL Server is registered in Enterprise Manager for Microsoft SQL Server 7.0 and the "Always prompt for login name and password" option is not set, then the Enterprise Manager uses weak encryption to store the login ID and password.

Votes:

   ACCEPT(5) Ozancin, Levy, Wall, Cole, Blake
   MODIFY(1) Frech
   REVIEWING(2) LeBlanc, Christey
Voter Comments:
 LeBlanc> I think this may just be user error - I'd like more information.
 Frech> XF:mssql-weak-encryption
   ISS:Vulnerability in Microsoft SQL Server 7.0 Encryption Used to Store
   Administrative Login ID
   URL:http://xforce.iss.net/alerts/advise45.php3
 Christey> According to Scott Culp, this can only be reproduced if the
   SQL server is running in an unsafe mode that is not
   recommended by Microsoft: "To securely use SQL Server,
   Microsoft recommends using Windows Integrated Security. In
   Windows Integrated Security mode passwords are never stored,
   as your Windows Domain sign-on is used as the security
   identifier to the database server."
   
   We still must consider approving this candidate, however, as a
   user configuration error instead of a software flaw.
   CD:DESIGN-WEAK-ENCRYPTION applies in this case, so if we
   decide to include configuration problems in which a user
   intentionally selects weak encryption, then we might still
   approve this candidate.


CAN-2000-0203

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000228 Re: TrendMicro OfficeScan tmlisten.exe DoS
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=412FC0AFD62ED31191B40008C7E9A11A0D481D@srvnt04.previnet.it
Reference: BUGTRAQ:20000315 Trend Micro release patch for "OfficeScan DoS & Message Replay" V ulnerabilies
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com
Reference: MISC:http://www.antivirus.com/download/ofce_patch_35.htm
Reference: BID:1013
Reference: URL:http://www.securityfocus.com/bid/1013

Description:
The Trend Micro OfficeScan client tmlisten.exe allows remote attackers to cause a denial of service via malformed data to port 12345.

Votes:

   ACCEPT(4) Levy, Wall, Armstrong, Blake
   MODIFY(1) Frech
   NOOP(3) Ozancin, LeBlanc, Cole
Voter Comments:
 Frech> XF:trendmicro-tmlisten-dos


CAN-2000-0204

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000226 DOS in Trendmicro OfficeScan
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-02/0340.html
Reference: BUGTRAQ:20000315 Trend Micro release patch for "OfficeScan DoS & Message Replay" V ulnerabilies
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com
Reference: MISC:http://www.antivirus.com/download/ofce_patch_35.htm
Reference: BID:1013
Reference: URL:http://www.securityfocus.com/bid/1013

Description:
The Trend Micro OfficeScan client allows remote attackers to cause a denial of service by making 5 connections to port 12345, which raises CPU utilization to 100%.

Votes:

   ACCEPT(5) Levy, Wall, Cole, Armstrong, Blake
   MODIFY(1) Frech
   NOOP(2) Ozancin, LeBlanc
Voter Comments:
 Frech> XF:trendmicro-simultaneous-dos


CAN-2000-0205

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000303 TrendMicro OfficeScan, numerous security holes, remote files modification.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-03/0015.html
Reference: BUGTRAQ:20000315 Trend Micro release patch for "OfficeScan DoS & Message Replay" V ulnerabilies
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=D129BBE1730AD2118A0300805FC1C2FE038AF28B@209-76-212-10.trendmicro.com
Reference: MISC:http://www.antivirus.com/download/ofce_patch_35.htm
Reference: BID:1013
Reference: URL:http://www.securityfocus.com/bid/1013

Description:
Trend Micro OfficeScan allows remote attackers to replay administrative commands and modify the configuration of OfficeScan clients.

Votes:

   ACCEPT(3) Levy, Cole, Blake
   MODIFY(1) Frech
   NOOP(3) Ozancin, LeBlanc, Wall
Voter Comments:
 Frech> XF:trendmicro-admin-command(4041)


CAN-2000-0213

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000223 Sambar Server alert!
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=38B3E60A.6A84FEC3@cybcom.net
Reference: CONFIRM:http://www.sambar.com/session/highlight?url=/syshelp/history.htm&words=security+&color=red
Reference: XF:sambar-batfiles
Reference: BID:1002
Reference: URL:http://www.securityfocus.com/bid/1002

Description:
The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to execute commands via shell metacharacters.

Votes:

   ACCEPT(5) Frech, Levy, Cole, Armstrong, Blake
   NOOP(3) Ozancin, LeBlanc, Wall

CAN-2000-0214

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000224 How the password could be recover using FTP Explorer's registry!
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.10002242035500.30645-100000@unreal.sekure.org
Reference: BID:1003
Reference: URL:http://www.securityfocus.com/bid/1003

Description:
FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.

Votes:

   ACCEPT(4) Ozancin, Levy, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Blake
Voter Comments:
 Frech> XF:ftp-explorer-weak-pwd(4038)


CAN-2000-0216

Phase: Proposed (20000322)
Reference: NTBUGTRAQ:20000229 mailbombing DoS easily exploitable against mail systems using MS mail clients.
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q1/0176.html

Description:
Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(1) Ozancin
   REJECT(3) Levy, LeBlanc, Blake
   REVIEWING(1) Wall
Voter Comments:
 Blake> This is a configuration issue.  Should the fact that NT can be configured
   to accept a blank Admin password have a CVE entry?
 LeBlanc> This is documented as bad practice - if you have a wide distribution
   mailing list, you should only allow certain users to send mail to it.
   I don't think we want to start listing all possible admin errors as
   vulnerabilities.
 Frech> XF:microsoft-mail-client-dos(4893)
 Levy> I agree with all the above comments. Furthermore the delivery status
   notification RFC makes it clear that mailing list software should
   strip messages from DSN headers. I assume Microsoft's products are
   using the DSN standard and not something else.


CAN-2000-0219

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000223 redhat 6.0: single user boot security hole
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=200002230248.NAA19185@cairo.anu.edu.au
Reference: BID:1005
Reference: URL:http://www.securityfocus.com/bid/1005

Description:
Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.

Votes:

   ACCEPT(4) Ozancin, Levy, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Blake
   REVIEWING(1) Christey
Voter Comments:
 Ozancin> We need an additional CVE entry for other distributions that simply drop you
   into a root shell in single user mode.
 Christey> Based on Craig's comments, need to consider if this is an LOA
   issue.
 Frech> XF:redhat-single-user-auth(4026)


CAN-2000-0220

Phase: Proposed (20000322)
Reference: BUGTRAQ:20000225 Zonealarm exports sensitive data

Description:
ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.

Votes:

   ACCEPT(1) Armstrong
   MODIFY(1) Frech
   NOOP(4) Ozancin, LeBlanc, Wall, Cole
   REJECT(1) Blake
   REVIEWING(1) Levy
Voter Comments:
 Blake> Discussion on Bugtraq shows that this is a really marginal issue.  Very
   tough to come up with a viable attack scenario.  Also, it's part of how
   this class of software works, not a flaw in the cited package.  Might be
   possible to recast this into something more generic....
 Frech> XF:zonealarm-exposes-info


CAN-2000-0227

Phase: Modified (20010910-01)
Reference: BUGTRAQ:20000323 Local Denial-of-Service attack against Linux
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-03/0254.html
Reference: BUGTRAQ:20000328 Re: Local Denial-of-Service attack against Linux
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95421263519558&w=2
Reference: BID:1072
Reference: URL:http://www.securityfocus.com/bid/1072
Reference: XF:linux-domain-socket-dos(4186)
Reference: URL:http://xforce.iss.net/static/4186.php

Description:
The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max paremeter, which allows local users to cause a denial of service by requesting a large number of sockets.

Votes:

   ACCEPT(8) Frech, Ozancin, Levy, Cole, Armstrong, Collins, Blake, Baker
   NOOP(3) Magdych, Wall, Christey
Voter Comments:
 Christey> Fix typo: 'paremeter'
 Magdych> I remember when this came up...  seems like there were some wildly
   mixed results for the exploit.
 Christey> See http://marc.theaimsgroup.com/?l=bugtraq&m=95421263519558&w=2
   for Elias' summary of the mixed results.  It looks like
   enough people were able to replicate it that we should
   include it.
 Christey> Fix typo: "paremeter"
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0239

Phase: Proposed (20000412)
Reference: BUGTRAQ:20000315 Local / Remote DoS Attack in MERCUR WebView WebMail-Client 1.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95325335825295&w=2
Reference: URL:http://www.ussrback.com/labs36.html
Reference: BID:1056
Reference: URL:http://www.securityfocus.com/bid/1056
Reference: XF:mercur-webview-get-dos

Description:
Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mail_user parameter in the GET request.

Votes:

   ACCEPT(3) Frech, Levy, Baker
   NOOP(2) Magdych, Cole
Voter Comments:
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0241

Phase: Proposed (20000412)
Reference: BUGTRAQ:20000321 vqserver /........../
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=4.1.20000321084646.0095c7f0@olga.swip.net
Reference: BID:1068
Reference: URL:http://www.securityfocus.com/bid/1068
Reference: XF:vqserver-passwd-plaintext

Description:
vqSoft vqServer stores sensitive information such as passwords in cleartext in the server.cfg file, which allows attackers to gain privileges.

Votes:

   ACCEPT(3) Frech, Levy, Baker
   NOOP(2) Magdych, Cole
Voter Comments:
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0242

Phase: Proposed (20000412)
Reference: BUGTRAQ:20000325 Windmail allow web user get any file
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-03-22&msg=20000325224146.6839.qmail@securityfocus.com
Reference: XF:windmail-fileread
Reference: XF:windmail-pipe-command
Reference: BID:1073
Reference: URL:http://www.securityfocus.com/bid/1073

Description:
WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.

Votes:

   ACCEPT(2) Levy, Cole
   RECAST(1) Frech
   REJECT(2) Magdych, Christey
Voter Comments:
 Frech> Violation of fundamentum divisionis (that is, it's more than one issue) and
   a potential nitpick:
   - windmail-fileread: allows remote attackers to read arbitrary files
   - windmail-pipe-command: execute commands via shell metacharacters
   - The conjunction 'or' should be 'and', if you decide to stick with one CAN.
 Christey> As Andre basically said without naming content decisions,
   CD:SF-LOC says this should be split.
   
   HOWEVER - the author of the product says that WindMail isn't
   supposed to be a CGI script, and says that the pipe 
   character problem is not related to Geocel.  So should CVE
   record when someone runs a program that wasn't intended to
   be a CGI?  There may be a level of abstraction issue here.
   Note that Perl and shell interpreters in CGI-BIN are 
   already mentioned in CAN-1999-0509.  If we want to include
   "using a program that wasn't designed to be a CGI" as a
   problem, we should have a separate candidate.
   
   See the author's comments at:
   http://www.securityfocus.com/templates/archive.pike?list=1&msg=3.0.5.32.20000331114325.013af680@mailhost.geocel.com
   
   which also claims that the original announcer hasn't provided
   any more details after the author was unable to reproduce the
   problem.
 CHANGE> [Magdych changed vote from REVIEWING to REJECT]
 Magdych> After reviewing the author's comments, I'm inclined to think that this is more of a misconfiguration than a vulnerability.


CAN-2000-0244

Phase: Proposed (20000412)
Reference: BUGTRAQ:20000328 Citrix ICA Basic Encryption
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.BSO.4.20.0003290949280.2640-100000@naughty.monkey.org
Reference: BID:1077
Reference: URL:http://www.securityfocus.com/bid/1077

Description:
The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.

Votes:

   ACCEPT(2) Levy, Magdych
   MODIFY(1) Frech
   NOOP(1) Cole
Voter Comments:
 Frech> XF:citrix-encryption


CAN-2000-0247

Phase: Proposed (20000412)
Reference: BUGTRAQ:20000322 Local root compromise in GNQS 3.50.6 and 3.50.7
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-03/0236.html
Reference: MISC:http://ftp.gnqs.org/pub/gnqs/source/by-version-number/v3.50/Generic-NQS-3.50.8-ChangeLog.txt

Description:
Vulnerability in Generic-NQS (GNQS) allows local users to gain root privileges.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Magdych, Cole, Christey
   REVIEWING(1) Levy
Voter Comments:
 Christey> ADDREF FREEBSD:FreeBSD-SA-00:13
   ADDREF ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00%3A13-generic-nqs.asc
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:generic-nqs-local-root
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0248

Phase: Proposed (20000426)
Reference: ISS:20000424 Backdoor Password in Red Hat Linux Virtual Server Package
Reference: URL:http://xforce.iss.net/alerts/advise46.php3
Reference: REDHAT:RHSA-2000:014-10

Description:
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor passowrd that allows remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
   REJECT(1) Cox
Voter Comments:
 Christey> Typo fix: change "passowrd" to "password"
   ADDREF BID:1148
   ADDREF URL:http://www.securityfocus.com/bid/1148
 Christey> ADDREF XF:piranha-default-password
 Frech> XF:piranha-default-password
   In description, passowrd should be password.
 Cox> The "execute arbitrary commands" part is a seperate vulnerability,
   already assigned CVE-2000-0322.  The package was designed to have no
   password on installation, so "backdoor" does not apply.  When users
   install Piranha they are expected to add a password to the web
   administration GUI, it's a documented part of the procedure.  "The web
   GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux
   Piranha package installs with a default password" is accurate if it
   qualifies as an exposure.
 Christey> BUGTRAQ:20000425 piranha default password/exploit
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95668829621268&w=2
   
   Default accounts/passwords need to be accounted for in CVE,
   but the question is what level of abstraction to use - a
   separate CVE for each password, or one CVE for all passwords,
   or somewhere in the middle?  That is the crux of CD:CF-PASS.


CAN-2000-0250

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000414 qnx crypt comprimised
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0072.html
Reference: BID:1114
Reference: URL:http://www.securityfocus.com/bid/1114

Description:
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.

Votes:

   ACCEPT(2) Levy, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:qnx-weak-encryption(4866)


CAN-2000-0256

Phase: Proposed (20000426)
Reference: MS:MS00-028
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-028.asp
Reference: BID:1117
Reference: URL:http://www.securityfocus.com/bid/1117

Description:
Buffer overflows in htimage.exe and Imagemap.exe in FrontPage 97 and 98 Server Extensions allow a user to conduct activities that are not otherwise available through the web site, aka the "Server-Side Image Map Components" vulnerability.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:frontpage-ext-image-map
 Christey> Possibly related to BUGTRAQ:20000418 More vulnerabilities in FP
   http://archives.neohapsis.com/archives/bugtraq/2000-04/0116.html


CAN-2000-0259

Phase: Proposed (20000426)
Reference: MS:MS00-024
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-024.asp
Reference: BID:1105
Reference: URL:http://www.securityfocus.com/bid/1105

Description:
The default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromise the cryptographic keys of other users.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:winnt-cryptkeys-compromise
 Christey> Include "CryptoAPI" to facilitate search.
   MSKB:Q259496
   URL:http://www.microsoft.com/technet/support/kb.asp?ID=259496


CAN-2000-0266

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000418 IE 5 security vulnerablity - circumventing Cross-frame security policy using Java/JavaScript (and disabling Active Scripting is not that easy)
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=38FC6130.D6D178FD@nat.bg
Reference: BID:1121
Reference: URL:http://www.securityfocus.com/bid/1121

Description:
Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.

Votes:

   ACCEPT(4) Levy, LeBlanc, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:ie-java-crossframe-security
 Christey> May be a duplicate of CVE-2000-0465 according to my
   communications with Microsoft people.  CAN-2000-0028 may
   also be a variant.
 LeBlanc> MS00-039 


CAN-2000-0269

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-04-15&msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de
Reference: BID:1125
Reference: URL:http://www.securityfocus.com/bid/1125

Description:
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.

Votes:

   ACCEPT(2) Levy, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> ADDREF XF:emacs-local-eavesdrop
   Verify BID for this - is it 1125, 1126, or 1127?
   Also, ADDREF CALDERA:CSSA-2000-011.1 ??
   URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt
 Frech> XF:emacs-local-eavesdrop
 Christey> ADDREF MANDRAKE:MDKSA-2000:088 ?
   Also http://www.securityfocus.com/bid/2164, but is that a
   duplicate of BID:1125?


CAN-2000-0270

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-04-15&msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de
Reference: BID:1125
Reference: URL:http://www.securityfocus.com/bid/1126

Description:
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Levy
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> ADDREF XF:emacs-tempfile-creation
   Verify BID for this - is it 1125, 1126, or 1127?
   Also, ADDREF CALDERA:CSSA-2000-011.1 ??
   URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt
 Frech> XF:emacs-tempfile-creation
 Levy> Change BID reference to BID 1126


CAN-2000-0271

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000418 RUS-CERT Advisory 200004-01: GNU Emacs 20
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-04-15&msg=tg4s8zioxq.fsf@mercury.rus.uni-stuttgart.de
Reference: BID:1125
Reference: URL:http://www.securityfocus.com/bid/1125

Description:
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Levy
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> Verify BID for this - is it 1125, 1126, or 1127?
   Also, ADDREF CALDERA:CSSA-2000-011.1 ??
   URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt
   ADDREF XF:emacs-password-history
 Frech> XF:emacs-password-history
 Levy> Change BID reference to BID 1127


CAN-2000-0275

Phase: Proposed (20000426)
Reference: L0PHT:20000410 CRYPTOCard PalmToken PIN Extraction
Reference: URL:http://www.l0pht.com/advisories/cc-pinextract.txt
Reference: BUGTRAQ:20000410 CRYPTOAdmin 4.1 server with PalmPilot PT-1 token 1.04 PIN Extract ion
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0033.html
Reference: BID:1097
Reference: URL:http://www.securityfocus.com/bid/1097

Description:
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:cryptoadmin-weak-encryption


CAN-2000-0280

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000403 Win32 RealPlayer 6/7 Buffer Overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0018.html
Reference: BID:1088
Reference: URL:http://www.securityfocus.com/bid/1088

Description:
Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of service via a long Location URL.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:realserver-ramgen-dos


CAN-2000-0281

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000326 neat little napster bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-03/0277.html
Reference: BUGTRAQ:20000330 Napster, Inc. response to Colten Edwards
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-03/0299.html

Description:
Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.

Votes:

   NOOP(2) Wall, Cole
   REJECT(3) Frech, Levy, Baker
Voter Comments:
 Frech> Does not meet CVE candidate requirements. The problem was remedied on the
   server end, and no fault exists at the client. Based on
   http://archives.neohapsis.com/archives/bugtraq/2000-03/0299.html:
   Approximately one hour after receiving the post from BugTraq, 
   Napster's servers were patched to prevent this from occurring. 
   Users of the Napster Win32 client software are NOT vulnerable. 
 Baker> Agree with Andre


CAN-2000-0284

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000416 imapd4r1 v12.264
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0074.html
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0085.html
Reference: BID:1110
Reference: URL:http://www.securityfocus.com/bid/1110

Description:
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> ADDREF FREEBSD:FreeBSD-SA-00:14
   URL:http://www.securityfocus.com/templates/advisory.html?id=2179
 Frech> XF:imap-mailserver-bo


CAN-2000-0286

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000416 xfs
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.10004161525040.1186-200000@localhost
Reference: BID:1111
Reference: URL:http://www.securityfocus.com/bid/1111

Description:
X fontserver xfs allows local users to cause a denial of service via malformed input to the server.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REJECT(2) Levy, Christey
Voter Comments:
 Frech> XF:redhat-fontserver-dos
   POTENTIAL DUPE: CAN-2000-0263: The X font server xfs in Red Hat Linux 6.x
   allows an attacker to cause a denial of service via a malformed request.
 Christey> As Andre observed, this is a duplicate of CAN-2000-0263.


CAN-2000-0288

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000412 Infonautic's getdoc.cgi may allow unauthorized access to documents
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0049.html

Description:
Infonautics getdoc.cgi allows remote attackers to bypass the payment phase for accessing documents via a modified form variable.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REVIEWING(2) Levy, Christey
Voter Comments:
 Frech> XF:http-cgi-infonautics-getdoc
 Christey> CD:EX-ONLINE-SVC applies here.  This may be a vulnerability in
   an online service (the search engines used by Infonautics)
   which poses no risk to anyone but the company itself.


CAN-2000-0291

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000416 StarOffice 5.1
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0077.html
Reference: BID:1112
Reference: URL:http://www.securityfocus.com/bid/1112

Description:
Buffer overflow in Star Office 5.1 allows attackers to cause a denial of service by embedding a long URL within a document.

Votes:

   ACCEPT(2) Levy, Dik
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:staroffice-long-url-bo


CAN-2000-0293

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000421 local user can delete arbitrary files on SuSE-Linux
Reference: BID:1130
Reference: URL:http://www.securityfocus.com/bid/1130

Description:
aaa_base in SuSE Linux 6.3, and cron.daily in earlier versions, allow local users to delete arbitrary files by creating files whose names include spaces, which are then incorrectly interpreted by aaa_base when it deletes expired files from the /tmp directory.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> ADDREF SUSE:20000502 aaabase < 2000.5.2
   URL: http://www.suse.de/de/support/security/suse_security_announce_47.txt
   
   This advisory references another problem that is listed in
   CAN-2000-0433.
 Frech> XF:aaabase-file-deletion


CAN-2000-0295

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000420 Remote vulnerability in LCDproc 0.4
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.3.96.1000421010946.15318I-200000@schizo.strange.net
Reference: BID:1131
Reference: URL:http://www.securityfocus.com/bid/1131

Description:
Buffer overflow in LCDproc allows remote attackers to gain root privileges via the screen_add command.

Votes:

   ACCEPT(2) Levy, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:lcdproc-remote-overflow


CAN-2000-0299

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000404 WebObjects DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0020.html

Description:
Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Williams, Wall, Cole, Christey
   REVIEWING(1) Levy
Voter Comments:
 Christey> ADDREF XF:webobjects-post-dos
 Frech> XF:webobjects-post-dos
 Christey> See http://til.info.apple.com/techinfo.nsf/artnum/n75087
   Document says:
   "A request with a large, malformed http header can crash a WOApp"
   (Apple reference #2470254) appears to be the acknowledgement needed.
   
   Is this sufficient acknowledgement?  This is dated AUgust 24,
   but the initial disclosure occurred on April 4.
 Christey> BID:1896


CAN-2000-0300

Phase: Proposed (20000426)
Reference: BUGTRAQ:20000405 PcAnywhere weak password encryption
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000406030958.23902.qmail@securityfocus.com
Reference: BID:1093
Reference: URL:http://www.securityfocus.com/bid/1093

Description:
The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt PcAnywhere or NT domain accounts.

Votes:

   ACCEPT(3) Levy, Cole, Prosser
   MODIFY(1) Frech
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:pcanywhere-weak-encryption
 Prosser> http://service2.symantec.com/SUPPORT/pca.nsf/pfdocs/1999022312571812
   Upgraded in pcA 10


CAN-2000-0312

Phase: Proposed (20010214)
Reference: OPENBSD:19990830 In cron(8), make sure argv[] is NULL terminated in the fake popen() and run sendmail as the user, not as root.
Reference: URL:http://www.openbsd.org/errata25.html#cron

Description:
cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.

Votes:

   ACCEPT(3) Baker, Cole, Collins
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:cron-sendmail-root(3335)
   Seems like this issue is not just OpenBSD, and is described
   differently by other vendors:
   SuSE Security Announcement #15	Security hole in cron
   http://www.suse.de/de/support/security/suse_security_announce_15.txt
   Red Hat, Inc. Security Advisory RHSA-1999:030-02	Buffer overflow in
   cron daemon
   http://www.redhat.com/support/errata/rh52-errata-general.html#vixie-cron
   Caldera Systems, Inc. Security Advisory CSSA-1999-023.0	serious security
   problem in cron
   http://www.calderasystems.com/support/security/advisories/CSSA-1999-023.0.tx
   t
   All are dated on or around 1999-08-27 to 1999-08-30.
   Also, may overlap with CVE-1999-0769: Vixie Cron on Linux systems allows
   local users to set parameters of sendmail commands via the MAILTO
   environmental variable.
 Christey> See Andre's comments, but I believe this is different than
   CVE-1999-0769.  Also consider CVE-1999-0768 and CAN-1999-0872
   (Vixie Cron buffer overflow via MAILTO), 


CAN-2000-0317

Phase: Proposed (20000518)
Reference: BUGTRAQ:20000424 Solaris 7 x86 lpset exploit.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0192.html
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0236.html
Reference: BUGTRAQ:20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95729763119559&w=2
Reference: SUNBUG:4334568
Reference: BID:1138
Reference: URL:http://www.securityfocus.com/bid/1138

Description:
Buffer overflow in Solaris 7 lpset allows local users to gain root privileges via a long -r option.

Votes:

   ACCEPT(3) Baker, Levy, Cole
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Christey
   RECAST(1) Dik
Voter Comments:
 Dik> there's a lot of confusion in this one. 
   These point to buffer overflows:
   Reference: BUGTRAQ:20000424 Solaris 7 x86 lpset exploit.
   Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0192.html
   Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0236.html
   But these point to dlopen() in libprint that doesnt' check pathnames:
   Reference: BUGTRAQ:20000427 Re: Solaris/SPARC 2.7 lpset exploit (well not likely !)
   Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95729763119559&w=2
   Reference: SUNBUG:4334568
   And this is a bufferoverflow again:
   Reference: BID:1138
   Reference: URL:http://www.securityfocus.com/bid/1138
 Frech> XF:solaris-lpset-bo
 Christey> ADDREF SUN:00195?  Need to check with Casper.


CAN-2000-0321

Phase: Proposed (20000518)
Reference: BUGTRAQ:20000424 Buffer Overflow in version .14
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-04/0190.html
Reference: BID:1147
Reference: URL:http://www.securityfocus.com/bid/1147

Description:
Buffer overflow in IC Radius package allows a remote attacker to cause a denial of service via a long user name.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(4) Baker, LeBlanc, Wall, Cole
   REJECT(1) Christey
Voter Comments:
 Frech> XF:icradius-username-bo
   Every reference I pull up shows the product's name as ICRADIUS. See
   http://mysql.eunet.fi/Downloads/Contrib/icradius.README
 Christey> In a followup, Alan DeKok (aland@FREERADIUS.ORG) says that
   this could occur in other RADIUS servers also; however, the
   bug could only be exploited if someone has altered the
   configuration file, which shouldn't normally be modifiable
   by anyone else.
   
   So, this should be REJECTed since the bug doesn't directly give
   anyone else any additional privileges or access.
 Christey> Alan DeKok <aland@FREERADIUS.ORG> says it applies to other RADIUS
   programs also, *however* since it needs a valid username, only
   the RADIUS owner can exploit it by changing the config file.  But
   if the config file can be written by others - well, that's still
   a potential risk, but you've probably got bigger problems then.
   - http://marc.theaimsgroup.com/?l=bugtraq&m=95671883515060&w=2
   Look at ChangeLog at ftp://ftp.cheapnet.net/pub/icradius/ChangeLog
   
   Possible confirmation in 0.15: "sql_getvpdata now dynamically
   allocates buffer sizes for sql queries to avoid over runs"
   
   But that's a bit general.
   
   Alan Kok said that Cistron and other RADIUS servers were affected; the
   ICRADIUS changelog says to check the Cistron logs for other possible
   bug fixes, since ICRADIUS uses Cistron codebase.  Go back to
   freeradius.org and find link to Cistron at
   http://www.miquels.cistron.nl/radius/
   
   Cistron changelog at http://www.miquels.cistron.nl/radius/ChangeLog It
   has different version numbers - go back to ICRADIUS changelog to find
   rought equivalents.  ICRADIUS 0.15 uses Cistron 1.6.3 patches, so
   start from there.
   
   No apparent problems in 1.6.3 or 1.6.4, but 1.6.1 says: "Fix all
   strcpy(), strcat(), sprintf() and sccanf() calls for buffer
   overflows."  So perhaps the problem was fixed then?  Or maybe the
   vulnerable sscanf() call was missed and/or disregarded because it was
   believed that the hostname could be trusted since it came from a
   well-controlled configuration file?


CAN-2000-0325

Phase: Modified (20020222-01)
Reference: MS:MS99-030
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms99-030.asp
Reference: XF:jet-vba-shell(3155)
Reference: URL:http://xforce.iss.net/static/3155.php
Reference: BID:548
Reference: URL:http://www.securityfocus.com/bid/548

Description:
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulnerability.

Votes:

   ACCEPT(5) Baker, Wall, Cole, Armstrong, Prosser
   MODIFY(1) Frech
   REJECT(1) LeBlanc
   REVIEWING(1) Christey
Voter Comments:
 LeBlanc> - same as CAN-1999-1011
   If I'm misunderstanding something here, please correct me.  In fact, it has
   the same bulletin as a reference.
 Frech> XF:jet-vba-shell
 Prosser> This entry is not the same as "now" CVE-1999-1011. That entry is "The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands."  This one should be correct.
 Christey> BUGTRAQ:19990525 Advisory: NT ODBC Remote Compromise
   http://marc.theaimsgroup.com/?l=bugtraq&m=92765973107637&w=2
   NTBUGTRAQ:19990526 Advisory: NT ODBC Remote Compromise
   http://marc.theaimsgroup.com/?l=ntbugtraq&m=92781907215748&w=2
 Christey> The Microsoft advisory itself describes two separate
   vulnerabilities, calling the TEXT I-ISAM problem
   (CVE-2000-0323) a variant of the VBA Shell problem (this
   CAN).  In addition, CVE-2000-0323 does *not* appear in Jet
   4.0, while this one does.  Since one problem appears in a
   different version than the other, CD:SF-LOC suggests keeping
   these candidates SPLIT.
   
   BID:548
   http://www.securityfocus.com/bid/548
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Need to clarify whether the Bugtraq/NTBugtraq posts are
   really describing the same issue (those are BID:286).


CAN-2000-0326

Phase: Proposed (20000518)
Reference: BID:1151
Reference: URL:http://www.securityfocus.com/bid/1151
Reference: CONFIRM:http://support.on.com/support/mmxp.nsf/31af51e08bcc93eb852565a90056138b/11af70407a16b165852568c50056a952?OpenDocument

Description:
Meeting Maker uses weak encryption (a polyalphabetic substitution cipher) for passwords, which allows remote attackers to sniff and decrypt passwords for Meeting Maker accounts.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(4) LeBlanc, Wall, Cole, Christey
Voter Comments:
 Frech> XF:meetingmaker-weak-encryption
 Christey> Add original Bugtraq reference at:
   http://archives.neohapsis.com/archives/bugtraq/2000-04/0223.html
   Also ADDREF XF:meetingmaker-weak-encryption


CAN-2000-0333

Phase: Proposed (20000518)
Reference: BUGTRAQ:20000502 Denial of service attack against tcpdump
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.SOL.4.10.10005021942380.2077-100000@paranoia.pgci.ca
Reference: BID:1165
Reference: URL:http://www.securityfocus.com/bid/1165

Description:
tcpdump, Ethereal, and other sniffer packages allow remote attackers to cause a denial of service via malformed DNS packets in which a jump offset refers to itself, which causes tcpdump to enter an infinite loop while decompressing the packet.

Votes:

   ACCEPT(3) Baker, Levy, Armstrong
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:sniffer-dns-decode-dos


CAN-2000-0343

Phase: Proposed (20000518)
Reference: BUGTRAQ:20000502 spj-003-000 - S0ftPj Advisory
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=200005021736.TAA01991@ALuSSi
Reference: BID:1158
Reference: URL:http://www.securityfocus.com/bid/1158

Description:
Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary commands via a long MAIL FROM mail header.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(2) Frech, Christey
   NOOP(2) Wall, Armstrong
Voter Comments:
 Frech> XF:sniffit-lmail-bo
 Christey> This issue was rediscovered.
   ADDREF BUGTRAQ:20020119 remote buffer overflow in sniffit
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101167452712383&w=2
   ADDREF BUGTRAQ:20000525 `sniffit -L mail' vulnerabilities
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95928090612990&w=2
   
   I reviewed the patch that was claimed in the 20020119 Bugtraq
   post, and it could well address the issue.  However, since the
   patch is also dated around the time of the original Bugtraq
   post, *and* it says that it's addressing an issue that's
   discussed on Bugtraq, that is sufficient to establish
   acknowledgement.
 CHANGE> [Christey changed vote from NOOP to MODIFY]
 Christey> XF:sniffit-normmail-l-bo(7933)
   URL:http://www.iss.net/security_center/static/7933.php


CAN-2000-0345

Phase: Proposed (20000518)
Reference: BUGTRAQ:20000502 Possible issue with Cisco on-line help?
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000502222246.28423.qmail@securityfocus.com
Reference: BID:1161
Reference: URL:http://www.securityfocus.com/bid/1161

Description:
The on-line help system options in Cisco routers allows non-privileged users without "enabled" access to obtain sensitive information via the show command.

Votes:

   ACCEPT(1) Prosser
   MODIFY(1) Frech
   NOOP(5) Baker, Levy, Wall, Cole, Armstrong
   REJECT(1) Balinsky
Voter Comments:
 Levy> Arguably this is not a vulnerability. Cisco replying saying this
   is standard behaviour that was simply not well documented. They have
   no plans to change it and will simply document it better.
 Frech> XF:cisco-online-help
 Balinsky> As noted in a bugtraq posting by Lisa Napier from Cisco's Product Security Incident Response Team, this is a poorly documented feature. This is intended behavior, and does not represent a vulnerability in Cisco's opinion.
   http://www.securityfocus.com/frames/?content=/templates/archive.pike?list=1&mid=59434
 Prosser> Although Lisa Napier did say this issue was "functioning as designed", it was not intended to allow unprivileged access.  Lisa did indicate that Cisco would be updating instructions on configuration to ensure proper user privileges.  So, this should be considered IMHO an "exposure" vice a vulnerability, but security-related none the less.
   http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000502222246.28423.qmail@securityfocus.com
   
   http://www.securityfocus.com/bid/1161


CAN-2000-0355

Phase: Proposed (20000524)
Reference: SUSE:19990920 Security hole in pbpg
Reference: URL:http://www.suse.de/de/support/security/suse_security_announce_21.txt
Reference: XF:linux-pb-fileread
Reference: XF:linux-pg-fileread

Description:
pg and pb in SuSE pbpg 1.x package allows an attacker to read arbitrary files.

Votes:

   ACCEPT(2) Frech, Levy
   NOOP(1) Christey
Voter Comments:
 Christey> ADDREF BID:1271
 Christey> ADDREF BID:1271
   URL:http://www.securityfocus.com/bid/1271


CAN-2000-0357

Phase: Proposed (20000524)
Reference: REDHAT:RHSA-1999:058-01
Reference: URL:http://www.redhat.com/corp/support/errata/RHSA1999058-01.html

Description:
ORBit and esound in Red Hat Linux 6.1 do not use sufficiently random numbers, which allows local users to guess the authentication keys.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> ADDREF BID:1275
 Christey> ADDREF BID:1275
   URL:http://www.securityfocus.com/bid/1275
 Frech> XF:linux-orbit-esound-authentication-keys


CAN-2000-0358

Phase: Proposed (20000524)
Reference: REDHAT:RHSA-1999:058-01
Reference: URL:http://www.redhat.com/corp/support/errata/RHSA1999058-01.html

Description:
ORBit and gnome-session in Red Hat Linux 6.1 allows remote attackers to crash a program.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> ADDREF BID:1283
 Christey> ADDREF BID:1283
   URL:http://www.securityfocus.com/bid/1283
 Frech> XF:linux-orbit-gnome-session-dos


CAN-2000-0364

Phase: Proposed (20000524)
Reference: BUGTRAQ:19990606 RedHat 6.0, /dev/pts permissions bug when using xterm
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92877527701347&w=2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92886009012161&w=2
Reference: REDHAT:RHSA1999014_01
Reference: URL:http://www.redhat.com/corp/support/errata/RHSA1999014_01.html
Reference: BID:309
Reference: URL:http://www.securityfocus.com/bid/309

Description:
screen and rxvt in Red Hat Linux 6.0 do not properly set the modes of tty devices, which allows local users to write to other ttys.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:linux-tty-improper-mode
 Christey> BUGTRAQ:19990607 Re: RedHat 6.0, /dev/pts permissions bug when using xterm
   http://marc.theaimsgroup.com/?l=bugtraq&m=92886008912147&w=2
   BUGTRAQ:19990607 Re: Red Hat 6.0, /dev/pts permissions bug when using xterm
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92886358415964&w=2


CAN-2000-0365

Phase: Proposed (20000524)
Reference: BUGTRAQ:19990606 RedHat 6.0, /dev/pts permissions bug when using xterm
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92877527701347&w=2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92886009012161&w=2
Reference: REDHAT:RHSA1999014_01
Reference: URL:http://www.redhat.com/corp/support/errata/RHSA1999014_01.html
Reference: BID:308
Reference: URL:http://www.securityfocus.com/bid/308

Description:
Red Hat Linux 6.0 installs the /dev/pts file system with insecure modes, which allows local users to write to other tty devices.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:linux-dev-insecure-mode
 Christey> BUGTRAQ:19990607 Re: RedHat 6.0, /dev/pts permissions bug when using xterm
   http://marc.theaimsgroup.com/?l=bugtraq&m=92886008912147&w=2
   BUGTRAQ:19990607 Re: Red Hat 6.0, /dev/pts permissions bug when using xterm
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=92886358415964&w=2


CAN-2000-0383

Phase: Modified (20000706-01)
Reference: BUGTRAQ:20000507 AOL Instant Messenger
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=002401bfb918$7310d5a0$1ef084ce@karemor.com
Reference: XF:aolim-file-path
Reference: BID:1180
Reference: URL:http://www.securityfocus.com/bid/1180

Description:
The file transfer component of AOL Instant Messenger (AIM) reveals the physical path of the transferred file to the remote recipient.

Votes:

   ACCEPT(5) Frech, Ozancin, Levy, Cole, Stracener
   NOOP(2) Christey, Prosser
Voter Comments:
 Christey> Normalize the Bugtraq reference!


CAN-2000-0384

Phase: Proposed (20000615)
Reference: L0PHT:20000508 NetStructure 7180 remote backdoor vulnerability
Reference: URL:http://www.lopht.com/advisories/ipivot7110.html
Reference: L0PHT:20000508 NetStructure 7110 console backdoor
Reference: URL:http://www.l0pht.com/advisories/ipivot7180.html
Reference: CONFIRM:http://216.188.41.136/
Reference: XF:netstructure-root-compromise
Reference: XF:netstructure-wizard-mode
Reference: BID:1182
Reference: URL:http://www.securityfocus.com/bid/1182
Reference: BID:1183
Reference: URL:http://www.securityfocus.com/bid/1183

Description:
NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access.

Votes:

   ACCEPT(5) Frech, Ozancin, Levy, Stracener, Prosser
   NOOP(1) Cole

CAN-2000-0385

Phase: Proposed (20000615)
Reference: MISC:http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html
Reference: CONFIRM:http://www.filemaker.com/support/webcompanion.html
Reference: XF:macos-filemaker-xml
Reference: XF:macos-filemaker-email

Description:
FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email capabilities.

Votes:

   ACCEPT(4) Frech, Ozancin, Stracener, Prosser
   MODIFY(1) Levy
   NOOP(1) Cole
Voter Comments:
 Levy> Reference: BID 1159


CAN-2000-0386

Phase: Proposed (20000615)
Reference: MISC:http://www.blueworld.com/blueworld/news/05.01.00-FM5_Security.html
Reference: CONFIRM:http://www.filemaker.com/support/webcompanion.html
Reference: XF:macos-filemaker-anonymous-email

Description:
FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.

Votes:

   ACCEPT(4) Frech, Ozancin, Stracener, Prosser
   MODIFY(1) Levy
   NOOP(1) Cole
Voter Comments:
 Levy> Reference: BID 1159


CAN-2000-0400

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000516 MICROSOFT SECURITY FLAW?
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95868514521257&w=2
Reference: BID:1221
Reference: URL:http://www.securityfocus.com/bid/1221
Reference: XF:ie-active-movie-control

Description:
The Microsoft Active Movie ActiveX Control in Internet Explorer 5 does not restrict which file types can be downloaded, which allows an attacker to download any type of file to a user's system by encoding it within an email message or news post.

Votes:

   ACCEPT(4) Frech, Ozancin, Levy, Wall
   NOOP(2) Cole, Stracener
   REJECT(1) Christey
   REVIEWING(1) LeBlanc
Voter Comments:
 LeBlanc> COMMENT - this definately will not work if the user has applied the security
   patch. I don't know whether this repros right now, and have sent a query to
   find out.
 Christey> Is this now documented in MS:MS00-042?
 LeBlanc> the problem isn't in the Active Movie control.  What was
   observed was a symptom of another problem that got fixed in
   some bulletin or another - I don't remember.
 Christey> According to Scott Culp, this existed because 
   the patch for the Cache Bypass vulnerability (MS:MS00-046,
   CAN-2000-0621) was not applied, so this should be REJECTed
   as a duplicate of CAN-2000-0621.


CAN-2000-0401

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000525 Alert: PDG Cart Overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95928319715983&w=2
Reference: NTBUGTRAQ:20000525 Alert: PDG Cart Overflows
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=95928667119963&w=2
Reference: CONFIRM:http://www.pdgsoft.com/Security/security2.html
Reference: BID:1256
Reference: URL:http://www.securityfocus.com/bid/1256

Description:
Buffer overflows in redirect.exe and changepw.exe in PDGSoft shopping cart allow remote attackers to execute arbitrary commands via a long query string.

Votes:

   ACCEPT(2) Levy, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:pdgsoft-changepw-bo
   XF:pdgsoft-redirect-bo


CAN-2000-0412

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000510 KNapster Vulnerability Compromises User-readable Files
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0124.html
Reference: BUGTRAQ:20000510 Gnapster Vulnerability Compromises User-readable Files
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0127.html
Reference: FREEBSD:FreeBSD-SA-00:18
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:18-gnapster.adv
Reference: XF:gnapster-view-files
Reference: BID:1186
Reference: URL:http://www.securityfocus.com/bid/1186

Description:
The gnapster and knapster clients for Napster do not properly restrict access only to MP3 files, which allows remote attackers to read arbitrary files from the client by specifying the full pathname for the file.

Votes:

   ACCEPT(3) Ozancin, Levy, Stracener
   MODIFY(1) Frech
   NOOP(2) Cole, Prosser
Voter Comments:
 Frech> ADDREF XF:knapster-view-files


CAN-2000-0413

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000506 shtml.exe reveal local path of IIS web directory
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0084.html
Reference: BID:1174
Reference: URL:http://www.securityfocus.com/bid/1174
Reference: XF:iis-shtml-reveal-path

Description:
The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the path.

Votes:

   ACCEPT(6) Frech, Ozancin, Levy, LeBlanc, Cole, Stracener
   MODIFY(1) Prosser
   NOOP(1) Christey
Voter Comments:
 Prosser> additional source Security BugWare
   http://161.53.42.3/~crv/security/bugs/NT/fpse10.html  comments on page re:
   "MS soon to be released service release OSR 1.2 with needed changes." 
   I haven't located anything on MS site yet.  Anyone help? 
 Christey> BID:1433 may also refer to this issue.
 Christey> [note to self: review comments by Mark Burnett]
 Christey> CHANGEREF XF:iis-shtml-reveal-path XF:frontpage-ext-shtml-path(4439)
 LeBlanc> Fixes are up on site now - have been for a while. 


CAN-2000-0415

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000512 Overflow in Outlook Express 4.* - too long filenames with graphic format extension
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0140.html
Reference: BID:1195
Reference: URL:http://www.securityfocus.com/bid/1195

Description:
Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name.

Votes:

   ACCEPT(3) Ozancin, Levy, Wall
   MODIFY(1) Frech
   NOOP(3) Cole, Stracener, Christey
   REJECT(1) LeBlanc
Voter Comments:
 LeBlanc> The poster re-discovered a vulnerability we patched two years
   ago, in
   http://www.microsoft.com/technet/security/bulletin/ms98-008.asp
   Microsoft posted a response to BugTraq when this one went
   public, and reminded them that we'd already patched it.
   
   BTW, I think we want to try and pay attention to follow-ups to
   these threads in order to minimize noise in the process.
 Christey> Based on David's comments, this is covered by CAN-1999-0002.
   However, that candidate may wind up being SPLIT, so I will
   keep this one around for the moment.
   
   With respect to watching followups, we are relying quite
   a bit on other data feeds instead of doing our own reviews
   of all the different data sources.  The data feeds may report
   these problems as new before corrections are posted.
   Followups do often lend additional information to the
   candidates, and as is the case with this one, we will
   often catch the discrepancy before the candidate becomes an
   official entry, whether by MITRE's own analysis or by that
   of other Board members.
 Frech> XF:outlook-image-long-filename


CAN-2000-0420

Phase: Proposed (20000615)
Reference: NTBUGTRAQ:20000511 ISS SAVANT Advisory 00/26
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0112.html
Reference: BID:1198
Reference: URL:http://www.securityfocus.com/bid/1198

Description:
The default configuration of SYSKEY in Windows 2000 stores the startup key in the registry, which could allow an attacker tor ecover it and use it to decrypt Encrypted File System (EFS) data.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(2) Cole, Stracener
   REJECT(1) LeBlanc
   REVIEWING(1) Wall
Voter Comments:
 LeBlanc> This is not a vulnerability.  It is essentially an advisory on best
   practices. Also, the description is extremely inaccurate. If I weren't
   intimately familiar with the issue, I would not be able to understand it
   from this. Syskey, when applied at lower levels, has well-documented
   limitations.  
 Stracener> "..to recover"
 Frech> XF:win2k-syskey-default-configuration
   Change "tor ecover" to "to recover"


CAN-2000-0422

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000504 Alert: DMailWeb buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95749276827558&w=2
Reference: XF:http-cgi-dmailweb-bo
Reference: BID:1171
Reference: URL:http://www.securityfocus.com/bid/1171

Description:
Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.

Votes:

   ACCEPT(5) Frech, Ozancin, Levy, Stracener, Prosser
   NOOP(1) Cole

CAN-2000-0423

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000505 Alert: DNewsWeb buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95764950403250&w=2
Reference: XF:http-cgi-dnews-bo
Reference: BID:1172
Reference: URL:http://www.securityfocus.com/bid/1172

Description:
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd, and utag.

Votes:

   ACCEPT(5) Frech, Ozancin, Levy, Stracener, Prosser
   NOOP(1) Cole

CAN-2000-0429

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000427 Alert: Cart32 secret password backdoor (CISADV000427)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95686068203138&w=2
Reference: CONFIRM:http://www.cart32.com/kbshow.asp?article=c048

Description:
A backdoor password in Cart32 3.0 and earlier allows remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(3) Ozancin, Stracener, Prosser
   MODIFY(2) Frech, Levy
   NOOP(1) Cole
Voter Comments:
 Levy> Reference: BID 1153
 Frech> XF:cart32-admin-password


CAN-2000-0433

Phase: Proposed (20000615)
Reference: SUSE:20000502 aaabase < 2000.5.2
Reference: URL:http://www.suse.de/de/support/security/suse_security_announce_47.txt
Reference: XF:aaabase-execute-dot-files

Description:
The SuSE aaa_base package installs some system accounts with home directories set to /tmp, which allows local users to gain privileges to those accounts by creating standard user startup scripts such as profiles.

Votes:

   ACCEPT(5) Frech, Ozancin, Levy, Cole, Stracener
   MODIFY(1) Prosser
Voter Comments:
 Prosser> add source:  
   SecurityFocus
   BID1357
   SuSE Linux aaabase User Account with /tmp Home Vulnerability
   http://www.securityfocus.com/bid/1357
 CHANGE> [Levy changed vote from REVIEWING to ACCEPT]


CAN-2000-0434

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000516 Allmanage.pl Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0167.html
Reference: BID:1217
Reference: URL:http://www.securityfocus.com/bid/1217

Description:
The administrative password for the Allmanage web site administration software is stored in plaintext in a file which could be accessed by remote attackers.

Votes:

   ACCEPT(3) Ozancin, Levy, Stracener
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:http-cgi-allmanage-plaintext-admin


CAN-2000-0444

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000524 HP Web JetAdmin Version 6.0 Remote DoS attack Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0277.html
Reference: XF:hp-jetadmin-malformed-url-dos
Reference: BID:1246
Reference: URL:http://www.securityfocus.com/bid/1246

Description:
HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.

Votes:

   ACCEPT(4) Frech, Levy, Stracener, Prosser
   NOOP(2) Wall, Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> ADDREF CONFIRM:http://www.hp.com/cposupport/networking/support_doc/bpj06522.html
 Christey> HP:HPSBUX0006-116 ?
   XF:jetadmin-network-dos
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Prosser> Vendor acknowledged in HP Bulletin HPSBUX0006-116 with upgrade info.


CAN-2000-0449

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000525 Omnis Weak Encryption - Many products affected
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0311.html
Reference: BID:1255
Reference: URL:http://www.securityfocus.com/bid/1255

Description:
Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.

Votes:

   ACCEPT(2) Levy, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:omnis-studio-weak-encryption


CAN-2000-0450

Phase: Proposed (20000615)
Reference: BUGTRAQ:20000518 FW: Security Notice: Big Brother System and Network Monitor
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0216.html
Reference: BID:1257
Reference: URL:http://www.securityfocus.com/bid/1257

Description:
Vulnerability in bbd server in Big Brother System and Network Monitor allows an attacker to execute arbitrary commands.

Votes:

   ACCEPT(3) Ozancin, Levy, Stracener
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
   RECAST(1) LeBlanc
Voter Comments:
 LeBlanc> I have no idea what this one is talking about from the description.  I also
   don't think it involves "Network Monitor", which is a component of Windows
   NT/Windows 2000. This should be clarified.
 Frech> XF:big-brother-bbd-bo
 Christey> The original advisory, as forwarded to Bugtraq, does not
   provide any details, so the description is necessarily vague.
   Also, the home page at http://bb4.com has it referring to
   itself as "Big Brother System and Network Monitor," so
   "Network Monitor" is apparently part of the name of the product.
   
   Change this description to mention version 1.4g, to distinguish
   from other Big Brother vulnerabilities.


CAN-2000-0473

Phase: Proposed (20000712)
Reference: BUGTRAQ:19991231 Local / Remote GET Buffer Overflow Vulnerability in AnalogX SimpleServer:WWW HTTP Server v1.1
Reference: MISC:http://www.analogx.com/contents/download/network/sswww.htm
Reference: BID:1349
Reference: URL:http://www.securityfocus.com/bid/1349

Description:
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET request for a program in the cgi-bin directory.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> Appears to be the same as, or similar to, CVE-2000-0011, which was
   also discovered by USSR.  Comments on the AnalogX web site are
   decidedly sparse.  In CAN-2000-0011, USSR only claims that
   the vendor was informed, so is this still the same problem?
   
   XF:simpleserver-long-url-dos
 Frech> XF:simpleserver-long-url-dos(4693)
   Please review whether your BUGTRAQ:19991231 reference is correct; seems like
   this is the reference to CVE-2000-0011: Buffer overflow in AnalogX
   SimpleServer:WWW HTTP server allows remote attackers to execute commands via
   a long GET request. They are subtle; almost the only thing that changed was
   the version.
   A possible reference is "Remote DoS attack in AnalogX SimpleServer WWW
   Version 1.05 Vulnerability" at http://www.ussrback.com/labs45.html.


CAN-2000-0476

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000601 [rootshell.com] Xterm DoS Attack
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0409.html
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0420.html
Reference: BID:1298
Reference: URL:http://www.securityfocus.com/bid/1298

Description:
xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:xterm-control-characters-dos(4987)


CAN-2000-0479

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96113734714517&w=2
Reference: BID:1352
Reference: URL:http://www.securityfocus.com/bid/1352

Description:
Dragon FTP server allows remote attackers to cause a denial of service via a long USER command.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> XF:dragon-ftp-dos
 Frech> XF:dragon-ftp-dos(4691)


CAN-2000-0480

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000616 Multiples Remotes DoS Attacks in Dragon Server v1.00 and v2.00
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96113734714517&w=2
Reference: BID:1352
Reference: URL:http://www.securityfocus.com/bid/1352

Description:
Dragon telnet server allows remote attackers to cause a denial of service via a long username.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> XF:dragon-telnet-dos
 Frech> XF:dragon-ftp-dos(4691)


CAN-2000-0487

Phase: Proposed (20000712)
Reference: MS:MS00-032
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-032.asp
Reference: BID:1295
Reference: URL:http://www.securityfocus.com/bid/1295

Description:
The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.

Votes:

   ACCEPT(3) Levy, LeBlanc, Wall
   MODIFY(1) Frech
   NOOP(1) Ozancin
Voter Comments:
 Frech> XF:ms-protected-store(4589)


CAN-2000-0491

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000521 "gdm" remote hole
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0241.html
Reference: SUSE:20000524 Security hole in gdm <= 2.0beta4-25
Reference: URL:http://www.suse.de/de/support/security/suse_security_announce_49.txt
Reference: BUGTRAQ:20000607 Conectiva Linux Security Announcement - gdm
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0025.html
Reference: CALDERA:CSSA-2000-013.0
Reference: URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-013.0.txt
Reference: BID:1233
Reference: URL:http://www.securityfocus.com/bid/1233
Reference: BID:1279
Reference: URL:http://www.securityfocus.com/bid/1279
Reference: BID:1370
Reference: URL:http://www.securityfocus.com/bid/1370

Description:
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.

Votes:

   MODIFY(2) Frech, Levy
   NOOP(2) LeBlanc, Wall
   REVIEWING(2) Ozancin, Christey
Voter Comments:
 Levy> The BID 1233 vulns is different from the other ones. BID 1233 uses
   a FORWARD_QUERY request to overflow an in_addr structure via a memmove
   in daemon/xdmcp.c, gdm_xdmcp_handle_forward_query(). In BID 1370
   a buffer is overflowed by a sprintf in xdmcp.c, send_failed().
 Frech> XF:gnome-gdm-bo(4530)
 Christey> MANDRAKE:MDKSA-2001:070
   URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-070.php3
 Christey> BUGTRAQ:20000527 gdm exploit
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96017189021021&w=2
   
   Consider REDHAT:RHSA-2000:027
 Christey> RHSA-2000:027 confirmed via Mark Cox


CAN-2000-0492

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000609 Insecure encryption in PassWD v1.2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0450.html
Reference: BID:1300
Reference: URL:http://www.securityfocus.com/bid/1300

Description:
PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the password file to easliy decrypt the passwords.

Votes:

   ACCEPT(1) Levy
   MODIFY(2) Frech, Ozancin
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Ozancin> change "attacker who can read the password" to "attacker to decrypt and read
   the password"
 Frech> XF:passwd-weak-encryption(4596)


CAN-2000-0503

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000606 IE 5 Cross-frame security vulnerability using IFRAME and WebBrowser control
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2000-q2/0154.html
Reference: BID:1311
Reference: URL:http://www.securityfocus.com/bid/1311

Description:
The IFRAME of the WebBrowser control in Internet Explorer 5.01 allows a remote attacker to violate the cross frame security policy via the NavigateComplete2 event.

Votes:

   ACCEPT(1) Levy
   MODIFY(2) Frech, Wall
   NOOP(2) Ozancin, LeBlanc
   REVIEWING(1) Christey
Voter Comments:
 Wall> This affects more than IE 5.01.  See http://www.securityfocus.com/bid/1311 for
   all versions of IE that this affects.  Works on Windows 98, IE 5.01 and IE 5.5.
 LeBlanc> If this is the one I was discussing offline with Steve, ACCEPT
 Frech> XF:ie-cross-frame(4610)
 Christey> Make sure this is the one I was discussing offline with David :-)
 Frech> CAN-2000-0503 was reassigned to ie-frame-domain-file-access(5504) from
   ie-cross-frame(4610), which was obsoleted and redirected to this
   issue. Since these are the same issues but just described differently,
   CAN-2000-0503 appears to be a dupe of CVE-2000-0768.


CAN-2000-0509

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000601 DST2K0008: Buffer Overrun in Sambar Server 4.3
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95990103207665&w=2
Reference: BID:1287
Reference: URL:http://www.securityfocus.com/bid/1287

Description:
Buffer overflows in the finger and whois demonstration scripts in Sambar Server 4.3 allow remote attackers to execute arbitrary commands via a long hostname.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:sambar-dll-bo(4592)


CAN-2000-0520

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000630 CONECTIVA LINUX SECURITY ANNOUNCEMENT - dump
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96240393814071&w=2
Reference: MISC:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11880
Reference: BID:1330
Reference: URL:http://www.securityfocus.com/bid/1330

Description:
Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands via a long tape name.

Votes:

   ACCEPT(2) Levy, Prosser
   MODIFY(1) Frech
   NOOP(4) Ozancin, LeBlanc, Wall, Christey
Voter Comments:
 Christey> ADDREF BUGTRAQ:20000711 MDKSA-2000:018 dump update
   URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0166.html
 Frech> XF:linux-restore-bo(4647)
 Prosser> Add Sources:
   http://www.linux-mandrake.com/en/updates/2000/MDKSA-2000-018.php3?dis=6.0
   http://www.redhat.com/support/errata/RHSA-2000-100.html


CAN-2000-0524

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000604 Microsoft Outlook (Express) bug..
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0045.html
Reference: BID:1333
Reference: URL:http://www.securityfocus.com/bid/1333

Description:
Microsoft Outlook and Outlook Express allow remote attackers to cause a denial of service by sending email messages with blank fields such as BCC, Reply-To, Return-Path, or From.

Votes:

   MODIFY(3) Frech, Levy, LeBlanc
   NOOP(1) Ozancin
   RECAST(1) Wall
Voter Comments:
 Levy> There was plenty of people that could not reproduce the problem although
   some did. More research (as in actual testing) is probably required.
 LeBlanc> This entry does not specify which versions of Outloook are vulnerable, nor
   is that clear from the BUGTRAQ record. It is much too broad to say just
   "Outlook" when it is definately not all versions of Outlook. The problem
   appears confined to some version of Outlook 97, and if I recall correctly,
   there has been a patch for this for quite some time.
 Frech> XF:outlook-header-dos(4645)
 CHANGE> [Wall changed vote from REVIEWING to RECAST]
 Wall> UNABLE TO DUPLICATE


CAN-2000-0526

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html
Reference: BID:1335
Reference: URL:http://www.securityfocus.com/bid/1335

Description:
mailview.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(4) Ozancin, LeBlanc, Wall, Christey
Voter Comments:
 Christey> ADDREF XF:mailstudio-view-files
 Frech> XF:mailstudio-view-files(4737)


CAN-2000-0527

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000609 Mailstudio2000 CGI Vulnerabilities [S0ftPj.4]
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0081.html
Reference: BID:1335
Reference: URL:http://www.securityfocus.com/bid/1335

Description:
userreg.cgi CGI program in MailStudio 2000 2.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(4) Ozancin, LeBlanc, Wall, Christey
Voter Comments:
 Christey> Modify description - explicitly mention %0a string; other
   metachar's are filtered
 Frech> XF:mailstudio-cgi-input-vaildation(4739)


CAN-2000-0531

Phase: Modified (20001010-1)
Reference: BUGTRAQ:20000620 Bug in gpm
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.10.10006201453090.1812-200000@apollo.aci.com.pl
Reference: REDHAT:RHSA-2000:045-01
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-045-01.html
Reference: BUGTRAQ:20000728 MDKSA:2000-025 gpm update
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0409.html
Reference: BID:1377
Reference: URL:http://www.securityfocus.com/bid/1377
Reference: XF:linux-gpm-gpmctl-dos
Reference: URL:http://xforce.iss.net/static/5010.php

Description:
Linux gpm program allows local users to cause a denial of service by flooding the /dev/gpmctl device with STREAM sockets.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:linux-gpm-gpmctl-dos(5010)
 Christey> ADDREF REDHAT:RHSA-2000:045-01
   ADDREF BUGTRAQ:20000728 MDKSA:2000-025 gpm update
   URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0409.html
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Per Andre Frech's comments for CAN-2000-0667.


CAN-2000-0535

Phase: Proposed (20000712)
Reference: FREEBSD:FreeBSD-SA-00:25
Reference: URL:http://archives.neohapsis.com/archives/freebsd/2000-06/0083.html
Reference: BID:1340
Reference: URL:http://www.securityfocus.com/bid/1340

Description:
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
   REVIEWING(1) Christey
Voter Comments:
 Christey> ADDREF NETBSD
   http://archives.neohapsis.com/archives/bugtraq/2000-06/0208.html
   
 Frech> XF:freebsd-alpha-weak-encryption(4704)
 Christey> ftp://ftp.netbsd.org/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-007.txt.asc
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Should the NetBSD problem really be combined with this?


CAN-2000-0543

Phase: Modified (20001010-1)
Reference: BUGTRAQ:20000614 Remote DoS attack in Networks Associates PGP Certificate Server Version 2.5 Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0107.html
Reference: BID:1343
Reference: URL:http://www.securityfocus.com/bid/1343
Reference: XF:pgp-cert-server-dos
Reference: URL:http://xforce.iss.net/static/4695.php

Description:
The command port for PGP Certificate Server 2.5.0 and 2.5.1 allows remote attackers to cause a denial of service if their hostname does not have a reverse DNS entry and they connect to port 4000.

Votes:

   ACCEPT(5) Baker, Ozancin, Levy, Cole, Collins
   MODIFY(1) Frech
   NOOP(1) Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Christey> XF:pgp-cert-server-dos
 Frech> XF:pgp-cert-server-dos(4695)
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Need to consult Jim Magdych on this one.


CAN-2000-0544

Phase: Proposed (20000712)
Reference: NTBUGTRAQ:20000604 anonymous SMBwriteX DoS
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0231.html
Reference: BID:1304
Reference: URL:http://www.securityfocus.com/bid/1304

Description:
Windows NT and Windows 2000 hosts allow a remote attacker to cause a denial of service via malformed DCE/RPC SMBwriteX requests that contain an invalid data length.

Votes:

   ACCEPT(2) Levy, LeBlanc
   MODIFY(1) Frech
   NOOP(1) Ozancin
   REVIEWING(2) Wall, Christey
Voter Comments:
 Frech> XF;nt-smb-request-dos(4600)
 Christey> Consult with Microsoft to see if this is MS:MS00-066
 Christey> ADDREF MS:MS00-066
   (confirmed offline with David LeBlanc)
   Subsequently, add  BID:1673 and XF:win2k-rpc-dos(5222)


CAN-2000-0545

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000602 /usr/bin/Mail exploit for Slackware 7.0 (mail-slack.c)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-05/0435.html
Reference: DEBIAN:20000605 mailx: mail group exploit in mailx
Reference: URL:http://www.debian.org/security/2000/20000605
Reference: BID:1305
Reference: URL:http://www.securityfocus.com/bid/1305

Description:
Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (carbon copy) parameter.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:sgi-mailx-bo(1371)
   CAN-2000-0545 seems to be a dupe of CVE-1999-0125 (Buffer overflow in SGI
   IRIX mailx program) since they both allow 'mail' group privileges. There was
   no exploit for SGI's vuln to compare.
 Christey> Since we are taking a split-by-default approach when
   there are insufficient details, we should keep this
   separate from CVE-1999-0125.  The difference in the
   time of discovery is also a factor, even if these wind
   up being the same problem.  However, there just aren't
   enough details to be sure if this is the same problem or not.
 Christey> On June 25, 1998, a buffer overflow in mailx via the HOME
   environmental variable was posted at:
   BUGTRAQ:19980625 security hole in mailx
   http://marc.theaimsgroup.com/?l=bugtraq&m=90221103125955&w=2
   
   This affected multiple OSes.
   
   SGI:19980605-01-PX (CVE-1999-0125) was published on September
   29, 1998; while the advisory is short on details, it does
   mention a buffer overflow.
   
   So, there's enough distinction here (time and what gets
   exploited) to say that these should remain split; but
   CVE-1999-0125 likely needs to be RECAST to mention other
   affected OSes.


CAN-2000-0546

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html
Reference: CONFIRM:http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt
Reference: CERT:CA-2000-11
Reference: URL:http://www.cert.org/advisories/CA-2000-11.html
Reference: CIAC:K-051
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/k-051.shtml
Reference: BID:1338
Reference: URL:http://www.securityfocus.com/bid/1338

Description:
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(2) Frech, Cox
   NOOP(3) LeBlanc, Wall, Christey
Voter Comments:
 Christey> ADDREF XF:kerberos-lastrealm-bo
 Frech> XF:kerberos-lastrealm-bo(4656)
   I question whether BID-1338 is appropriate here.
 Cox> ADDREF REDHAT:RHSA-2000:031


CAN-2000-0547

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000609 Security Advisory: MULTIPLE DENIAL OF SERVICE VULNERABILITIES IN KRB4 KDC
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0064.html
Reference: CONFIRM:http://web.mit.edu/kerberos/www/advisories/krb4kdc.txt
Reference: CERT:CA-2000-11
Reference: URL:http://www.cert.org/advisories/CA-2000-11.html
Reference: CIAC:K-051
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/k-051.shtml
Reference: BID:1338
Reference: URL:http://www.securityfocus.com/bid/1338

Description:
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(2) Frech, Cox
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:kerberos-localrealm-bo(4657)
   I question whether BID-1338 is appropriate here.
 Cox> ADDREF REDHAT:RHSA-2000:031


CAN-2000-0554

Phase: Proposed (20000712)
Reference: NTBUGTRAQ:20000608 DST2K0010: DoS & Path Revealing Vulnerability in Ceilidh v2.60a
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0246.html
Reference: BID:1320
Reference: URL:http://www.securityfocus.com/bid/1320

Description:
Ceilidh allows remote attackers to obtain the real path of the Ceilidh directory via the translated_path hidden form field.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(4) Ozancin, LeBlanc, Wall, Christey
Voter Comments:
 Christey> ADDREF XF:ceilidh-path-disclosure
 Frech> XF:ceilidh-path-disclosure(4620)


CAN-2000-0559

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000607 SessionWall-3 Paper + (links to) code
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.BSO.4.21.0006072124320.28062-100000@bearclaw.bogus.net
Reference: BID:1341
Reference: URL:http://www.securityfocus.com/bid/1341

Description:
eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords in the registry, which allows local users to easily decrypt the passwords.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:etrust-weak-password-encryption(5051)


CAN-2000-0562

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000620 BlackICE by Network ICE Corp vulnerability against Back Orifice 1.2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0190.html

Description:
BlackIce Defender 2.1 and earlier, and BlackIce Pro 2.0.23 and earlier, do not properly block Back Orifice traffic when the security setting is Nervous or lower.

Votes:

   ACCEPT(3) Levy, Cole, Armstrong
   MODIFY(2) Baker, Frech
   NOOP(1) Ozancin
   REVIEWING(1) Christey
Voter Comments:
 Levy> What do others think? Should this be a vuln? I can see the argument
   that some features are simply not available unless you use the maximum
   security settings.
 Christey> At the very least, this needs to be modified to state that
   this problem/concern applies to high ports in general, not
   just Back orifice.
   
   The Bugtraq poster claims that BlackICE "shuts down" the port, 
   but only *after* some initial traffic "leaks" out.  This may
   be by design, but it does mean that there is a small window
   of opportunity in which BlackICE may not work "as
   advertised," even at lower security settings.
 Christey> XF:blackice-security-level-nervous
   BID:1389
 Frech> XF:blackice-security-level-nervous(4777)
 CHANGE> [Levy changed vote from REVIEWING to ACCEPT]
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Baker> I accept it more as a security exposure, than a real vulnerability.
   It performs just as any other "firewall" or IDS product can be configured to
   allow traffic without notifying the user. You can adjust settings on
   any product that allow traffic that other people or organizations would
   find unacceptable.  So, as long as it is reflected that this is more of
   a configuration that allows such traffic as opposed to a defective
   or improperly functioning software issue, I don't have a problem with
   it.


CAN-2000-0563

Phase: Proposed (20000712)
Reference: BUGTRAQ:20000609 Security Holes Found in URLConnection of MRJ and IE of Mac OS (was Re: Reappearance of an old IE security bug)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0056.html
Reference: BUGTRAQ:20000513 Re: Reappearance of an old IE security bug
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-05-8&msg=391C95DE2DA.5E3BTAKAGI@java-house.etl.go.jp
Reference: BID:1336
Reference: URL:http://www.securityfocus.com/bid/1336

Description:
The URLConnection function in MacOS Runtime Java (MRJ) 2.1 and earlier and the Microsoft virtual machine (VM) for MacOS allows a malicious web site operator to connect to arbitrary hosts using a HTTP redirection, in violation of the Java security model.

Votes:

   ACCEPT(2) Ozancin, Levy
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
   REVIEWING(1) LeBlanc
Voter Comments:
 Christey> Confirmed by Scott Culp, but this only applies to
   outdated/unsupported versions of the JVM.
 Frech> XF:macos-java-security-ignored(5052)
 Christey> Consult with Microsoft to ensure that this is fixed by
   MS:MS00-059.  If so, then this might not just be in MacOS.


CAN-2000-0564

Phase: Proposed (20000712)
Reference: NTBUGTRAQ:20000529 ICQ Web Front Remote DoS Attack Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q2/0218.html

Description:
The guestbook CGI program in ICQ Web Front service for ICQ 2000a, 99b, and others allows remote attackers to cause a denial of service via a URL with a long name parameter.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(5) Ozancin, LeBlanc, Wall, Cole, Christey
Voter Comments:
 Christey> ADDREF BID:1463
   URL:http://www.securityfocus.com/bid/1463
 Frech> XF:icq-webfront-guestbook-dos(4574)


CAN-2000-0572

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000704 Recovering Passwords in Visible Systems' Razor
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-07-8&msg=613309F30B6DD2118C020000F809376C05CABD49@emss03m09.orl.lmco.com
Reference: BID:1424
Reference: URL:http://www.securityfocus.com/bid/1424

Description:
The Razor configuration management tool uses weak encryption for its password file, which allows local users to gain privileges.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(4) Magdych, LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF;razor-weak-encryption(4875)
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0574

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000705 proftp advisory
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0031.html
Reference: BUGTRAQ:20000706 ftpd and setproctitle()
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0061.html
Reference: CERT:CA-2000-13
Reference: URL:http://www.cert.org/advisories/CA-2000-13.html
Reference: BUGTRAQ:20000710 opieftpd setproctitle() patches
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0121.html
Reference: NETBSD:NetBSD-SA2000-009
Reference: URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-009.txt.asc
Reference: BID:1425
Reference: URL:http://www.securityfocus.com/bid/1425
Reference: BID:1438
Reference: URL:http://www.securityfocus.com/bid/1438

Description:
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.

Votes:

   ACCEPT(3) Levy, Magdych, Cole
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
   REVIEWING(1) Christey
Voter Comments:
 Christey> CD:SF-CODEBASE applies here.  There are many ftpd's that
   have this setproctitle() problem, but it might be traced
   back to the same codebase.  See if the HP problem is the
   same here as well, and if so, ADDREF HP:HPSBUX0007-117
   URL:http://www.securityfocus.com/templates/advisory.html?id=2404
 Frech> XF:ftp-setproctitle-format-string(4908)
   BID:1438 does not exist.
 Christey> ADDREF HP:HPSBUX0007-117??
   http://archives.neohapsis.com/archives/hp/2000-q4/0020.html
 Christey> ADDREF BID:650 ?


CAN-2000-0578

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000621 Predictability Problems in IRIX Cron and Compilers
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0204.html
Reference: BID:1412
Reference: URL:http://www.securityfocus.com/bid/1412

Description:
SGI MIPSPro compilers C, C++, F77 and F90 generate temporary files in /tmp with predictable file names, which could allow local users to insert malicious contents into these files as they are being compiled by another user.

Votes:

   ACCEPT(4) Baker, Levy, Cole, Blake
   MODIFY(1) Frech
   NOOP(7) Ozancin, Magdych, Oliver, LeBlanc, Wall, Armstrong, Christey
Voter Comments:
 Frech> XF:sgi-mipspro-modify-files(5007)
 CHANGE> [Cole changed vote from NOOP to ACCEPT]
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]
 Christey> SGI:20030605-01-A
   URL:ftp://patches.sgi.com/support/free/security/advisories/20030605-01-A


CAN-2000-0580

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000630 SecureXpert Advisory [SX-20000620-2]
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.3.96.1000630161935.4619B-100000@fjord.fscinternet.com
Reference: XF:win2k-cpu-overload-dos
Reference: BID:1415
Reference: URL:http://www.securityfocus.com/bid/1415

Description:
Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros to various TCP and UDP ports, which significantly increases the CPU utilization.

Votes:

   ACCEPT(3) Frech, Levy, Cole
   REJECT(2) Magdych, LeBlanc
   REVIEWING(1) Wall
Voter Comments:
 LeBlanc> Insufficient data.  Most of their claims are not reproducible. You can,
   however, DoS the telnet server this way. As far as I know, there is no repro
   on any of the other ports. I am not sure of fix status at this time
   (7/19/00). Also overlaps with CAN-2000-0581
 CHANGE> [Magdych changed vote from REVIEWING to REJECT]
 Magdych> The only independent verification of these claims I have heard is for the Telnet denial of service, which is already defined in CVE candidate CAN-2000-0581.
 Frech> Replace win2k-cpu-overload-dos(4824) with win2k-telnetserver-dos(4823)


CAN-2000-0589

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000626 sawmill5.0.21 old path bug & weak hash algorithm
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0271.html
Reference: BUGTRAQ:20000706 Patch for Flowerfire Sawmill Vulnerabilities Available
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0080.html
Reference: BID:1403
Reference: URL:http://www.securityfocus.com/bid/1403
Reference: XF:sawmill-weak-encryption

Description:
SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.

Votes:

   ACCEPT(3) Frech, Levy, Magdych
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 CHANGE> [Magdych changed vote from REVIEWING to ACCEPT]


CAN-2000-0592

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000627 [SPSadvisory #37]WinProxy 2.0.0/2.0.1 DoS and Exploitable Buffer Overflow
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=200006271417.GFE84146.-BJXON@lac.co.jp
Reference: XF:winproxy-command-bo
Reference: BID:1400
Reference: URL:http://www.securityfocus.com/bid/1400

Description:
Buffer overflows in POP3 service in WinProxy 2.0 and 2.0.1 allow remote attackers to execute arbitrary commands via long USER, PASS, LIST, RETR, or DELE commands.

Votes:

   ACCEPT(4) Frech, Levy, Magdych, Cole
   NOOP(1) LeBlanc
   REVIEWING(1) Wall

CAN-2000-0605

Phase: Proposed (20000719)
Reference: NTBUGTRAQ:20000710 Two issues: Blackboard CourseInfo 4.0 stores admin password in clear text; strange settings on the winreg key.
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0007&L=NTBUGTRAQ&P=R1647
Reference: BID:1460
Reference: URL:http://www.securityfocus.com/bid/1460

Description:
Blackboard CourseInfo 4.0 stores the local and SQL administrator user names and passwords in cleartext in a registry key whose access control allows users to access the passwords.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(4) Magdych, LeBlanc, Cole, Christey
   REVIEWING(1) Wall
Voter Comments:
 Christey> ADDREF NTBUGTRAQ:20000718 Security Fix for Blackboard CourseInfo 4.0
   URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0040.html
 Frech> XF:blackboard-courseinfo-plaintext(4904)
 Christey> Vendor acknowledgement is at:
   BUGTRAQ:20000719 Security Fix for Blackboard CourseInfo 4.0
   URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3D20000719151904.I17986@securityfocus.com
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0606

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000619 Problems with "kon2" package
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk
Reference: XF:linux-kon-bo
Reference: BID:1371
Reference: URL:http://www.securityfocus.com/bid/1371

Description:
Buffer overflow in kon program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via a long -StartupMessage parameter.

Votes:

   ACCEPT(3) Baker, Frech, Levy
   NOOP(4) Magdych, LeBlanc, Wall, Cole
Voter Comments:
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0607

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000619 Problems with "kon2" package
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Pine.LNX.4.21.0006192340340.19998-100000@ferret.lmh.ox.ac.uk
Reference: XF:linux-kon-bo
Reference: BID:1371
Reference: URL:http://www.securityfocus.com/bid/1371

Description:
Buffer overflow in fld program in Kanji on Console (KON) package on Linux may allow local users to gain root privileges via an input file containing long CHARSET_REGISTRY or CHARSET_ENCODING settings.

Votes:

   ACCEPT(3) Baker, Frech, Levy
   NOOP(5) Magdych, LeBlanc, Wall, Cole, Christey
Voter Comments:
 Christey> BID:1983
   URL:http://www.securityfocus.com/bid/1983
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0608

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000620 NetWin dMailWeb Denial of Service
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-06-15&msg=4.1.20000621113334.00996820@qlink.queensu.ca
Reference: BID:1376
Reference: URL:http://www.securityfocus.com/bid/1376
Reference: XF:dmailweb-long-pophost-dos

Description:
NetWin dMailWeb and cwMail 2.6i and earlier allows remote attackers to cause a denial of service via a long POP parameter (pophost).

Votes:

   ACCEPT(3) Frech, Levy, Magdych
   NOOP(3) LeBlanc, Wall, Cole

CAN-2000-0609

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000620 NetWin dMailWeb Denial of Service
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&date=2000-06-15&msg=4.1.20000621113334.00996820@qlink.queensu.ca
Reference: XF:dmailweb-long-username-dos
Reference: BID:1376
Reference: URL:http://www.securityfocus.com/bid/1376

Description:
NetWin dMailWeb and cwMail 2.6g and earlier allows remote attackers to cause a denial of service via a long username parameter.

Votes:

   ACCEPT(3) Frech, Levy, Magdych
   NOOP(3) LeBlanc, Wall, Cole

CAN-2000-0612

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000629 Buggy ARP handling in Windoze
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=395B7E64.9FB3D4DB@starzetz.de
Reference: XF:win-arp-spoofing
Reference: BID:1406
Reference: URL:http://www.securityfocus.com/bid/1406

Description:
Windows 95 and Windows 98 do not properly process spoofed ARP packets, which allows remote attackers to overwrite static entries in the cache table.

Votes:

   ACCEPT(4) Frech, Levy, LeBlanc, Cole
   NOOP(2) Magdych, Wall
   REVIEWING(1) Christey
Voter Comments:
 LeBlanc> I know we have a repro on this, but you may want to leave this in
   the REVIEWING state until a fix is released.
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0614

Phase: Proposed (20000719)
Reference: SUSE:20000710 Security Hole in tnef < 0-124
Reference: URL:http://archives.neohapsis.com/archives/vendor/2000-q3/0002.html
Reference: BID:1450
Reference: URL:http://www.securityfocus.com/bid/1450

Description:
Tnef program in Linux systems allows remote attackers to overwrite arbitrary files via TNEF encoded compressed attachments which specify absolute path names for the decompressed output.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(4) Magdych, LeBlanc, Wall, Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> This problem appears in AMaViS as well, so they may be the
   same codebase.  If so, then CD:SF-CODEBASE says to merge the
   two (thus ADDREF BID:1461).  If they are not the same
   codebase, then create a separate candidate for BID:1461.
 Frech> XF:linux-tnef-email-overwrite(4915)
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0617

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000622 RHL 6.2 xconq package - overflows yield gid games
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html

Description:
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long USER environmental variable.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(4) Magdych, LeBlanc, Wall, Christey
Voter Comments:
 Frech> XF:xconq-elevate-privileges(4995)
 Christey> ADDREF BID:1495
   ADDREF URL:http://www.securityfocus.com/bid/1495
 CHANGE> [Levy changed vote from REVIEWING to ACCEPT]
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0618

Phase: Proposed (20000719)
Reference: BUGTRAQ:20000622 RHL 6.2 xconq package - overflows yield gid games
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-06/0222.html

Description:
Buffer overflow in xconq and cconq game programs on Red Hat Linux allows local users to gain additional privileges via long DISPLAY environmental variable.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(4) Magdych, LeBlanc, Wall, Christey
Voter Comments:
 Frech> XF:xconq-elevate-privileges(4995)
 Christey> ADDREF BID:1495
   ADDREF URL:http://www.securityfocus.com/bid/1495
 CHANGE> [Levy changed vote from REVIEWING to ACCEPT]
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0623

Phase: Proposed (20000803)
Reference: NTBUGTRAQ:20000719 Alert: Buffer Overrun is O'Reilly WebsitePro httpd32.exe (CISADV000717)
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0007&L=ntbugtraq&F=&S=&P=5946
Reference: BID:1492
Reference: URL:http://www.securityfocus.com/bid/1492

Description:
Buffer overflow in O'Reilly WebSite Professional web server 2.4 and earlier allows remote attackers to execute arbitrary commands via a long GET request or Referrer header.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(1) LeBlanc
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:website-httpd32-bo(4970)
   In the description, I think it's spelled "referer"


CAN-2000-0625

Phase: Proposed (20000803)
Reference: L0PHT:20000718 NetZero Password Encryption Algorithm
Reference: URL:http://www.l0pht.com/advisories/netzero.txt
Reference: BID:1483
Reference: URL:http://www.securityfocus.com/bid/1483

Description:
NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decrypt the password.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Wall
Voter Comments:
 Frech> XF:zeroport-weak-encryption(4963)


CAN-2000-0626

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000718 Multiple bugs in Alibaba 2.0
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0237.html
Reference: BID:1482
Reference: URL:http://www.securityfocus.com/bid/1482

Description:
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.

Votes:

   ACCEPT(4) Baker, Levy, Wall, Blake
   MODIFY(1) Frech
   NOOP(5) Ozancin, Oliver, LeBlanc, Cole, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:alibaba-get-dos(4934)
 Christey> This is in a relatively old Nessus plugin, though the exploit
   uses POST instead of GET.  This was probably discovered
   earlier than the references indicate.
 CHANGE> [Wall changed vote from NOOP to ACCEPT]
 Wall> Found by Arne Vidstrom and found in multiple sources
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> See the POST comment in
   http://marc.theaimsgroup.com/?l=bugtraq&m=94182951012884&w=2
   Also see http://marc.theaimsgroup.com/?l=bugtraq&m=94191318721834&w=2
   
   One poster says that a large number of sites are running
   Alibaba (based on a netcraft report), but I'm not 100%
   sure Netcraft's doing a good job of identifying Alibaba
   servers.


CAN-2000-0629

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000711 Sun's Java Web Server remote command execution vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0163.html
Reference: MISC:http://www.sun.com/software/jwebserver/faq/jwsca-2000-02.html
Reference: BID:1459
Reference: URL:http://www.securityfocus.com/bid/1459

Description:
The default configuration of the Sun Java web server 2.0 and earlier allows remote attackers to execute arbitrary commands by uploading Java code to the server via board.html, then directly calling the JSP compiler servlet.

Votes:

   ACCEPT(3) Levy, Cole, Dik
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Christey
Voter Comments:
 Frech> XF:sunjava-webadmin-bbs(5135)
 Christey> Need to create/update 
 Dik> (through internal confirmation)


CAN-2000-0645

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html
Reference: BID:1506
Reference: URL:http://www.securityfocus.com/bid/1506

Description:
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and writing beyond the end of a file, or writing to a file that does not exist, via commands such as STORE UNIQUE (STOU), STORE (STOR), or APPEND (APPE).

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:wftpd-rest-dos(5004)


CAN-2000-0646

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html
Reference: BID:1506
Reference: URL:http://www.securityfocus.com/bid/1506

Description:
WFTPD and WFTPD Pro 2.41 allows remote attackers to obtain the real pathname for a file by executing a STATUS (STAT) command while the file is being transferred.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:wftpd-stat-info(5005)


CAN-2000-0647

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000721 WFTPD/WFTPD Pro 2.41 RC11 vulnerabilities.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html
Reference: BID:1506
Reference: URL:http://www.securityfocus.com/bid/1506

Description:
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before logging into the server.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:wftpd-mlst-dos(5006)


CAN-2000-0648

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000711 WFTPD/WFTPD Pro 2.41 RC10 denial-of-service
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=E13BvU6-0007d8-00@dwarf.box.sk
Reference: BID:1456
Reference: URL:http://www.securityfocus.com/bid/1456

Description:
WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command before a RENAME FROM (RNFR) command.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(2) LeBlanc, Cole
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:wftpd-rnto-dos(4930)


CAN-2000-0649

Phase: Proposed (20000803)
Reference: NTBUGTRAQ:20000713 IIS4 Basic authentication realm issue
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0025.html
Reference: BID:1499
Reference: URL:http://www.securityfocus.com/bid/1499

Description:
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.

Votes:

   ACCEPT(2) Levy, LeBlanc
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(2) Wall, Christey
Voter Comments:
 Christey> ADDREF http://support.microsoft.com/support/kb/articles/Q218/1/80.ASP
   
   Change description to point out that the internal IP address
   exposure is due to the default configuration as opposed to
   a bug.
 Frech> XF:iis-internal-ip-disclosure(5106)
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> There are two variants of the same type of issue here.  The
   KB article shows that IIS 4.0 reveals the IP address in a
   Content-Location MIME header field.  The NTBugtraq article
   says that the IP address is shown in the WWW-Authenticate
   MIME header.  Which one has been fixed, or both, and when?
 Christey> MSKB:Q218180 identifies a problem in which IIS returns the
   info in a Content-Location header, but the authentication
   realm problem is not specifically mentioned.  Are these the
   same problem?


CAN-2000-0653

Phase: Proposed (20000803)
Reference: MS:MS00-045
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-045.asp
Reference: BID:1502
Reference: URL:http://www.securityfocus.com/bid/1502

Description:
Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   NOOP(1) LeBlanc
   REJECT(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> Is this a duplicate of CAN-2000-0105? I can find no differentiating evidence
   to show that this issue is unique.
 Christey> I need to look through my email logs to recall whether I 
   resolved this potential duplicate with Microsoft people.
 CHANGE> [Frech changed vote from REVIEWING to REJECT]


CAN-2000-0656

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000724 AnalogX Proxy DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html
Reference: CONFIRM:http://www.analogx.com/contents/download/network/proxy.htm
Reference: BID:1504
Reference: URL:http://www.securityfocus.com/bid/1504

Description:
Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the FTP protocol.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:analogx-proxy-ftp-crash(4981)


CAN-2000-0657

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000724 AnalogX Proxy DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html
Reference: CONFIRM:http://www.analogx.com/contents/download/network/proxy.htm
Reference: BID:1504
Reference: URL:http://www.securityfocus.com/bid/1504

Description:
Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long HELO command in the SMTP protocol.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:analogx-proxy-smtp-helo(5164)


CAN-2000-0658

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000724 AnalogX Proxy DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html
Reference: CONFIRM:http://www.analogx.com/contents/download/network/proxy.htm
Reference: BID:1504
Reference: URL:http://www.securityfocus.com/bid/1504

Description:
Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long USER command in the POP3 protocol.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:analogx-proxy-pop3-crash(4982)


CAN-2000-0659

Phase: Proposed (20000803)
Reference: BUGTRAQ:20000724 AnalogX Proxy DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0360.html
Reference: BID:1504
Reference: URL:http://www.securityfocus.com/bid/1504

Description:
Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long user ID in a SOCKS4 CONNECT request.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
Voter Comments:
 Frech> XF:analogx-proxy-socks4-crash(4997)


CAN-2000-0667

Phase: Proposed (20000803)
Reference: CALDERA:CSSA-2000-024.0
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0273.html
Reference: BID:1512
Reference: URL:http://www.securityfocus.com/bid/1512

Description:
Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(3) LeBlanc, Wall, Cole
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:linux-gpm-gpmctl-dos(5010)
   We show this issue to be cross-Linux-platform and not Caldera specific. May
   also be a LOA issue or duplicate or specific instance of CAN-2000-0531. This
   position is further validated by BID-1512 and BID-1377, which lists this as
   a Conectiva Linux/Mandrake issue and list Mandrake:MDKSA-2000:025 in common.
   We will list both CVEs under the listed XF tag unless otherwise instructed.
 Christey> ADDREF Conectiva?
   URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0396.html
 Christey> ADDREF REDHAT:RHSA-2000:045-01
   ADDREF BUGTRAQ:20000727 CONECTIVA LINUX SECURITY ANNOUNCEMENT - GPM
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96473014104340&w=2
   Another possible reference is:
   BUGTRAQ:20000728 MDKSA:2000-025 gpm update
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96480812908563&w=2
   although the advisory is not explicit.  It also refers to
   CAN-2000-0531.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Per Andre Frech's comments.


CAN-2000-0680

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000728 cvs security problem
Reference: URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26msg%3Dhvou2daoebb.fsf%40serein.m17n.org
Reference: BID:1524
Reference: URL:http://www.securityfocus.com/bid/1524

Description:
The CVS 1.10.8 server does not properly restrict users from creating arbitrary Checkin.prog or Update.prog programs, which allows remote CVS committers to modify or create Trojan horse programs with the Checkin.prog or Update.prog names, then performing a CVS commit action.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:cvs-checkin-execute-binary


CAN-2000-0686

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000823 Auction WeaverT LITE 1.0
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html
Reference: BID:1630
Reference: URL:http://www.securityfocus.com/bid/1630

Description:
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the fromfile parameter.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:cgi-auction-weaver-read-files
 Frech> XF:cgi-auction-weaver-read-files(5150)


CAN-2000-0687

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000823 Auction WeaverT LITE 1.0
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0310.html
Reference: BID:1630
Reference: URL:http://www.securityfocus.com/bid/1630

Description:
Auction Weaver CGI script 1.03 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack in the catdir parameter.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:cgi-auction-weaver-read-files
 Christey> Need to double-check BID's on all these Auction Weaver prob's.
 Frech> XF:cgi-auction-weaver-read-files(5150)


CAN-2000-0688

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000823 Subscribe Me Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0292.html
Reference: BUGTRAQ:20000823 Re: Subscribe Me CGI Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96722957421029&w=2
Reference: CONFIRM:http://www.cgiscriptcenter.com/subscribe/
Reference: BID:1607
Reference: URL:http://www.securityfocus.com/bid/1607

Description:
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the subscribe.pl script with the setpwd parameter.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:subscribe-me-overwrite-password
 Christey> Make sure the mention of Account Manager is correct.
   XF:subscribe-me-overwrite-password
   http://xforce.iss.net/static/5126.php
 Frech> XF:subscribe-me-overwrite-password(5126)


CAN-2000-0689

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000823 Account Manager CGI Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0291.html
Reference: CONFIRM:http://www.cgiscriptcenter.com/acctlite/
Reference: BID:1604
Reference: URL:http://www.securityfocus.com/bid/1604

Description:
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote attackers to gain privileges for the Account Manager by directly calling the amadmin.pl script with the setpasswd parameter.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:account-manager-overwrite-password
   In description, you probably want to indicate both Account Manager LITE and PRO.
   Because CONFIRM redirects, you may want to verify and normalize to http://www.cgiscriptcenter.com/acctman/index2.html.
 Christey> XF:account-manager-overwrite-password
   http://xforce.iss.net/static/5125.php
 Frech> XF:account-manager-overwrite-password(5125)


CAN-2000-0690

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000830 More problems with Auction Weaver & CGI Script Center.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0370.html
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0452.html

Description:
Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the fromfile parameter.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Levy
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Levy> Reference: BID 1645
 Christey> BID:1645
   URL:http://www.securityfocus.com/bid/1645
 Frech> XF:auction-weaver-execute-commands(6175)


CAN-2000-0691

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000826 Advisory: mgetty local compromise
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0329.html
Reference: CONFIRM:http://archives.neohapsis.com/archives/bugtraq/2000-08/0330.html
Reference: CALDERA:CSSA-2000-029.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-029.0.txt
Reference: BID:1612
Reference: URL:http://www.securityfocus.com/bid/1612

Description:
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink attack which creates a symlink in from /var/spool/fax/outgoing/.last_run to the target file.

Votes:

   ACCEPT(1) Levy
   MODIFY(2) Frech, Cox
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Frech> XF:mgetty-faxrunq-symlink
 Christey> ADDREF XF:mgetty-faxrunq-symlink
   ADDREF URL:http://xforce.iss.net/static/5159.php
   ADDREF REDHAT:RHSA-2000:059-02
   ADDREF BUGTRAQ:20000830 Conectiva Linux Security Announcement - mgetty
   ADDREF MANDRAKE:MDKSA-2000:042
 Christey> ADDREF REDHAT:RHSA-2000:059-02
 Christey> ADDREF FREEBSD:FreeBSD-SA-00:71
   ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:71.mgetty.asc
 Frech> XF:mgetty-faxrunq-symlink(5159)	
 Cox> ADDREF REDHAT:RHSA-2000:059


CAN-2000-0692

Phase: Modified (20001010-1)
Reference: BUGTRAQ:20000822 DOS on RealSecure 3.2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0267.html
Reference: BID:1597
Reference: URL:http://www.securityfocus.com/bid/1597
Reference: XF:realsecure-rskill-dos

Description:
ISS RealSecure 3.2.1 and 3.2.2 allows remote attackers to cause a denial of service via a flood of fragmented packets with the SYN flag set.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:realsecure-rskill-dos
 Christey> CHANGEREF XF:realsecure-rskill-dos to XF:realsecure-frag-syn-dos?
   http://xforce.iss.net/static/5133.php
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> In an email to issforum@iss.net on September 7, 2000, ISS says
   that Network Sensor 3.2.2 is affected by SYN flooding, but
   RealSecure 5.0 is not affected by Syn flooding.  In addition,
   they could not find conclusive evidence that RS 3.2.2 or 5.0
   was affected by IP fragmentation.  This seems to indicate
   that there are 2 *possible* problems: syn flooding (acknowledged
   by ISS) and fragmentation (unconfirmed).  Perhaps this
   candidate needs to be split, or its description should be
   rewritten to separate the 2 reported problems.
 Frech> XF:realsecure-rskill-dos(5133)


CAN-2000-0695

Phase: Modified (20010417-01)
Reference: BUGTRAQ:20000802 Local root compromise in PGX Config Sun Sparc Solaris
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0463.html

Description:
Buffer overflows in pgxconfig in the Raptor GFX configuration tool allow local users to gain privileges via command line options.

Votes:

   ACCEPT(3) Baker, Levy, Dik
   NOOP(2) Wall, Cole
Voter Comments:
 Dik> as CAN-2000-0693


CAN-2000-0696

Phase: Modified (20020222-01)
Reference: BUGTRAQ:20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server
Reference: URL:http://www.securityfocus.com/archive/1/74382
Reference: SUN:00196
Reference: URL:http://archives.neohapsis.com/archives/sun/2000-q3/0001.html
Reference: XF:solaris-answerbook2-admin-interface(5069)
Reference: URL:http://xforce.iss.net/static/5069.php
Reference: BID:1554
Reference: URL:http://www.securityfocus.com/bid/1554

Description:
The administration interface for the dwhttpd web server in Solaris AnswerBook2 does not properly authenticate requests to its supporting CGI scripts, which allows remote attackers to add user accounts to the interface by directly calling the admin CGI script.

Votes:

   ACCEPT(3) Levy, Cole, Dik
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:solaris-answerbook2-admin-interface
 Christey> XF:solaris-answerbook2-admin-interface
   http://xforce.iss.net/static/5069.php
 Christey> BUGTRAQ:20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server
   http://www.securityfocus.com/archive/1/74382
 Christey> Fix typo: "CGi"
 CHANGE> [Dik changed vote from REVIEWING to ACCEPT]


CAN-2000-0697

Phase: Modified (20020222-01)
Reference: BUGTRAQ:20000807 Vulnerabilities in Sun Solaris AnswerBook2 dwhttpd server
Reference: URL:http://www.securityfocus.com/archive/1/74382
Reference: SUN:00196
Reference: URL:http://archives.neohapsis.com/archives/sun/2000-q3/0001.html
Reference: XF:solaris-answerbook2-remote-execution(5058)
Reference: URL:http://www.iss.net/security_center/static/5058.php
Reference: BID:1556
Reference: URL:http://www.securityfocus.com/bid/1556

Description:
The administration interface for the dwhttpd web server in Solaris AnswerBook2 allows interface users to remotely execute commands via shell metacharacters.

Votes:

   ACCEPT(3) Levy, Cole, Dik
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:solaris-answerbook2-remote-execution
 Christey> XF:solaris-answerbook2-remote-execution
   http://xforce.iss.net/static/5058.php
 CHANGE> [Dik changed vote from REVIEWING to ACCEPT]
 Dik> COMMENTS
   verified bug existance.
 Christey> There needs to be a separate item for the .. problem reported
   in this same post.


CAN-2000-0701

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000801 Advisory: mailman local compromise
Reference: URL:http://www.securityfocus.com/archive/1/73220
Reference: CONFIRM:http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000802105050.A11733@rak.isternet.sk
Reference: BUGTRAQ:20000802 CONECTIVA LINUX SECURITY ANNOUNCEMENT - mailman
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0474.html
Reference: BUGTRAQ:20000802 MDKSA-2000:030 - Linux-Mandrake not affected by mailman problem
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0479.html
Reference: REDHAT:RHSA-2000:030-03
Reference: URL:http://www.redhat.com/support/errata/secureserver/RHSA-2000-030-03.html
Reference: BID:1539
Reference: URL:http://www.securityfocus.com/bid/1539

Description:
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:gnu-mailman-format-string
   You can perhaps normalize Bugtraq URL to CONFIRM:http://www.securityfocus.com/archive/1/73355.


CAN-2000-0704

Phase: Proposed (20000921)
Reference: SGI:20000803-01-A
Reference: URL:ftp://sgigate.sgi.com/security/20000803-01-A
Reference: BID:1603
Reference: URL:http://www.securityfocus.com/bid/1603

Description:
Buffer overflow in SGI Omron WorldView Wnn allows remote attackers to execute arbitrary commands via long JS_OPEN, JS_MKDIR, or JS_FILE_INFO commands.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:irix-worldview-wnn-bo
 Christey> XF:irix-worldview-wnn-bo
   http://xforce.iss.net/static/5163.php


CAN-2000-0709

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000823 Xato Advisory: FrontPage DOS Device DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html
Reference: CONFIRM:http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp
Reference: BID:1608
Reference: URL:http://www.securityfocus.com/bid/1608

Description:
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers to cause a denial of service in some components by requesting a URL whose name includes a standard DOS device name.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> [note to self: review comments by Mark Burnett]
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> XF:frontpage-ext-device-name-dos(5124)
 Frech> XF:frontpage-ext-device-name-dos(5124)


CAN-2000-0710

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000823 Xato Advisory: FrontPage DOS Device DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0288.html
Reference: CONFIRM:http://msdn.microsoft.com/workshop/languages/fp/2000/sr12.asp
Reference: BID:1608
Reference: URL:http://www.securityfocus.com/bid/1608

Description:
The shtml.exe component of Microsoft FrontPage 2000 Server Extensions 1.1 allows remote attackers determine the physical path of the server components by requesting an invalid URL whose name includes a standard DOS device name.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> [note to self: review comments by Mark Burnett]
 Frech> XF:frontpage-ext-device-name-dos(5124)


CAN-2000-0713

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000726 [SPSadvisory#39]Adobe Acrobat Series PDF File Buffer Overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0382.html
Reference: CONFIRM:http://www.adobe.com/misc/pdfsecurity.html
Reference: BID:1509
Reference: URL:http://www.securityfocus.com/bid/1509

Description:
Buffer overflow in Adobe Acrobat 4.05, Reader, Business Tools, and Fill In products that handle PDF files allows attackers to execute arbitrary commands via a long /Registry or /Ordering specifier.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   NOOP(1) Christey
Voter Comments:
 Christey> ADDREF XF:adobe-pdf-bo(5002)


CAN-2000-0714

Phase: Proposed (20000921)
Reference: REDHAT:RHSA-2000:047-03
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-047-03.html
Reference: BID:1551
Reference: URL:http://www.securityfocus.com/bid/1551

Description:
umb-scheme 3.2-11 for Red Hat Linux is installed with world-writeable files.

Votes:

   ACCEPT(4) Cox, Levy, Williams, Cole
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:linux-umb-scheme
   http://xforce.iss.net/static/5048.php
 Cox> (If me voting speeds up its inclusion :))


CAN-2000-0715

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000805 Diskcheck 3.1.1 Symlink Vulnerability
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=398BD1FD.BAEE3B70@chonnam.chonnam.ac.kr
Reference: BID:1552
Reference: URL:http://www.securityfocus.com/bid/1552

Description:
DiskCheck script diskcheck.pl in Red Hat Linux allows local users to create or overwrite arbitrary files via a symlink attack.

Votes:

   ACCEPT(3) Baker, Levy, Williams
   MODIFY(2) Cox, Christey
   NOOP(2) Wall, Cole
Voter Comments:
 Christey> XF:diskcheck-tmp-race-condition
   http://xforce.iss.net/static/5061.php
 Christey> ADDREF REDHAT:RHSA-2000:122-04 ?
   The advisory addresses some diskcheck symlink vulnerability,
   but the initial announcement was 4 months before the advisory
   was released; however, the DiskCheck versions seem to
   correspond.
 Christey> See various Bugtraq posts relating to this, and verify if the
   Conectiva/Red Hat/etc. advisories are really addressing this
   particular problem.
   e.g.: BUGTRAQ:20000622 Re: rh 6.2 - gid compromises, etc [+ MORE!!!]
   http://marc.theaimsgroup.com/?l=bugtraq&m=96172022819526&w=2
   BUGTRAQ:20000810 CONECTIVA LINUX SECURITY ANNOUNCEMENT - diskcheck
   http://marc.theaimsgroup.com/?l=bugtraq&m=96604843017702&w=2
   REDHAT:RHSA-2000:122-06
   http://marc.theaimsgroup.com/?l=bugtraq&m=97649229201967&w=2
   BID:2050
   URL:http://www.securityfocus.com/bid/2050
 Christey> The following RedHat advisory appears to identify the same
   problem as one that was posted to Bugtraq on August 8, 2000:
   REDHAT:RHSA-2000:122-06
   http://www.redhat.com/support/errata/powertools/RHSA-2000-122.html
   
   See the following BugID, as referenced in the advisory:
   http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=11724
   So, add:
   BID:2050
   URL:http://www.securityfocus.com/bid/2050
   XF:linux-diskcheck-race-symlink
   URL:http://xforce.iss.net/static/5624.php
   
   [note the apparent BID duplicates, however]
 CHANGE> [Christey changed vote from NOOP to MODIFY]
 Christey> Missing BID - BID:1552
 Cox> ADDREF REDHAT:RHSA-2000:122


CAN-2000-0719

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000810 VariCAD 7.0 premission vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0126.html

Description:
VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.

Votes:

   MODIFY(1) Frech
   NOOP(4) Williams, Wall, Cole, Christey
   REVIEWING(1) Levy
Voter Comments:
 Christey> XF:varicad-world-write-permissions
   http://xforce.iss.net/static/5077.php
 Frech> XF:aricad-world-write-permissions(5077)
 Christey> BID:1862


CAN-2000-0721

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000810 FlagShip v4.48.7449 premission vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0114.html
Reference: BID:1586
Reference: URL:http://www.securityfocus.com/bid/1586

Description:
The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows local users to replace them with Trojan horses.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:flagship-incorrect-permissions(5114)


CAN-2000-0722

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000819 Multiple Local Vulnerabilities in Helix Gnome Installer
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=E13QAYl-0007il-00@the-village.bc.nu
Reference: BUGTRAQ:20000820 Helix Code Security Advisory - Helix GNOME Update
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0240.html
Reference: BUGTRAQ:20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html
Reference: BID:1593
Reference: URL:http://www.securityfocus.com/bid/1593

Description:
Helix GNOME Updater helix-update 0.5 and earlier allows local users to install arbitrary RPM packages by creating the /tmp/helix-install installation directory before root has begun installing packages.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:linux-update-race-condition
 Frech> XF:gnome-installer-overwrite-configuration(5129)


CAN-2000-0723

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000819 Multiple Local Vulnerabilities in Helix Gnome Installer
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=E13QAYl-0007il-00@the-village.bc.nu
Reference: BUGTRAQ:20000820 [Helix Beta] Helix Code Security Advisory - Helix GNOME Installer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0251.html
Reference: BID:1596
Reference: URL:http://www.securityfocus.com/bid/1596

Description:
Helix GNOME Updater helix-update 0.5 and earlier does not properly create /tmp directories, which allows local users to create empty system configuration files such as /etc/config.d/bashrc, /etc/config.d/csh.cshrc, and /etc/rc.config.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:gnome-installer-overwrite-configuration(5129)
 Frech> XF:gnome-installer-overwrite-configuration(5129)


CAN-2000-0724

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000829 More Helix Code installation problems (go-gnome)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0351.html
Reference: BUGTRAQ:20000829 Helix Code Security Advisory - go-gnome pre-installer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0356.html
Reference: BID:1622
Reference: URL:http://www.securityfocus.com/bid/1622

Description:
The go-gnome Helix GNOME pre-installer allows local users to overwrite arbitrary files via a symlink attack on various files in /tmp, including uudecode, snarf, and some installer files.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:go-gnome-preinstaller-symlink(5161)
 Frech> XF:go-gnome-preinstaller-symlink(5161)


CAN-2000-0734

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000831 Remote DoS Attack in Eeye Iris 1.01 and SpyNet CaptureNet v3.12
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96774637326591&w=2
Reference: BID:1627
Reference: URL:http://www.securityfocus.com/bid/1627

Description:
eEye IRIS 1.01 beta allows remote attackers to cause a denial of service via a large number of UDP connections.

Votes:

   MODIFY(1) Levy
   NOOP(2) Wall, Cole
   REJECT(1) Frech
Voter Comments:
 Levy> The product is in wide use even while is in beta. eEye brought another company and made all their previous customers upgrade to the new software.


CAN-2000-0735

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000818 Becky! Internet Mail Buffer overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html
Reference: CONFIRM:http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt
Reference: BID:1588
Reference: URL:http://www.securityfocus.com/bid/1588

Description:
Buffer overflow in Becky! Internet Mail client 1.26.03 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user replies to a message.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:becky-imail-header-dos
   http://xforce.iss.net/static/5110.php
 Frech> XF:becky-imail-header-dos(5110)


CAN-2000-0736

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000818 Becky! Internet Mail Buffer overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0234.html
Reference: CONFIRM:http://member.nifty.ne.jp/rimarts/becky-e/Readme.txt
Reference: BID:1588
Reference: URL:http://www.securityfocus.com/bid/1588

Description:
Buffer overflow in Becky! Internet Mail client 1.26.04 and earlier allows remote attackers to cause a denial of service via a long Content-type: MIME header when the user forwards a message.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:becky-imail-header-dos
   http://xforce.iss.net/static/5110.php
 Frech> XF:becky-imail-header-dos(5110)


CAN-2000-0746

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000821 IIS 5.0 cross site scripting vulnerability - using .shtml files or /_vti_bin/shtml.dll
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=39A12BD6.E811BF4F@nat.bg
Reference: MS:MS00-060
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-060.asp
Reference: BID:1594
Reference: URL:http://www.securityfocus.com/bid/1594
Reference: BID:1595
Reference: URL:http://www.securityfocus.com/bid/1595

Description:
Vulnerabilities in IIS 4.0 and 5.0 do not properly protect against cross-site scripting (CSS) attacks. They allow a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site, aka the "IIS Cross-Site Scripting" vulnerabilities.

Votes:

   ACCEPT(3) Levy, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> Make sure both BID's are appropriate
   XF:iis-cross-site-scripting
   http://xforce.iss.net/static/5156.php
 Frech> XF: iis-cross-site-scripting(5156)
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> A re-release of MS:MS00-060 indicates that a new variant of
   this problem was discovered, but the advisory does not
   provide sufficient details to distinguish it from this
   candidate.  A new candidate is being created, but the 
   description can't be written without mentioning this CAN.


CAN-2000-0747

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000726 CONECTIVA LINUX SECURITY ANNOUNCEMENT - OPENLDAP
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0379.html

Description:
The logrotate script for openldap earlier than 1.2.11 in Conectiva Linux sends an improper signal to the kernel log daemon (klogd) and kills it.

Votes:

   ACCEPT(2) Baker, Cole
   NOOP(1) Wall
   REVIEWING(1) Levy

CAN-2000-0748

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000726 Group-writable executable in OpenLDAP
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0375.html
Reference: BID:1511
Reference: URL:http://www.securityfocus.com/bid/1511

Description:
OpenLDAP 1.2.11 and earlier improperly installs the ud binary with group write permissions, which could allow any user in that group to replace the binary with a Trojan horse.

Votes:

   ACCEPT(1) Levy
   NOOP(3) Williams, Wall, Cole

CAN-2000-0752

Phase: Proposed (20000921)
Reference: FREEBSD:FreeBSD-SA-00:43
Reference: URL:http://archives.neohapsis.com/archives/freebsd/2000-08/0339.html
Reference: BID:1629
Reference: URL:http://www.securityfocus.com/bid/1629

Description:
Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:freebsd-brouted-bo(6185)


CAN-2000-0755

Phase: Proposed (20000921)
Reference: HP:HPSBUX0008-118
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0144.html
Reference: BID:1581
Reference: URL:http://www.securityfocus.com/bid/1581

Description:
Vulnerability in the newgrp command in HP-UX 11.00 allows local users to gain privileges.

Votes:

   ACCEPT(2) Levy, Cole
   NOOP(1) Wall
   REJECT(2) Frech, Christey
Voter Comments:
 Christey> DUPE CVE-2000-0730
   Also, the BID is wrong.
 Frech> DUPE OF CVE-2000-0730
   Also, the BID is wrong.


CAN-2000-0756

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000831 vCard DoS on Outlook 2000
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=Springmail.105.967737080.0.16997300@www.springmail.com
Reference: BID:1633
Reference: URL:http://www.securityfocus.com/bid/1633

Description:
Microsoft Outlook 2000 does not properly process long or malformed fields in vCard (.vcf) files, which allows attackers to cause a denial of service.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(2) Frech, LeBlanc
   REVIEWING(2) Wall, Christey
Voter Comments:
 LeBlanc> - if a KB article, bulletin, or patch can be found, then
   I'll ACCEPT
 Christey> This is the same as MS:MS01-012 (CAN-2001-0145)
   See the Bugtraq post by Joel Moses:
   http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2
   
   As of this writing, it is not certain which candidate
   should be preferred: the candidate that has been publicly
   known longer (i.e. CAN-2000-0756), or the more "official"
   candidate, which has probably been publicized more (i.e.
   CAN-2001-0145).
 Frech> XF:outlook-vcard-dos(5175)
   XF:outlook-vcard-bo(6145)
   Because there's another more recent CAN linked to @stake and
   Microsoft's advisories, we'll link both of our records to both
   candiates until a final decision occurs. If a decision has been made
   to promote the CAN-2001 entry, then enter my vote as a REJECT for
   CAN-2000-0756.
 Frech> Replace outlook-vcard-bo(6145) with outlook-vcard-dos(5175)


CAN-2000-0757

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000808 Exploit for Totalbill...
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0074.html
Reference: BID:1555
Reference: URL:http://www.securityfocus.com/bid/1555

Description:
The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privileges by connecting to the service and specifying the commands to be executed.

Votes:

   ACCEPT(2) Baker, Levy
   NOOP(4) Williams, Wall, Cole, Christey
Voter Comments:
 Christey> XF:totalbill-remote-execution
   http://xforce.iss.net/static/5068.php


CAN-2000-0759

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000719 [LoWNOISE] Tomcat 3.1 Path Revealing Problem.
Reference: URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719184401.17782A-100000@grex.cyberspace.org
Reference: BID:1531
Reference: URL:http://www.securityfocus.com/bid/1531
Reference: XF:tomcat-error-path-reveal

Description:
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.

Votes:

   ACCEPT(2) Baker, Levy
   NOOP(3) Williams, Wall, Cole

CAN-2000-0760

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000719 [LoWNOISE] Snoop Servlet (Tomcat 3.1 and 3.0)
Reference: URL:http://www.securityfocus.com/frames/?content=/templates/archive.pike%3Flist%3D1%26date%3D2000-07-15%26msg%3DPine.SUN.3.96.1000719235404.24004A-100000@grex.cyberspace.org
Reference: XF:tomcat-snoop-info
Reference: BID:1532
Reference: URL:http://www.securityfocus.com/bid/1532

Description:
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.

Votes:

   ACCEPT(2) Baker, Levy
   NOOP(3) Williams, Wall, Cole

CAN-2000-0769

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000824 WebServer Pro 2.3.7 Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96715834610888&w=2
Reference: BID:1611
Reference: URL:http://www.securityfocus.com/bid/1611

Description:
O'Reilly WebSite Pro 2.3.7 installs the uploader.exe program with execute permissions for all users, which allows remote attackers to create and execute arbitrary files by directly calling uploader.exe.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(2) Cole, Christey
   REVIEWING(1) Wall
Voter Comments:
 Christey> XF:website-pro-upload-files(5157)
 Frech> XF:website-pro-upload-files(5157)


CAN-2000-0772

Phase: Modified (20010116-01)
Reference: BUGTRAQ:20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0098.html
Reference: CONFIRM:http://thompson.tumbleweed.com/NewKB/bulletin/UPFiles/sa-official.htm
Reference: BID:1562
Reference: URL:http://www.securityfocus.com/bid/1562
Reference: XF:tumbleweed-mms-blank-password
Reference: URL:http://xforce.iss.net/static/5072.php

Description:
The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password.

Votes:

   ACCEPT(1) Levy
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:tumbleweed-mms-blank-password
   http://xforce.iss.net/static/5072.php
 Frech> XF:umbleweed-mms-blank-password(5072)


CAN-2000-0773

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000731 Two security flaws in Bajie Webserver
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html
Reference: BID:1522
Reference: URL:http://www.securityfocus.com/bid/1522

Description:
Bajie HTTP web server 0.30a allows remote attackers to read arbitrary files by requesting a URL that contains a "....", a variant of the dot dot attack.

Votes:

   ACCEPT(2) Levy, Williams
   NOOP(2) Wall, Cole

CAN-2000-0774

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000731 Two security flaws in Bajie Webserver
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0426.html
Reference: BID:1521
Reference: URL:http://www.securityfocus.com/bid/1521

Description:
The sample Java servlet "test" in Bajie HTTP web server 0.30a reveals the real pathname of the web document root.

Votes:

   ACCEPT(2) Levy, Williams
   NOOP(2) Wall, Cole

CAN-2000-0775

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000828 [NT] Viking security vulnerabilities enable remote code execution (long URL, date parsing)
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=399a01c01122$0d7f2310$0201a8c0@aviram
Reference: CONFIRM:http://www.robtex.com/viking/bugs.htm
Reference: BID:1614
Reference: URL:http://www.securityfocus.com/bid/1614

Description:
Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or execute arbitrary commands via a long HTTP GET request, or long Unless-Modified-Since, If-Range, or If-Modified-Since headers.

Votes:

   ACCEPT(2) Baker, Levy
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:viking-server-bo(5158)
 Frech> XF:viking-server-bo(5158)


CAN-2000-0781

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000728 Client Agent 6.62 for Unix Vulnerability
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000728034420.A19824@sdf.freeshell.org
Reference: BID:1519
Reference: URL:http://www.securityfocus.com/bid/1519

Description:
uagentsetup in ARCServeIT Client Agent 6.62 does not properly check for the existence or ownership of a temporary file which is moved to the the agent.cfg configuration file, which allows local users to execute arbitrary commands by modifying the temporary file before it is moved.

Votes:

   ACCEPT(2) Levy, Williams
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> fix typo: "the the"


CAN-2000-0784

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000816 Remote Root Compromise On All RapidStream VPN Appliances
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0216.html
Reference: BID:1574
Reference: URL:http://www.securityfocus.com/bid/1574

Description:
sshd program in the Rapidstream 2.1 Beta VPN appliance has a hard-coded "rsadmin" account with a null password, which allows remote attackers to execute arbitrary commands via ssh.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:rapidstream-remote-execution
   http://xforce.iss.net/static/5093.php
 Frech> XF:rapidstream-remote-execution(5093)


CAN-2000-0785

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000713 More wIRCSrv stupidity
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96353027909756&w=2

Description:
WircSrv IRC Server 5.07s allows IRC operators to read arbitrary files via the importmotd command, which sets the Message of the Day (MOTD) to the specified file.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Levy
   NOOP(3) Williams, Wall, Cole
Voter Comments:
 Levy> BID 1472


CAN-2000-0789

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000816 WinU 4/5 weak password vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0201.html

Description:
WinU 5.x and earlier uses weak encryption to store its configuration password, which allows local users to decrypt the password and gain privileges.

Votes:

   ACCEPT(1) Williams
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
   REVIEWING(1) Levy
Voter Comments:
 Frech> XF:winu-backdoor(5376)
 Christey> ADDREF BID:1741
   ADDREF URL:http://www.securityfocus.com/bid/1741


CAN-2000-0791

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000815 Trustix security advisory - apache-ssl
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0179.html
Reference: BID:1575
Reference: URL:http://www.securityfocus.com/bid/1575

Description:
Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.

Votes:

   ACCEPT(2) Levy, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> XF:trustix-secure-apache-misconfig
   http://xforce.iss.net/static/5099.php
 Frech> XF:trustix-secure-apache-misconfig(5099)


CAN-2000-0793

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000728 Norton Antivirus Protection Disabled under Novell Netware
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=398222C5@zathras.cc.vt.edu
Reference: BID:1533
Reference: URL:http://www.securityfocus.com/bid/1533

Description:
Norton AntiVirus 5.00.01C with the Novell Netware client does not properly restart the auto-protection service after the first user has logged off of the system.

Votes:

   ACCEPT(1) Levy
   NOOP(3) Williams, Wall, Cole

CAN-2000-0794

Phase: Modified (20020222-01)
Reference: BUGTRAQ:20000802 [LSD] some unpublished LSD exploit codes
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=200008021924.e72JOVs12558@ix.put.poznan.pl
Reference: BID:1527
Reference: URL:http://www.securityfocus.com/bid/1527
Reference: XF:irix-libgl-bo(5063)
Reference: URL:http://www.iss.net/security_center/static/5063.php

Description:
Buffer overflow in IRIX libgl.so library allows local users to gain root privileges via a long HOME variable to programs such as (1) gmemusage and (2) gr_osview.

Votes:

   ACCEPT(3) Baker, Levy, Williams
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:irix-libgl-bo
   http://xforce.iss.net/static/5063.php


CAN-2000-0797

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000802 [LSD] some unpublished LSD exploit codes
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=200008021924.e72JOVs12558@ix.put.poznan.pl
Reference: BID:1526
Reference: URL:http://www.securityfocus.com/bid/1526

Description:
Buffer overflow in gr_osview in IRIX 6.2 and 6.3 allows local users to gain privileges via a long -D option.

Votes:

   ACCEPT(2) Baker, Levy
   NOOP(4) Williams, Wall, Cole, Christey
Voter Comments:
 Christey> XF:irix-grosview-bo
   http://xforce.iss.net/static/5062.php


CAN-2000-0798

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000802 [LSD] some unpublished LSD exploit codes
Reference: URL:http://www.securityfocus.com/templates/archive.pike?list=1&msg=200008021924.e72JOVs12558@ix.put.poznan.pl
Reference: BID:1540
Reference: URL:http://www.securityfocus.com/bid/1540

Description:
The truncate function in IRIX 6.x does not properly check for privileges when the file is in the xfs file system, which allows local users to delete the contents of arbitrary files.

Votes:

   ACCEPT(3) Baker, Levy, Williams
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:irix-xfs-truncate
   http://xforce.iss.net/static/5011.php
 Christey> XF:sgi-xfs(2110) ?
   SGI:19970102-01-PX ?
 Christey> Consulting SGI on this... the relationship is pretty close.


CAN-2000-0800

Phase: Proposed (20000921)
Reference: SUSE:20000810 Security Hole in knfsd, all versions
Reference: URL:http://www.suse.de/de/support/security/suse_security_announce_58.txt

Description:
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.

Votes:

   ACCEPT(1) Cole
   MODIFY(2) Frech, Levy
   NOOP(1) Wall
   REJECT(1) Christey
Voter Comments:
 Levy> This is the same as other Linux vendors statd format string problem.
   
   Reference: BID 1480
 Christey> If this is the same as the other statd format string problems,
   then this is a duplicate of CAN-2000-0666.
 Frech> XF:linux-rpcstatd-format-overwrite(4939)
 CHANGE> [Christey changed vote from REVIEWING to REJECT]
 Christey> OK, I agree that this is a dupe of CVE-2000-0666.
   Here's why:
   
   BUGTRAQ:20000803 SuSE Security: miscellaneous
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96540330329127&w=2
   
   One statement says "The SuSE package containing rpc.kstatd
   (other vendors named it rpc.statd)... An updated package is
   currently being tested."


CAN-2000-0801

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000727 [ Hackerslab bug_paper ] HP-UX bdf -t option buffer overflow vul.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0388.html
Reference: BID:1520
Reference: URL:http://www.securityfocus.com/bid/1520

Description:
Buffer overflow in bdf program in HP-UX 11.00 may allow local users to gain root privileges via a long -t option.

Votes:

   ACCEPT(2) Levy, Williams
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> ADDREF HP:HPSBUX0010-127??
   http://archives.neohapsis.com/archives/hp/2000-q4/0028.html


CAN-2000-0802

Phase: Proposed (20000921)
Reference: BUGTRAQ:20000722 More bad censorware
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96430372326912&w=2
Reference: XF:bair-security-removal

Description:
The BAIR program does not properly restrict access to the Internet Explorer Internet options menu, which allows local users to obtain access to the menu by modifying the registry key that starts BAIR.

Votes:

   NOOP(4) Williams, LeBlanc, Wall, Cole
   REVIEWING(1) Levy
Voter Comments:
 LeBlanc> What the heck is BAIR? I don't think it is MS software.


CAN-2000-0812

Phase: Interim (20010117)
Reference: SUN:00197
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/197&type=0&nav=sec.sba
Reference: MISC:http://www.securityfocus.com/templates/advisory.html?id=2542
Reference: BID:1600
Reference: URL:http://www.securityfocus.com/bid/1600
Reference: XF:sunjava-webadmin-bbs
Reference: URL:http://xforce.iss.net/static/5135.php

Description:
The administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invoke the com.sun.server.http.pagecompile.jsp92.JspServlet by requesting a URL that begins with a /servlet/ tag.

Votes:

   ACCEPT(2) Baker, Dik
   MODIFY(2) Frech, Levy
   NOOP(3) Wall, Cole, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:sunjava-webadmin-bbs(5135)
 Levy> BID 1600
 Frech> We also show this associated with CAN-2000-0629: The default
   configuration of the Sun Java web server 2.0 and earlier allows remote
   attackers to execute arbitrary commands by uploading Java code to the
   server via board.html, then directly calling the JSP compiler
   servlet. CVE web site concurs.
 Christey> I think that Casper Dik confirmed that CAN-2000-0629 is a
   configuration problem, and this one is a bug, so they are
   different problems.  I need to dig up that email, though...
 Dik> CAN-2000-0629 indeed is about sample code which shouldn't
   be run on prodution servers
   This one is an actual bug and patches have been produced
   for JWS 2.0 and 1.1.3


CAN-2000-0817

Phase: Modified (20010119-01)
Reference: ISS:20001101 Buffer Overflow in Microsoft Windows NT 4.0 and Windows 2000 Network Monitor
Reference: URL:http://xforce.iss.net/alerts/index.php
Reference: MS:MS00-083
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-083.asp
Reference: XF:network-monitor-bo(5399)

Description:
Buffer overflow in the HTTP protocol parser for Microsoft Network Monitor (Netmon) allows remote attackers to execute arbitrary commands via malformed data, aka the "Netmon Protocol Parsing" vulnerability.

Votes:

   ACCEPT(3) Baker, Mell, Cole
   MODIFY(1) Frech
   NOOP(1) Renaud
Voter Comments:
 Frech> XF:network-monitor-bo(5399)


CAN-2000-0826

Phase: Proposed (20001018)
Reference: ATSTAKE:A090800-1
Reference: URL:http://www.atstake.com/research/advisories/2000/a090800-1.txt
Reference: BID:1657
Reference: URL:http://www.securityfocus.com/bid/1657
Reference: XF:documentdirect-get-bo
Reference: URL:http://xforce.iss.net/static/5210.php

Description:
Buffer overflow in ddicgi.exe program in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long GET request.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0827

Phase: Proposed (20001018)
Reference: ATSTAKE:A090800-1
Reference: URL:http://www.atstake.com/research/advisories/2000/a090800-1.txt
Reference: BID:1657
Reference: URL:http://www.securityfocus.com/bid/1657
Reference: XF:documentdirect-username-bo
Reference: URL:http://xforce.iss.net/static/5211.php

Description:
Buffer overflow in the web authorization form of Mobius DocumentDirect for the Internet 1.2 allows remote attackers to cause a denial of service or execute arbitrary commands via a long username.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0828

Phase: Proposed (20001018)
Reference: ATSTAKE:A090800-1
Reference: URL:http://www.atstake.com/research/advisories/2000/a090800-1.txt
Reference: BID:1657
Reference: URL:http://www.securityfocus.com/bid/1657
Reference: XF:documentdirect-user-agent-bo
Reference: URL:http://xforce.iss.net/static/5212.php

Description:
Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary commands via a long User-Agent parameter.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0831

Phase: Proposed (20001018)
Reference: WIN2KSEC:20000912 DST2K0027: DoS in Faststream FTP++ 2.0
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0109.html

Description:
Buffer overflow in Fastream FTP++ 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long username.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Magdych, Cole, Armstrong, Christey
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:fastream-ftp-dos(5235)
 Christey> XF:fastream-ftp-dos


CAN-2000-0832

Phase: Modified (20010910-01)
Reference: BUGTRAQ:20000817 Htgrep CGI Arbitrary File Viewing Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0208.html
Reference: XF:htgrep-cgi-view-files(5476)
Reference: URL:http://xforce.iss.net/static/5476.php

Description:
Htgrep CGI program allows remote attackers to read arbitrary files by specifying the full pathname in the hdr parameter.

Votes:

   ACCEPT(2) Baker, Collins
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:htgrep-cgi-view-files(5476)
 Collins> http://www.iam.unibe.ch/~scg/Src/Doc/
 Christey> The change log for htgrep acknowledges the problem, but it
   says that the qry tag is also affected.  CD:SF-LOC says that
   multiple problems of the same type in the same version should
   be combined, so this candidate should get a "soft recast"
   and qry should be added to the description.


CAN-2000-0833

Phase: Modified (20020222-01)
Reference: BUGTRAQ:2000911 WinSMTPD remote exploit/DoS problem
Reference: URL:http://www.securityfocus.com/archive/1/81693
Reference: BID:1680
Reference: URL:http://www.securityfocus.com/bid/1680
Reference: XF:winsmtp-helo-bo(5255)
Reference: URL:http://xforce.iss.net/static/5255.php

Description:
Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2) HELO command.

Votes:

   ACCEPT(5) Baker, Frech, Wall, Cole, Collins
   NOOP(2) Magdych, Armstrong
Voter Comments:
 Cole> HAS-INDEPENDENT-CONFIRMATION
 CHANGE> [Wall changed vote from REVIEWING to ACCEPT]


CAN-2000-0835

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000915 Sambar Server search CGI vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0175.html
Reference: BID:1684
Reference: URL:http://www.securityfocus.com/bid/1684

Description:
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query paramater.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Cole, Armstrong, Collins, Christey
   REJECT(2) Baker, Magdych
Voter Comments:
 Magdych> Unless the beta product is in very widespread use, or the product is in
   "perpetual beta" (e.g. ICQ), I would prefer not to include beta software.
 Christey> XF:sambar-search-view-folder
 Frech> XF:sambar-search-view-folder(5247)
 Baker> Unless we change our CD:EX-BETA, we should reject this entry.  Perhaps we need to address the issue of Beta software again, but the previous discussion was pretty thorough and I believe the editorial board was unanimous in excluding normal beta software.
 Christey> Fix typo: "paramater"


CAN-2000-0836

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000915 [NEWS] Vulnerability in CamShot server (Authorization)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0176.html
Reference: BID:1685
Reference: URL:http://www.securityfocus.com/bid/1685
Reference: XF:camshot-password-bo
Reference: URL:http://xforce.iss.net/static/5246.php

Description:
Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorization header.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Magdych, Cole, Armstrong
   REVIEWING(1) Wall

CAN-2000-0840

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html
Reference: BID:1652
Reference: URL:http://www.securityfocus.com/bid/1652
Reference: XF:xmail-long-user-bo
Reference: URL:http://xforce.iss.net/static/5192.php

Description:
Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long USER command.

Votes:

   ACCEPT(4) Baker, Cole, Armstrong, Collins
   NOOP(2) Wall, Christey
Voter Comments:
 Cole> INDEPENDENT-CONFIRMATION
 Christey> CONFIRM:http://www.mycio.com/davidel/xmail/xmaildoc.htm
   The entry dated 30-07-2000 for version 0.59 says: "A possible
   buffer overflow error has been fixed."


CAN-2000-0841

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000906 [NEWS] XMail vulnerable to a remotely exploitable buffer overflow (APOP, USER)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0001.html
Reference: BID:1652
Reference: URL:http://www.securityfocus.com/bid/1652
Reference: XF:xmail-long-apop-bo
Reference: URL:http://xforce.iss.net/static/5191.php

Description:
Buffer overflow in XMail POP3 server before version 0.59 allows remote attackers to execute arbitrary commands via a long APOP command.

Votes:

   ACCEPT(4) Baker, Cole, Armstrong, Collins
   NOOP(2) Wall, Christey
Voter Comments:
 Cole> INDEPENDENT-CONFIRMATION
 Christey> CONFIRM:http://www.mycio.com/davidel/xmail/xmaildoc.htm
   The entry dated 30-07-2000 for version 0.59 says: "A possible
   buffer overflow error has been fixed."


CAN-2000-0842

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000911 SCO scohelhttp documentation webserver exposes local files
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0086.html
Reference: BID:1663
Reference: URL:http://www.securityfocus.com/bid/1663

Description:
The search97cgi/vtopic" in the UnixWare 7 scohelphttp webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(5) Magdych, Wall, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:sco-help-view-files(5226)
 Christey> What is the proper "spelling" for the SCO help HTTP server?
   I've seen it as "SCOhelp" and "scohelphttp" and "SCO help HTTP"
 Christey> XF:sco-help-view-files


CAN-2000-0843

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000910 (SRADV00002) Remote root compromise through pam_smb and pam_ntdom
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0073.html
Reference: DEBIAN:20000911 libpam-smb: remote root exploit
Reference: URL:http://www.debian.org/security/2000/20000911
Reference: SUSE:20000913 pam_smb remotely exploitable buffer overflow
Reference: URL:http://www.suse.de/de/support/security/adv8_draht_pam_smb_txt.txt
Reference: MANDRAKE:MDKSA-2000:047
Reference: URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-047.php3
Reference: BUGTRAQ:20000911 Conectiva Linux Security Announcement - pam_smb
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0114.html
Reference: BID:1666
Reference: URL:http://www.securityfocus.com/bid/1666

Description:
Buffer overflow in pam_smb and pam_ntdom pluggable authentication modules (PAM) allow remote attackers to execute arbitrary commands via a login with a long user name.

Votes:

   ACCEPT(4) Baker, Magdych, Armstrong, Collins
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Magdych> ACKNOWLEDGED-BY-VENDOR
 Christey> ADDREF XF:pam-authentication-bo
 Frech> XF:pam-authentication-bo(5225)


CAN-2000-0845

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000918 [ENIGMA] Digital UNIX/Tru64 UNIX remote kdebug Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0204.html

Description:
kdebug daemon (kdebugd) in Digital Unix 4.0F allows remote attackers to read arbitrary files by specifying the full file name in the initialization packet.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(5) Magdych, Wall, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:du-kdebugd-write-access(5262)
 Christey> This problem also allows attackers to overwrite files.
   ADDREF BID:1693
   ADDREF URL:http://www.securityfocus.com/bid/1693
   ADDREF XF:du-kdebugd-write-access
   ADDREF http://xforce.iss.net/static/5262.php


CAN-2000-0855

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000901 [EXPL] SunFTP vulnerable to two Denial-of-Service attacks (long buffer, half-open)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0408.html
Reference: BID:1637
Reference: URL:http://www.securityfocus.com/bid/1637

Description:
SunFTP build 9(1) allows remote attackers to cause a denial of service by connecting to the server and disconnecting before sending a newline.

Votes:

   ACCEPT(4) Baker, Cole, Armstrong, Collins
   NOOP(1) Wall
Voter Comments:
 Cole> INDEPENDENT-CONFIRMATION


CAN-2000-0857

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000909 format string bug in muh
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0067.html
Reference: BUGTRAQ:20000909 Re: format string bug in muh
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0068.html
Reference: BID:1665
Reference: URL:http://www.securityfocus.com/bid/1665
Reference: XF:muh-log-dos
Reference: URL:http://xforce.iss.net/static/5215.php

Description:
The logging capability in muh 2.05d IRC server does not properly cleanse user-injected format strings, which allows remote attackers to cause a denial of service or execute arbitrary commands via a malformed nickname.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Collins
   NOOP(4) Magdych, Wall, Armstrong, Christey
Voter Comments:
 Cole> HAS-INDEPENDENT-CONFIRMATION
 Christey> ADDREF FREEBSD:FreeBSD-SA-00:57
 CHANGE> [Magdych changed vote from REVIEWING to NOOP]


CAN-2000-0866

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000907 SEGFAULTING Interbase 6 SS Linux
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0027.html
Reference: BID:1654
Reference: URL:http://www.securityfocus.com/bid/1654
Reference: XF:interbase-query-dos
Reference: URL:http://xforce.iss.net/static/5205.php

Description:
Interbase 6 SuperServer for Linux allows an attacker to cause a denial of service via a query containing 0 bytes.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0872

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000906 PhotoAlbum 0.9.9 explorer.php Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0015.html
Reference: BID:1650
Reference: URL:http://www.securityfocus.com/bid/1650
Reference: XF:phpphoto-dir-traverse
Reference: URL:http://xforce.iss.net/static/5198.php

Description:
explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0879

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000906 Multiple Security Holes in LPPlus
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html
Reference: BID:1643
Reference: URL:http://www.securityfocus.com/bid/1643
Reference: XF:lpplus-permissions-dos
Reference: URL:http://xforce.iss.net/static/5199.php

Description:
LPPlus programs dccsched, dcclpdser, dccbkst, dccshut, dcclpdshut, and dccbkstshut are installed setuid root and world executable, which allows arbitrary local users to start and stop various LPD services.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0880

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000906 Multiple Security Holes in LPPlus
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html
Reference: BID:1643
Reference: URL:http://www.securityfocus.com/bid/1643
Reference: XF:lpplus-process-perms-dos
Reference: URL:http://xforce.iss.net/static/5200.php

Description:
LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processes by specifying an alternate process ID and using the setuid dcclpdshut program to kill the process that was specified in the lpdprocess file.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0881

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000906 Multiple Security Holes in LPPlus
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0531.html
Reference: BID:1644
Reference: URL:http://www.securityfocus.com/bid/1644
Reference: XF:lpplus-dccscan-file-read
Reference: URL:http://xforce.iss.net/static/5201.php

Description:
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is specified to dccscan, which allows local users to print arbitrary files.

Votes:

   ACCEPT(2) Baker, Collins
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0882

Phase: Proposed (20001018)
Reference: BUGTRAQ:20000906 VIGILANTE-2000010: Intel Express Switch series 500 DoS #2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-08/0533.html
Reference: BID:1647
Reference: URL:http://www.securityfocus.com/bid/1647

Description:
Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.

Votes:

   ACCEPT(1) Baker
   NOOP(3) Wall, Cole, Armstrong

CAN-2000-0885

Phase: Modified (20010119-01)
Reference: NAI:20001101 Multiple Network Monitor Overflows
Reference: MS:MS00-083
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-083.asp
Reference: XF:network-monitor-bo(5399)

Description:
Buffer overflows in Microsoft Network Monitor (Netmon) allow remote attackers to execute arbitrary commands via a long Browser Name in a CIFS Browse Frame, a long SNMP community name, or a long username or filename in an SMB session, aka the "Netmon Protocol Parsing" vulnerability. NOTE: It is highly likely that this candidate will be split into multiple candidates.

Votes:

   ACCEPT(4) Baker, Renaud, Mell, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:network-monitor-bo(5399)


CAN-2000-0889

Phase: Proposed (20010202)
Reference: CERT:CA-2000-19
Reference: URL:http://www.cert.org/advisories/CA-2000-19.html
Reference: SUN:00198
Reference: URL:http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/198&type=0&nav=sec.sba

Description:
Two Sun security certificates have been compromised, which could allow attackers to insert malicious code such as applets and make it appear that it is signed by Sun.

Votes:

   ACCEPT(3) Baker, Cole, Dik
   MODIFY(1) Frech
   NOOP(2) Ziese, Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:sun-compromised-certificate(5404)
 Christey> Should revoked cert's be included in CVE?  How about the ones
   for Microsoft from early 2001?


CAN-2000-0893

Phase: Proposed (20010202)
Reference: CERT-VN:VU#28027
Reference: URL:http://www.kb.cert.org/vuls/id/28027

Description:
The presence of the Distributed GL Daemon (dgld) service on port 5232 on SGI IRIX systems allows remote attackers to identify the target host as an SGI system.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REVIEWING(1) Ziese
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:irix-dgld-port-scan(6592)


CAN-2000-0894

Phase: Proposed (20010202)
Reference: ISS:20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall
Reference: URL:http://xforce.iss.net/alerts/advise70.php

Description:
HTTP server on the WatchGuard SOHO firewall does not properly restrict access to administrative functions such as password resets or rebooting, which allows attackers to cause a denial of service or conduct unauthorized activities.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:watchguard-soho-web-auth(5554)
 Christey> Consider adding BID:2119


CAN-2000-0895

Phase: Proposed (20010202)
Reference: ISS:20001214 Multiple vulnerabilities in the WatchGuard SOHO Firewall
Reference: URL:http://xforce.iss.net/alerts/advise70.php
Reference: BID:2114
Reference: URL:http://www.securityfocus.com/bid/2114

Description:
Buffer overflow in HTTP server on the WatchGuard SOHO firewall allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:watchguard-soho-web-dos(5218)


CAN-2000-0898

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001114 Vulnerabilites in SmallHTTP Server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97421834001092&w=2

Description:
Small HTTP Server 2.01 does not properly process Server Side Includes (SSI) tags that contain null values, which allows local users, and possibly remote attackers, to cause the server to crash by inserting the SSI into an HTML file.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Balinsky, Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:small-http-ssi-dos(5960)
 Balinsky> Found no data on vendor web site to support this.
   http://home.lanck.net/mf/srv/index.htm


CAN-2000-0899

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001114 Vulnerabilites in SmallHTTP Server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97421834001092&w=2
Reference: BID:1942
Reference: URL:http://www.securityfocus.com/bid/1942

Description:
Small HTTP Server 2.01 allows remote attackers to cause a denial of service by connecting to the server and sending out multiple GET, HEAD, or POST requests and closing the connection before the server responds to the requests.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Balinsky, Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:small-http-request-dos(5523)
 Balinsky> Found no data on vendor web site to support this.
   http://home.lanck.net/mf/srv/index.htm


CAN-2000-0902

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000907 Re: PhotoAlbum 0.9.9 explorer.php Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/80858
Reference: XF:phpphotoalbum-getalbum-directory-traversal
Reference: URL:http://xforce.iss.net/static/5209.php

Description:
getalbum.php in PhotoAlbum before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(2) Mell, Collins
   NOOP(2) Wall, Cole

CAN-2000-0903

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000901 Multiple QNX Voyager Issues
Reference: URL:http://www.securityfocus.com/archive/1/79956
Reference: BID:1648
Reference: URL:http://www.securityfocus.com/bid/1648

Description:
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(1) Mell
   NOOP(3) Wall, Cole, Collins
   REVIEWING(1) Baker
Voter Comments:
 Collins> Assigning CVE numbers for demo software is not appropriate
 Baker> Was this a beta version in the demo disk?  I don't think it was.  While we do have an exclusion for beta software,
   software that is distributed as production software, just limited in scope, does not mean beta..
   The current version is 4, but it is still offered for free download from their website for use.


CAN-2000-0904

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000901 Multiple QNX Voyager Issues
Reference: URL:http://www.securityfocus.com/archive/1/79956
Reference: BID:1648
Reference: URL:http://www.securityfocus.com/bid/1648

Description:
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote attackers to obtain that information.

Votes:

   ACCEPT(1) Mell
   NOOP(3) Wall, Cole, Collins
Voter Comments:
 Collins> assigning CVE numbers for demo software is not appropriate


CAN-2000-0905

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000901 Multiple QNX Voyager Issues
Reference: URL:http://www.securityfocus.com/archive/1/79956
Reference: BID:1648
Reference: URL:http://www.securityfocus.com/bid/1648

Description:
QNX Embedded Resource Manager in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to read sensitive system statistics information via the embedded.html web page.

Votes:

   ACCEPT(1) Mell
   NOOP(2) Wall, Cole

CAN-2000-0906

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001002 Moreover Cached_Feed CGI Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0013.html
Reference: XF:moreover-cgi-dir-traverse
Reference: URL:http://xforce.iss.net/static/5334.php
Reference: BID:1762
Reference: URL:http://www.securityfocus.com/bid/1762

Description:
Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the category or format parameters.

Votes:

   ACCEPT(3) Frech, Mell, Collins
   NOOP(2) Wall, Cole

CAN-2000-0907

Phase: Proposed (20001129)
Reference: WIN2KSEC:20000925 DST2K0030: DoS in EServ 2.92 Build 2982
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2000-q3/0131.html

Description:
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.

Votes:

   ACCEPT(3) Baker, Mell, Collins
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:eserv-remote-dos(5643)


CAN-2000-0916

Phase: Proposed (20001129)
Reference: FREEBSD:FreeBSD-SA-00:52
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:52.tcp-iss.asc
Reference: BID:1766
Reference: URL:http://www.securityfocus.com/bid/1766

Description:
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.

Votes:

   ACCEPT(2) Mell, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:tcp-seq-predict(139)
 Christey> Abstraction issue: CVE-1999-0077 is for TCP sequence
   prediction as a general problem; but here we have a specific
   implementation flaw.


CAN-2000-0918

Phase: Proposed (20001129)
Reference: BID:1700
Reference: URL:http://www.securityfocus.com/bid/1700
Reference: BUGTRAQ:20000919 kvt format bug
Reference: URL:http://www.securityfocus.com/archive/1/83914

Description:
Format string vulnerability in kvt in KDE 1.1.2 may allow local users to execute arbitrary commands via a DISPLAY environmental variable that contains formatting characters.

Votes:

   ACCEPT(2) Baker, Mell
   NOOP(2) Wall, Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> May be a duplicate of CVE-2000-0373, but the ref's in that CVE
   are vague.  I suspect this *isn't* a duplicate because this is
   a format string problem.
 Baker> I think it is sufficiently different from 2000-0373.


CAN-2000-0931

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001004 Another Pegasus Mail vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/137518
Reference: BID:1750
Reference: URL:http://www.securityfocus.com/bid/1750

Description:
Buffer overflow in Pegasus Mail 3.11 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long email message containing binary data.

Votes:

   ACCEPT(1) Mell
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:pegasus-mail-bo(5644)


CAN-2000-0939

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001030 Samba 2.0.7 SWAT vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0430.html
Reference: XF:samba-swat-url-filename-dos
Reference: URL:http://xforce.iss.net/static/5444.php

Description:
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.

Votes:

   ACCEPT(2) Frech, Mell
   NOOP(1) Cole
   REJECT(1) Renaud
Voter Comments:
 Renaud> SWAT makes this DoS easier to perform, but actually, it is an inetd
   problem, not a swat problem.


CAN-2000-0940

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001029 Minor bug in Pagelog.cgi
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0422.html
Reference: BID:1864
Reference: URL:http://www.securityfocus.com/bid/1864
Reference: XF:pagelog-cgi-dir-traverse
Reference: URL:http://xforce.iss.net/static/5451.php

Description:
Directory traversal vulnerability in Metertek pagelog.cgi allows remote attackers to read arbitrary files via a .. (dot dot) attack on the "name" or "display" parameter.

Votes:

   ACCEPT(2) Frech, Mell
   NOOP(1) Cole

CAN-2000-0950

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001026 FWTK x-gw Security Advisory [GSA2000-01]
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0376.html
Reference: XF:tisfwtk-xgw-execute-code
Reference: URL:http://xforce.iss.net/static/5420.php

Description:
Format string vulnerability in x-gw in TIS Firewall Toolkit (FWTK) allows local users to execute arbitrary commands via a malformed display name.

Votes:

   ACCEPT(4) Baker, Frech, Mell, Cole
   NOOP(1) Renaud
   REVIEWING(1) Christey
Voter Comments:
 Christey> I thought I saw some mailing list that questioned whether this
   problem was only a DoS...


CAN-2000-0954

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001009 Shambala 4.5 vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0134.html
Reference: BID:1771
Reference: URL:http://www.securityfocus.com/bid/1771
Reference: XF:shambala-password-plaintext
Reference: URL:http://xforce.iss.net/static/5346.php

Description:
Shambala Server 4.5 stores passwords in plaintext, which could allow local users to obtain the passwords and compromise the server.

Votes:

   ACCEPT(3) Baker, Frech, Mell
   NOOP(1) Cole

CAN-2000-0955

Phase: Proposed (20001129)
Reference: ATSTAKE:A102600-1
Reference: URL:http://www.atstake.com/research/advisories/2000/a102600-1.txt
Reference: BID:1885
Reference: URL:http://www.securityfocus.com/bid/1885
Reference: XF:cisco-vco-snmp-passwords
Reference: URL:http://xforce.iss.net/static/5425.php

Description:
Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker who knows the community name to crack the password and gain privileges.

Votes:

   ACCEPT(4) Frech, Ziese, Mell, Cole
   NOOP(2) Christey, Balinsky
Voter Comments:
 Christey> CISCO:20001026 VCO/4K Remote Password Disclosure
   http://www.cisco.com/warp/public/707/vco4kpasswdexposure-pub.shtml
 CHANGE> [Balinsky changed vote from REVIEWING to NOOP]


CAN-2000-0963

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001009 ncurses buffer overflows
Reference: URL:http://www.securityfocus.com/archive/1/138550
Reference: CALDERA:CSSA-2000-036.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-036.0.txt
Reference: BID:1142
Reference: URL:http://www.securityfocus.com/bid/1142

Description:
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.

Votes:

   ACCEPT(2) Mell, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> Various vendor writeups indicate that there are multiple
   overflows, so maybe this needs to be SPLIT.
   
   ADDREF FREEBSD:FreeBSD-SA-00:68
   ADDREF DEBIAN:20001121 ncurses: local privilege escalation
   http://www.debian.org/security/2000/20001121
   ADDREF REDHAT:RHSA-2000:115
   http://www.redhat.com/support/errata/RHSA-2000-115.html
   BUGTRAQ:20001201 Immunix OS Security update for ncurses
   http://marc.theaimsgroup.com/?l=bugtraq&m=97570745306444&w=2
 Frech> XF:libmytinfo-bo(4422)
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> This is all a library issue in which TERM/TERMINFO_DIRS are
   one possible attack vector, but another is through entries
   in the .terminfo file.  Add .terminfo and termcap to the
   description, as well as libncurses.
   
   ADDREF MANDRAKE:MDKSA-2001:052
   URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-052.php3
   
   Now need to examine whether this is a dupe of CAN-2002-0062,
   and/or BID:2116.  There's certainly enough confusion to go
   around.
 CHANGE> [Christey changed vote from REVIEWING to NOOP]
 Christey> This is not a dupe of CAN-2002-0062.  As explained in
   DEBIAN:DSA-113, the original patches for CAN-2000-0963
   didn't catch every problem.
   
   ADDREF SUSE:SuSE-SA:2000:043
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97267560724404&w=2
 CHANGE> [Christey changed vote from NOOP to REVIEWING]


CAN-2000-0971

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001023 Avirt Mail 4.x DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0301.html
Reference: XF:avirt-mail-from-dos
Reference: URL:http://xforce.iss.net/static/5397.php
Reference: XF:avirt-rcpt-to-dos
Reference: URL:http://xforce.iss.net/static/5398.php

Description:
Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possible execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

Votes:

   ACCEPT(3) Frech, Mell, Cole
   NOOP(2) Christey, Armstrong
Voter Comments:
 Christey> Fix typo: "possible" should be "possibly"
 Christey> fix typo: "and possible"


CAN-2000-0985

Phase: Proposed (20001129)
Reference: ATSTAKE:A101200-2
Reference: URL:http://www.atstake.com/research/advisories/2000/a101200-2.txt
Reference: BID:1789
Reference: URL:http://www.securityfocus.com/bid/1789

Description:
Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.

Votes:

   ACCEPT(2) Baker, Mell
   MODIFY(1) Frech
   NOOP(1) Cole
Voter Comments:
 Frech> XF:all-mail-smtp-bo(5360)


CAN-2000-0986

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001020 [ Hackerslab bug_paper ] Linux ORACLE 8.1.5 vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0294.html
Reference: XF:oracle-home-bo
Reference: URL:http://xforce.iss.net/static/5390.php

Description:
Buffer overflow in Oracle 8.1.5 applications such as names, namesctl, onrsd, osslogin, tnslsnr, tnsping, trcasst, and trcroute possibly allow local users to gain privileges via a long ORACLE_HOME environmental variable.

Votes:

   ACCEPT(3) Baker, Frech, Mell
   NOOP(2) Cole, Armstrong

CAN-2000-0987

Phase: Proposed (20001129)
Reference: XF:oracle-oidldap-bo
Reference: URL:http://xforce.iss.net/static/5401.php
Reference: BUGTRAQ:20001018 vulnerability in Oracle Internet Directory in Oracle 8.1.6
Reference: URL:http://www.securityfocus.com/archive/1/140340
Reference: BUGTRAQ:20001020 In response to posting 10/18/2000 vulnerability in Oracle Internet Directory in Oracle 8.1.6
Reference: URL:http://www.securityfocus.com/archive/1/140709

Description:
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line parameter.

Votes:

   ACCEPT(3) Frech, Mell, Cole
   NOOP(2) Christey, Armstrong
Voter Comments:
 Christey> http://archives.neohapsis.com/archives/bugtraq/2000-12/0400.html
   appears to be a rediscovery of this problem.
 Christey> It looks like Juan Manuel Pascual Escriba saw this issue
   in a later version and re-posted, but that later post doesn't
   mention the earlier one.  The exploit is almost exactly the
   same, but the affected version is 8.1.7.
   ADDREF BUGTRAQ:20001221 vulnerability #1 in Oracle Internet Directory 2.1.1.1 in Oracle 8.1.7
   http://archives.neohapsis.com/archives/bugtraq/2000-12/0400.html
   ADDREF BUGTRAQ:20010118 Patch for Potential Buffer Overflow Vulnerabilities in Oracle Internet Directory
   http://archives.neohapsis.com/archives/bugtraq/2001-01/0325.html


CAN-2000-0988

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001013 WinU Backdoor passwords!!!!
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0238.html
Reference: CONFIRM:http://www.bardon.com/pwdcrack.htm
Reference: BID:1801
Reference: URL:http://www.securityfocus.com/bid/1801
Reference: XF:winu-backdoor
Reference: URL:http://xforce.iss.net/static/5376.php

Description:
WinU 1.0 through 5.1 has a backdoor password that allows remote attackers to gain access to its administrative interface and modify configuration.

Votes:

   ACCEPT(4) Frech, Mell, Cole, Armstrong

CAN-2000-0997

Phase: Proposed (20001129)
Reference: OPENBSD:20001006 There are printf-style format string bugs in several privileged programs.
Reference: MISC:ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch
Reference: BID:1752
Reference: URL:http://www.securityfocus.com/bid/1752
Reference: XF:bsd-eeprom-format
Reference: URL:http://xforce.iss.net/static/5337.php

Description:
Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.

Votes:

   ACCEPT(3) Frech, Mell, Cole
   NOOP(1) Wall

CAN-2000-0998

Phase: Proposed (20001129)
Reference: OPENBSD:20001006 There are printf-style format string bugs in several privileged programs.
Reference: MISC:ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch
Reference: FREEBSD:FreeBSD-SA-00:62
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:62.top.v1.1.asc
Reference: BID:1895
Reference: URL:http://www.securityfocus.com/bid/1895

Description:
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.

Votes:

   ACCEPT(3) Mell, Cole, Collins
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
Voter Comments:
 Frech> XF:top-format-string(5486)
 Christey> BUGTRAQ:20011114 SCO skunkware top format strings issue
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100576637928933&w=2


CAN-2000-0999

Phase: Proposed (20001129)
Reference: OPENBSD:20001006 There are printf-style format string bugs in several privileged programs.
Reference: MISC:ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/028_format_strings.patch

Description:
Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Mell
Voter Comments:
 Frech> XF:bsd-ssh-format(5637)


CAN-2000-1008

Phase: Modified (20010116-01)
Reference: ATSTAKE:A092600-1
Reference: URL:http://www.atstake.com/research/advisories/2000/a092600-1.txt
Reference: BID:1715
Reference: URL:http://www.securityfocus.com/bid/1715

Description:
PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to the Palm device to decrypt the password and gain access to the device.

Votes:

   ACCEPT(2) Mell, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:palm-weak-encryption(5308)


CAN-2000-1009

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001030 Redhat 6.2 dump command executes external program with suid priviledge.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0438.html
Reference: BID:1871
Reference: URL:http://www.securityfocus.com/bid/1871
Reference: XF:linux-dump-execute-code
Reference: URL:http://xforce.iss.net/static/5437.php

Description:
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.

Votes:

   ACCEPT(5) Baker, Frech, Renaud, Mell, Cole
   NOOP(1) Christey
Voter Comments:
 Christey> http://www.redhat.com/support/errata/RHSA-2000-100.html
   ADDREF BUGTRAQ:20001103 Trustix Security Advisory - dump
   http://archives.neohapsis.com/archives/bugtraq/2000-11/0026.html


CAN-2000-1012

Phase: Proposed (20001129)
Reference: FREEBSD:FreeBSD-SA-00:53
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc

Description:
The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.

Votes:

   ACCEPT(3) Mell, Cole, Collins
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:freebsd-display-read-files(5645)


CAN-2000-1013

Phase: Proposed (20001129)
Reference: FREEBSD:FreeBSD-SA-00:53
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:53.catopen.asc

Description:
The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.

Votes:

   ACCEPT(2) Mell, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:freebsd-display-read-files(5645)


CAN-2000-1015

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000929 Default admin password with Slashcode.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0366.html
Reference: BID:1731
Reference: URL:http://www.securityfocus.com/bid/1731
Reference: XF:slashcode-default-admin-passwords
Reference: URL:http://xforce.iss.net/static/5306.php

Description:
The default configuration of Slashcode before version 2.0 Alpha has a default administrative password, which allows remote attackers to gain Slashcode priviliges and possibly execute arbitrary commands.

Votes:

   ACCEPT(4) Frech, Mell, Cole, Collins
   NOOP(1) Wall

CAN-2000-1017

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001002 DST2K0039: Webteachers Webdata: Importing files lower than web ro ot possible in to database
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0007.html
Reference: BUGTRAQ:20001003 Update to DST2K0039: Webteachers Webdata: Importing files lower t han web root possible in to database
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0032.html
Reference: BID:1732
Reference: URL:http://www.securityfocus.com/bid/1732

Description:
Webteachers Webdata allows remote attackers with valid Webdata accounts to read arbitrary files by posting a request to import the file into the WebData database.

Votes:

   ACCEPT(2) Frech, Mell
   NOOP(2) Wall, Cole

CAN-2000-1020

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96925269716274&w=2
Reference: BID:1689
Reference: URL:http://www.securityfocus.com/bid/1689
Reference: XF:mdaemon-url-dos
Reference: URL:http://xforce.iss.net/static/5250.php

Description:
Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.

Votes:

   ACCEPT(4) Baker, Mell, Cole, Collins
   NOOP(1) Wall

CAN-2000-1021

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000917 VIGILANTE-2000012: Mdaemon Web Services Heap Overflow DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96925269716274&w=2
Reference: BID:1689
Reference: URL:http://www.securityfocus.com/bid/1689
Reference: XF:mdaemon-url-dos
Reference: URL:http://xforce.iss.net/static/5250.php

Description:
Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL.

Votes:

   ACCEPT(4) Baker, Mell, Cole, Collins
   NOOP(1) Wall

CAN-2000-1023

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000924 Major Vulnerability in Alabanza Control Panel
Reference: URL:http://www.securityfocus.com/archive/1/84766
Reference: BID:1710
Reference: URL:http://www.securityfocus.com/bid/1710
Reference: XF:alabanza-unauthorized-access
Reference: URL:http://xforce.iss.net/static/5284.php

Description:
The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers to modify domain name information via the nsManager.cgi CGI program.

Votes:

   ACCEPT(2) Mell, Collins
   NOOP(2) Wall, Cole
   REVIEWING(1) Baker
Voter Comments:
 Baker> I agree with Steve that this appears to be an on-line applet, accessible from their server only.


CAN-2000-1025

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001030 Unify eWave ServletExec DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97295224226042&w=2
Reference: BID:1868
Reference: URL:http://www.securityfocus.com/bid/1868
Reference: XF:ewave-servletexec-dos
Reference: URL:http://xforce.iss.net/static/5435.php

Description:
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of service via a URL that contains the "/servlet/" string, which invokes the ServletExec servlet and causes an exception if the servlet is already running.

Votes:

   ACCEPT(2) Frech, Mell
   NOOP(1) Cole

CAN-2000-1028

Phase: Modified (20010119-01)
Reference: BUGTRAQ:20001102 HPUX cu -l option buffer overflow vulnerabilit
Reference: URL:http://www.securityfocus.com/archive/1/142792
Reference: BID:1886
Reference: URL:http://www.securityfocus.com/bid/1886
Reference: XF:hp-cu-bo(5460)

Description:
Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument.

Votes:

   ACCEPT(1) Mell
   MODIFY(1) Frech
   NOOP(2) Renaud, Cole
Voter Comments:
 Frech> XF:hp-cu-bo(5460)


CAN-2000-1029

Phase: Modified (20010119-01)
Reference: BUGTRAQ:20001027 old version of host command vulnearbility
Reference: URL:http://www.securityfocus.com/archive/1/141660
Reference: BID:1887
Reference: URL:http://www.securityfocus.com/bid/1887
Reference: XF:isc-bind-axfr-bo(5462)

Description:
Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR query.

Votes:

   ACCEPT(1) Mell
   MODIFY(1) Frech
   NOOP(2) Renaud, Cole
Voter Comments:
 Frech> XF:isc-bind-axfr-bo(5462)


CAN-2000-1030

Phase: Modified (20010119-01)
Reference: BUGTRAQ:20001031 Re: Samba 2.0.7 SWAT vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/142672
Reference: BID:1888
Reference: URL:http://www.securityfocus.com/bid/1888
Reference: XF:corporatetime-brute-force(5529)

Description:
CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.

Votes:

   ACCEPT(1) Mell
   MODIFY(1) Frech
   NOOP(1) Cole
Voter Comments:
 Frech> XF:corporatetime-brute-force(5529)


CAN-2000-1033

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001029 Brute Forcing FTP Servers with enabled anti-hammering (anti brute-force) modus
Reference: URL:http://www.securityfocus.com/archive/1/141905
Reference: BID:1860
Reference: URL:http://www.securityfocus.com/bid/1860
Reference: XF:ftp-servu-brute-force
Reference: URL:http://xforce.iss.net/static/5436.php

Description:
Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.

Votes:

   ACCEPT(2) Frech, Mell
   NOOP(1) Cole

CAN-2000-1035

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000912 TYPSoft FTP Server remote DoS Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96879389027478&w=2
Reference: MISC:http://www.synnergy.net/Archives/Advisories/dethy/typsoft-ftpd.txt
Reference: BID:1690
Reference: URL:http://www.securityfocus.com/bid/1690

Description:
Buffer overflows in TYPSoft FTP Server 0.78 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long USER, PASS, or CWD command.

Votes:

   ACCEPT(1) Mell
   MODIFY(1) Baker
   NOOP(2) Wall, Cole
Voter Comments:
 CHANGE> [Baker changed vote from NOOP to MODIFY]
 Baker> http://www.synnergy.net/downloads/advisories/SLA-2000-07.typsoft-ftpd.txt


CAN-2000-1037

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000815 Firewall-1 session agent 3.0 -> 4.1, dictionnary and brute force attack
Reference: URL:http://www.securityfocus.com/archive/1/76389
Reference: BID:1662
Reference: URL:http://www.securityfocus.com/bid/1662

Description:
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.

Votes:

   ACCEPT(2) Baker, Mell
   NOOP(2) Wall, Cole

CAN-2000-1039

Phase: Proposed (20001219)
Reference: BINDVIEW:20001130 The NAPTHA DoS vulnerabilities
Reference: URL:http://razor.bindview.com/publish/advisories/adv_NAPTHA.html
Reference: WIN2KSEC:20001204 NAPTHA Advisory Updated - BindView RAZOR
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0105.html
Reference: CERT:CA-2000-21
Reference: URL:http://www.cert.org/advisories/CA-2000-21.html
Reference: MS:MS00-091
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-091.asp
Reference: BID:2022
Reference: URL:http://www.securityfocus.com/bid/2022

Description:
Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connection attempts and completing the TCP/IP handshake without maintaining the connection state on the attacker host, aka the "NAPTHA" class of vulnerabilities. NOTE: this candidate may change significantly as the security community discusses the technical nature of NAPTHA and learns more about the affected applications. This candidate is at a higher level of abstraction than is typical for CVE.

Votes:

   ACCEPT(3) Baker, Renaud, Cole
   MODIFY(1) Frech
   NOOP(2) Magdych, Wall
   REVIEWING(1) Christey
Voter Comments:
 Baker> Although this is at a high level, the fact is that it is a vulnerability, and as such we need to recognize this, even if we have to recast or modify the description at some later time.
 Christey> This needs to be commented on and reviewed by many Board
   members.
 Frech> XF:naptha-resource-starvation(5810)
 Christey> ADDREF SGI:20020304-01-A
 Christey> SGI:20020304-01-A


CAN-2000-1046

Phase: Proposed (20001129)
Reference: BUGTRAQ:20000911 Advisory Code: VIGILANTE-2000011 Lotus Domino ESMTP Service Buffer overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-09/0093.html

Description:
Buffer overflows in ESMTP service of Lotus Domino 5.0.2c and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO," "SAML FROM," or "SOML FROM" command.

Votes:

   ACCEPT(1) Mell
   MODIFY(1) Collins
   NOOP(2) Wall, Cole
   REVIEWING(1) Baker
Voter Comments:
 Collins> http://www.synnergy.net/downloads/advisories/SLA-2000-07.typsoft-ftpd.txt
 Baker> Reference by Collins was entered into the wrong CAN Entry...
   It should have been for 2000-1035, not this CAN


CAN-2000-1048

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001016 Wingate 4.1 Beta A vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0245.html
Reference: XF:wingate-view-files
Reference: URL:http://xforce.iss.net/static/5373.php

Description:
Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.

Votes:

   ACCEPT(3) Baker, Frech, Mell
   NOOP(2) Cole, Armstrong

CAN-2000-1052

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001023 Allaire JRUN 2.3 Arbitrary File Retrieval
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97236692714978&w=2

Description:
Allaire JRun 2.3 server allows remote attackers to obtain source code for executable content by directly calling the SSIFilter servlet.

Votes:

   ACCEPT(3) Mell, Cole, Armstrong
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:allaire-jrun-ssifilter-url(5405)


CAN-2000-1053

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001023 Allaire JRUN 2.3 Remote command execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97236125107957&w=2
Reference: ALLAIRE:ASB00-029
Reference: URL:http://www.allaire.com/handlers/index.cfm?ID=17969&Method=Full
Reference: XF:allaire-jrun-jsp-execute
Reference: URL:http://xforce.iss.net/static/5406.php

Description:
Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scripting (CSS) attack and directly calling the com.livesoftware.jrun.plugins.JSP JSP servlet.

Votes:

   ACCEPT(4) Frech, Mell, Cole, Armstrong

CAN-2000-1062

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97119729613778&w=2
Reference: BID:1775
Reference: URL:http://www.securityfocus.com/bid/1775
Reference: XF:hp-jetdirect-firmware-dos
Reference: URL:http://xforce.iss.net/static/5353.php

Description:
Buffer overflow in the FTP service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

Votes:

   ACCEPT(3) Baker, Frech, Mell
   NOOP(1) Cole

CAN-2000-1063

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97119729613778&w=2
Reference: BID:1775
Reference: URL:http://www.securityfocus.com/bid/1775
Reference: XF:hp-jetdirect-firmware-dos
Reference: URL:http://xforce.iss.net/static/5353.php

Description:
Buffer overflow in the Telnet service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

Votes:

   ACCEPT(3) Frech, Mell, Cole

CAN-2000-1064

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97119729613778&w=2
Reference: BID:1775
Reference: URL:http://www.securityfocus.com/bid/1775
Reference: XF:hp-jetdirect-firmware-dos
Reference: URL:http://xforce.iss.net/static/5353.php

Description:
Buffer overflow in the LPD service in HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service.

Votes:

   ACCEPT(3) Frech, Mell, Cole

CAN-2000-1065

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001010 VIGILANTE-2000014: HP Jetdirect multiple DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97119729613778&w=2
Reference: BID:1775
Reference: URL:http://www.securityfocus.com/bid/1775
Reference: XF:hp-jetdirect-ip-implementation
Reference: URL:http://xforce.iss.net/static/5354.php

Description:
Vulnerability in IP implementation of HP JetDirect printer card Firmware x.08.20 and earlier allows remote attackers to cause a denial of service (printer crash) via a malformed packet.

Votes:

   ACCEPT(3) Baker, Frech, Mell
   NOOP(1) Cole

CAN-2000-1066

Phase: Modified (20010119-01)
Reference: FREEBSD:FreeBSD-SA-00:63
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:63.getnameinfo.asc
Reference: BID:1894
Reference: URL:http://www.securityfocus.com/bid/1894
Reference: XF:getnameinfo-dos(5454)

Description:
The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.

Votes:

   ACCEPT(2) Mell, Cole
   MODIFY(1) Frech
   NOOP(1) Renaud
Voter Comments:
 Frech> XF:getnameinfo-dos(5454)


CAN-2000-1076

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001026 [CORE SDI ADVISORY] iPlanet Certificate Management System 4.2 path traversal bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0383.html
Reference: XF:iplanet-netscape-plaintext-password
Reference: URL:http://xforce.iss.net/static/5422.php

Description:
Netscape (iPlanet) Certificate Management System 4.2 and Directory Server 4.12 stores the administrative password in plaintext, which could allow local and possibly remote attackers to gain administrative privileges on the server.

Votes:

   ACCEPT(3) Baker, Frech, Mell
   NOOP(2) Cole, Christey
Voter Comments:
 Christey> Partial vendor acknowledgement at:
   http://docs.iplanet.com/docs/manuals/cms/42/relnotes/release_notes.html
   "By default, Administration Server administrator's password
   (also known as the SIE password) is stored in clear text in the
   adm.conf file.
   This does not usually pose a security threat because most
   administrators use their Operating System's security features to
   ensure that the file is protected from other users."


CAN-2000-1078

Phase: Proposed (20001129)
Reference: BUGTRAQ:20001007 ICQ WebFront HTTPd DoS
Reference: URL:http://www.securityfocus.com/archive/1/138332
Reference: XF:icq-webfront-url-dos
Reference: URL:http://xforce.iss.net/static/5332.php

Description:
ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.

Votes:

   ACCEPT(3) Baker, Frech, Mell
   NOOP(2) Cole, Christey
Voter Comments:
 Christey> The following post appears to describe the same problem, 7
   months earlier:
   BUGTRAQ:20000310 ICQ remote DoS


CAN-2000-1079

Phase: Proposed (20001129)
Reference: NAI:20000829 Windows NetBIOS Unsolicited Cache Corruption
Reference: URL:http://www.nai.com/research/covert/advisories/045.asp
Reference: NTBUGTRAQ:20000829 Re: [COVERT-2000-10] Windows NetBIOS Unsolicited Cache Corruption
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q3/0116.html
Reference: BID:1620
Reference: URL:http://www.securityfocus.com/bid/1620
Reference: XF:win-netbios-corrupt-cache
Reference: URL:http://xforce.iss.net/static/5168.php

Description:
Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.

Votes:

   ACCEPT(3) Baker, Wall, Mell
   NOOP(1) Cole
   REVIEWING(1) Christey
Voter Comments:
 Wall> No known exploit or patch yet.
 Christey> This was a little controversial, if I recall correctly.


CAN-2000-1081

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 Microsoft SQL Server extended stored procedure vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570878710037&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2030
Reference: URL:http://www.securityfocus.com/bid/2030

Description:
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(3) Baker, Magdych, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Baker> ALready posted in refs
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1082

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 Microsoft SQL Server extended stored procedure vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570878710037&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2031
Reference: URL:http://www.securityfocus.com/bid/2031

Description:
The xp_enumresultset function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(3) Baker, Magdych, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1083

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 Microsoft SQL Server extended stored procedure vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570878710037&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2038
Reference: URL:http://www.securityfocus.com/bid/2038

Description:
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(3) Baker, Magdych, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1084

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 Microsoft SQL Server extended stored procedure vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570878710037&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2039
Reference: URL:http://www.securityfocus.com/bid/2039

Description:
The xp_updatecolvbm function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(3) Baker, Magdych, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1085

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 SQL Server 2000 Extended Stored Procedure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570884410184&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2040
Reference: URL:http://www.securityfocus.com/bid/2040

Description:
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(4) Baker, Magdych, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> CAN-2000-1085, CAN-2000-1086, CAN-2000-1087, and CAN-2000-1088
   all have abstraction issues; perhaps they should be RECAST
   into a single candidate.
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1086

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 SQL Server 2000 Extended Stored Procedure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570884410184&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2041
Reference: URL:http://www.securityfocus.com/bid/2041

Description:
The xp_printstatements function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(4) Baker, Magdych, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> CAN-2000-1085, CAN-2000-1086, CAN-2000-1087, and CAN-2000-1088
   all have abstraction issues; perhaps they should be RECAST
   into a single candidate.
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1087

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 SQL Server 2000 Extended Stored Procedure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570884410184&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2042
Reference: URL:http://www.securityfocus.com/bid/2042

Description:
The xp_proxiedmetadata function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(4) Baker, Magdych, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> CAN-2000-1085, CAN-2000-1086, CAN-2000-1087, and CAN-2000-1088
   all have abstraction issues; perhaps they should be RECAST
   into a single candidate.
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1088

Phase: Proposed (20001219)
Reference: ATSTAKE:20001201 SQL Server 2000 Extended Stored Procedure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97570884410184&w=2
Reference: MS:MS00-092
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-092.asp
Reference: BID:2043
Reference: URL:http://www.securityfocus.com/bid/2043

Description:
The xp_SetSQLSecurity function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.

Votes:

   ACCEPT(4) Baker, Magdych, Wall, Cole
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Christey> CAN-2000-1085, CAN-2000-1086, CAN-2000-1087, and CAN-2000-1088
   all have abstraction issues; perhaps they should be RECAST
   into a single candidate.
 Christey> ADDREF XF:mssql-xp-paraminfo-bo
   URL:http://xforce.iss.net/static/5622.php
 Frech> XF:mssql-xp-paraminfo-bo(5622)


CAN-2000-1090

Phase: Proposed (20010202)
Reference: MISC:http://www.nsfocus.com/english/homepage/sa_08.htm
Reference: BID:2100
Reference: URL:http://www.securityfocus.com/bid/2100
Reference: XF:microsoft-iis-file-disclosure
Reference: URL:http://xforce.iss.net/static/5729.php

Description:
Microsoft IIS for Far East editions 4.0 and 5.0 allows remote attackers to read source code for parsed pages via a malformed URL that uses the lead-byte of a double-byte character.

Votes:

   ACCEPT(3) Baker, Frech, LeBlanc
   NOOP(1) Cole
   REVIEWING(3) Ziese, Wall, Christey
Voter Comments:
 LeBlanc> Fixed in SP2 for Win2K. NT 4.0 is not affected. bulletin
   MS99-022
 Christey> Need to add the Bugtraq references for this.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Is this really the same problem addressed by MS99-022,
   which is covered by CVE-1999-0725 ?


CAN-2000-1092

Phase: Modified (20020327-01)
Reference: BUGTRAQ:20001213 NSFOCUS SA2000-09 : AHG EZshopper Loadpage.cgi File List
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97676270729984&w=2
Reference: BID:2109
Reference: URL:http://online.securityfocus.com/bid/2109
Reference: XF:ezshopper-cgi-file-disclosure(5740)
Reference: URL:http://xforce.iss.net/static/5740.php

Description:
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data directory by inserting a "/" in front of the target filename in the "file" parameter.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Magdych, Wall, Cole, Christey
Voter Comments:
 Christey> This is documented in an NSFOCUS security advisory released
   sometime around December 11.  Also, it's BID:2109.
 Christey> BUGTRAQ:20001213 NSFOCUS SA2000-09 : AHG EZshopper Loadpage.cgi File List
   http://marc.theaimsgroup.com/?l=bugtraq&m=97676270729984&w=2
   XF:ezshopper-cgi-file-disclosure
   URL:http://xforce.iss.net/static/5740.php
 Frech> XF:ezshopper-cgi-file-disclosure(5740)
 Christey> Followup posts indicate that this problem may have been
   discovered earlier than 20001213.


CAN-2000-1093

Phase: Modified (20010417-01)
Reference: ATSTAKE:A121200-1
Reference: URL:http://www.atstake.com/research/advisories/2000/a121200-1.txt
Reference: XF:aim-remote-bo(5732)

Description:
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a long "goim" command.

Votes:

   ACCEPT(2) Baker, Wall
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:aim-remote-bo(5732)
 Christey> CD:SF-LOC as currently written suggests merging this with
   CVE-2000-1094, since both describe buffer overflows in the
   same software version.
 Christey> Consider adding BID:2118


CAN-2000-1098

Phase: Interim (20010117)
Reference: BUGTRAQ:20001201 Re: DoS in Sonicwall SOHO firewall
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0439.html
Reference: BUGTRAQ:20001201 FW: SonicWALL SOHO Vulnerability (fwd)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0435.html

Description:
The web server for the SonicWALL SOHO firewall allows remote attackers to cause a denial of service via an empty GET or POST request.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> The company's name is SonicWALL.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:sonicwall-empty-request-dos(6042)
   The company's name is SonicWALL.


CAN-2000-1100

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001130 PostACI Webmail Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0433.html
Reference: BID:2029
Reference: URL:http://www.securityfocus.com/bid/2029

Description:
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web root, which allows remote attackers to read sensitive information such as database usernames and passwords via a direct HTTP GET request.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:postaci-webmail-reveal-passwords(5612)


CAN-2000-1102

Phase: Proposed (20001219)
Reference: BID:2008
Reference: URL:http://www.securityfocus.com/bid/2008
Reference: BUGTRAQ:20001126 Vulnerablity in PTlink3.5.3ircd + PTlink.Services.1.8.1...
Reference: URL:http://www.securityfocus.com/archive/1/147115

Description:
PTlink IRCD 3.5.3 and PTlink Services 1.8.1 allow remote attackers to cause a denial of service (server crash) via "mode +owgscfxeb" and "oper" commands.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:ptlink-ircd-mode-dos(5589)


CAN-2000-1103

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001127 BSDi 3.0/4.0 rcvtty gid=tty exploit... (mh package)
Reference: URL:http://www.securityfocus.com/archive/1/147120
Reference: BID:2009
Reference: URL:http://www.securityfocus.com/bid/2009

Description:
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to gain privileges by specifying an alternate Trojan horse script on the command line.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:rcvtty-elevate-privileges(5587)


CAN-2000-1104

Phase: Proposed (20001219)
Reference: MS:MS00-060
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms00-060.asp

Description:
Variant of the "IIS Cross-Site Scripting" vulnerability as originally discussed in MS:MS00-060 (CAN-2000-0746) allows a malicious web site operator to embed scripts in a link to a trusted site, which are returned without quoting in an error message back to the client. The client then executes those scripts in the same context as the trusted site.

Votes:

   ACCEPT(3) Baker, Wall, Cole
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:iis-cross-site-scripting(5156)


CAN-2000-1105

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001110 IE 5.x Win2000 Indexing service vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/144270
Reference: WIN2KSEC:20001110 IE 5.x Win2000 Indexing service vulnerability
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0074.html
Reference: BID:1933
Reference: URL:http://www.securityfocus.com/bid/1933

Description:
The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a script that remotely determines the existence of files on visiting Windows 2000 systems that have Indexing Services enabled.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   REVIEWING(2) Wall, Christey
Voter Comments:
 Frech> XF:win2k-index-service-ixsso(5502)
 Christey> ADDREF MS:MS00-098
   ADDREF XF:win2k-index-service-activex
   URL:http://xforce.iss.net/static/5800.php
   Add 'aka the "Indexing Service File Enumeration" vulnerability'
   to the description.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> DUPE CVE-2001-0245?  Need to check w/Microsoft.


CAN-2000-1110

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001128 IBM Net.Data Local Path Disclosure Vulnerability?
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0384.html
Reference: BID:2017
Reference: URL:http://www.securityfocus.com/bid/2017

Description:
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of the web server by sending a nonexistent command to the program.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:ibm-netdata-reveal-path(5599)


CAN-2000-1114

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001121 Disclosure of JSP source code with ServletExec AS v3.0c + web ins tance
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0285.html
Reference: BID:1970
Reference: URL:http://www.securityfocus.com/bid/1970

Description:
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:ewave-jsp-source-read(5562)


CAN-2000-1116

Phase: Proposed (20001219)
Reference: WIN2KSEC:20001018 TransSoft's Broker FTP Server 3.x & 4.x Remote DoS attack Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0041.html
Reference: XF:broker-ftp-username-dos
Reference: URL:http://xforce.iss.net/static/5388.php

Description:
Buffer overflow in TransSoft Broker FTP Server before 4.3.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long command.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:broker-user-dos(3482)


CAN-2000-1117

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001124 Security Hole in ECL Feature of Java VM Embedded in Lotus Notes Client R5
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0341.html
Reference: BID:1994
Reference: URL:http://www.securityfocus.com/bid/1994

Description:
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:lotus-notes-verify-files(5565)


CAN-2000-1118

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001127 24Link Webserver
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0369.html

Description:
24Link 1.06 web server allows remote attackers to bypass access restrictions by prepending strings such as "/+/" or "/." to the HTTP GET request.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:24link-bypass-authentication(5930)


CAN-2000-1125

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001104 Redhat 6.2 restore exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97336034309944&w=2
Reference: BID:1914
Reference: URL:http://www.securityfocus.com/bid/1914

Description:
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:restore-rsh-executable(5483)


CAN-2000-1126

Phase: Proposed (20001219)
Reference: HP:HPSBUX0011-130
Reference: URL:http://www.securityfocus.com/advisories/2850
Reference: BID:1954
Reference: URL:http://www.securityfocus.com/bid/1954

Description:
Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:hpux-autoparms-execute-commands(5961)


CAN-2000-1127

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001108 HP-UX 10.20 resource monitor service
Reference: URL:http://www.securityfocus.com/archive/1/143845
Reference: BID:1919
Reference: URL:http://www.securityfocus.com/bid/1919

Description:
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the original registrar.log log file and creating a symbolic link to the target file, to which registrar appends log information and sets the permissions to be world readable.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:hp-registrar-file-read(5485)


CAN-2000-1128

Phase: Proposed (20001219)
Reference: NTBUGTRAQ:20001103 Elevation of Privileges Exploit with McAfee VirusScan 4.5
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0073.html
Reference: BID:1920
Reference: URL:http://www.securityfocus.com/bid/1920

Description:
The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:nai-virusscan-unquoted-imagepath(5484)


CAN-2000-1129

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001123 McAfee WebShield SMTP vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html
Reference: BID:1999
Reference: URL:http://www.securityfocus.com/bid/1999

Description:
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:webshield-smtp-recpt-dos(5572)


CAN-2000-1130

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001123 McAfee WebShield SMTP vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0324.html
Reference: BID:1993
Reference: URL:http://www.securityfocus.com/bid/1993

Description:
McAfee WebShield SMTP 4.5 allows remote attackers to bypass email content filtering rules by including Extended ASCII characters in name of the attachment.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(2) Cole, Christey
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:webshield-smtp-filter-bypass(5571)
 Christey> Fix typo: "in name"


CAN-2000-1133

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001106 Authentix Security Advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97353881829760&w=2
Reference: BUGTRAQ:20001107 Explanation Authentix Input Validation Error
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97362374200478&w=2
Reference: BID:1907
Reference: URL:http://www.securityfocus.com/bid/1907

Description:
Authentix Authentix100 allows remote attackers to bypass authentication by inserting a . (dot) into the URL for a protected directory.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:flicks-authentix-url-info(5477)


CAN-2000-1134

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001028 tcsh: unsafe tempfile in << redirects
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-10/0418.html
Reference: BUGTRAQ:20001130 [ADV/EXP]: RH6.x root from bash /tmp vuln + MORE
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97561816504170&w=2
Reference: BUGTRAQ:20001128 /bin/sh creates insecure tmp files
Reference: URL:http://www.securityfocus.com/archive/1/146657
Reference: DEBIAN:20001111 tcsh: local exploit
Reference: URL:http://www.debian.org/security/2000/20001111a
Reference: MANDRAKE:MDKSA-2000-069
Reference: URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-069.php3
Reference: FREEBSD:FreeBSD-SA-00:76
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:76.tcsh-csh.asc
Reference: CONECTIVA:CLSA-2000:354
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000354
Reference: CALDERA:CSSA-2000-043.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-043.0.txt
Reference: CALDERA:CSSA-2000-042.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2000-042.0.txt
Reference: REDHAT:RHSA-2000:117
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-117.html
Reference: REDHAT:RHSA-2000:121
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-121.html
Reference: MANDRAKE:MDKSA-2000:075
Reference: URL:http://www.linux-mandrake.com/en/security/MDKSA-2000-075.php3
Reference: BID:1926
Reference: URL:http://www.securityfocus.com/bid/1926
Reference: BID:2006
Reference: URL:http://www.securityfocus.com/bid/2006
Reference: CONECTIVA:CLA-2000:350
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000350

Description:
tcsh, csh, sh, and bash on various Unix systems follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:linux-bash-tmp-symlink(5593)
 Christey> Don't all these shell programs originate from the same
   codebase, including ksh?  If so, we should have a single CAN
   for all of these, and add:
   XF:ksh-redirection-symlink
   URL:http://xforce.iss.net/static/5811.php
   CONECTIVA:CLA-2000:354
   BUGTRAQ:20001208 Immunix OS Security update for tcsh
   http://archives.neohapsis.com/archives/linux/immunix/2000-q4/0041.html
   BUGTRAQ:20001220 /bin/ksh creates insecure tmp files
   http://archives.neohapsis.com/archives/bugtraq/2000-12/0368.html
   BUGTRAQ:20001227 IBM Findings: Korn Shell Redirection Race Condition Vulnerability
   http://archives.neohapsis.com/archives/bugtraq/2000-12/0473.html
   
   Also see: http://archives.neohapsis.com/archives/bugtraq/2000-12/0420.html
   which gives some shell history which may be of use.
 Christey> ADDREF FREEBSD:FreeBSD-SA-01:03 for the bash problem.
 Christey> Consider adding BID:2148 if this CAN should include ksh
 Christey> SGI:20011103-01-I
   URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-01-I
   Also, DELREF BID:2148 and BID:1926.  Keep BID:2006
 Christey> COMPAQ:SSRT1-41U
   URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0742U-59U.shtml
   CERT-VN:VU#10277
   URL:http://www.kb.cert.org/vuls/id/10277
 Christey> SGI:20011103-02-P
   URL:ftp://patches.sgi.com/support/free/security/advisories/20011103-02-P
   Note that this is an update of the other SGI reference.
 Christey> CALDERA:CSSA-2001-SCO.24
   URL:ftp://stage.caldera.com/pub/security/openserver/CSSA-2001-SCO.24.1/CSSA-2001-SCO.24.1.txt
   CERT-VN:VU#10277
   URL:http://www.kb.cert.org/vuls/id/10277
 Christey> Missing BID - BID:1926


CAN-2000-1138

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001108 Lotus Notes R5 clients - no warning for broken signature or encryption
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97370725220953&w=2
Reference: BID:1925
Reference: URL:http://www.securityfocus.com/bid/1925

Description:
Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:lotus-notes-r5-mime(5492)


CAN-2000-1147

Phase: Modified (20010116-01)
Reference: BUGTRAQ:20001103 IIS ASP $19.95 hack - IISHack 1.5
Reference: URL:http://www.securityfocus.com/archive/1/143070
Reference: BID:1911
Reference: URL:http://www.securityfocus.com/bid/1911
Reference: XF:iis-isapi-asp-bo
Reference: URL:http://xforce.iss.net/static/5510.php

Description:
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to the "LANGUAGE" argument in a script tag.

Votes:

   ACCEPT(2) Baker, Wall
   MODIFY(1) Frech
   NOOP(1) Cole
   RECAST(1) LeBlanc
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:iis-isapi-asp-bo(5510)
 Christey> Consult Microsoft on this one.
 LeBlanc> This one was already fixed in several hotfixes when it was
   found. I'm not sure what the content decision is on this. It is a valid
   problem, but it was already fixed when announced. I will go along with
   an accept vote once it is modified to show fixes.


CAN-2000-1150

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001113 beos vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html

Description:
Felix IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:felix-irc-long-url(5520)


CAN-2000-1151

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001113 beos vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html

Description:
Baxter IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:baxter-irc-bo(5518)


CAN-2000-1152

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001113 beos vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html

Description:
Browser IRC client in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:bowser-irc-dos(5964)


CAN-2000-1153

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001113 beos vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html

Description:
PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:postmaster-long-url-bo(5522)


CAN-2000-1154

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001113 beos vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html

Description:
RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:robinhood-cpp-request-bo(5521)


CAN-2000-1155

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001113 beos vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0203.html

Description:
RHDaemon in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service via long HTTP request.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:robinhood-cpp-request-bo(5521)


CAN-2000-1156

Phase: Modified (20010116-01)
Reference: BUGTRAQ:20001108 StarOffice 5.2 Temporary Dir Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0115.html
Reference: BID:1922
Reference: URL:http://www.securityfocus.com/bid/1922
Reference: XF:staroffice-tmp-sym-link
Reference: URL:http://xforce.iss.net/static/5487.php

Description:
StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directory, which allows a local user to read files of the user who is using StarOffice.

Votes:

   ACCEPT(3) Baker, Cole, Dik
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:staroffice-tmp-sym-link(5487)
 Christey> Consult Sun on this one.
 Dik> Supposedly fixed in Soffice 5.1 Service pack 1


CAN-2000-1157

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html
Reference: BID:1901
Reference: URL:http://www.securityfocus.com/bid/1901

Description:
Buffer overflow in NAI Sniffer Agent allows remote attackers to execute arbitrary commands via a long SNMP community name.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:sniffer-agent-snmp-bo(5455)


CAN-2000-1158

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html

Description:
NAI Sniffer Agent uses base64 encoding for authentication, which allows attackers to sniff the network and easily decrypt usernames and passwords.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:sniffer-agent-weak-authentication(5951)


CAN-2000-1159

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html
Reference: BID:1902
Reference: URL:http://www.securityfocus.com/bid/1902

Description:
NAI Sniffer Agent allows remote attackers to gain privileges on the agent by sniffing the initial UDP authentication packets and spoofing commands.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:sniffer-agent-snmp-bo(5455)
 Christey> Consult NAI on this one.


CAN-2000-1160

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001102 Remotely exploitable buffer overflow in NAI's Distributed Sniffer Agent
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0038.html
Reference: BID:1903
Reference: URL:http://www.securityfocus.com/bid/1903

Description:
NAI Sniffer Agent allows remote attackers to cause a denial of service (crash) by sending a large number of login requests.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:sniffer-agent-login-dos(5456)
 Christey> Consult NAI on this one.


CAN-2000-1161

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001120 security problem in AdCycle installation
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0271.html
Reference: BID:1969
Reference: URL:http://www.securityfocus.com/bid/1969

Description:
The installation of AdCycle banner management system leaves the build.cgi program in a web-accessible directory, which allows remote attackers to execute the program and view passwords or delete databases.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:adcycle-password-disclosure(5559)


CAN-2000-1168

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001123 IBM HTTP Server 1.3.6 Remote Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97502498610979&w=2
Reference: BID:1988
Reference: URL:http://www.securityfocus.com/bid/1988

Description:
IBM HTTP Server 1.3.6 (based on Apache) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long GET request.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:ibm-http-server-dos(5577)
 Christey> Consult Troy Bollinger on this one.


CAN-2000-1172

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001110 Advisory: Gaim remote vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0204.html
Reference: BID:1948
Reference: URL:http://www.securityfocus.com/bid/1948

Description:
Buffer overflow in Gaim 0.10.3 and earlier using the OSCAR protocol allows remote attackers to conduct a denial of service and possibly execute arbitrary commands via a long HTML tag.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:gaim-remote-bo(5511)


CAN-2000-1173

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001122 CyberPatrol - poor credit card protection
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0323.html
Reference: BID:1977
Reference: URL:http://www.securityfocus.com/bid/1977

Description:
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the remainder of the information during registration, which could allow attackers to sniff network traffic and obtain this sensitive information.

Votes:

   ACCEPT(2) Baker, Cole
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:cyberpatrol-insecure-data(5578)


CAN-2000-1175

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001120 local exploit for linux's Koules1.4 package
Reference: URL:http://www.securityfocus.com/archive/1/145823
Reference: BID:1967
Reference: URL:http://www.securityfocus.com/bid/1967

Description:
Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:koules-svgalib-bo(5558)


CAN-2000-1176

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001107 Insecure input balidation in YaBB Search.pl
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0110.html
Reference: BID:1921
Reference: URL:http://www.securityfocus.com/bid/1921

Description:
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a .. (dot dot) attack in the "catsearch" form field.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:yabb-search-format-string(5501)


CAN-2000-1177

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001121 Big Brother Advisory - Fate Research Labs
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0284.html
Reference: CONFIRM:http://bb4.com/incident.nov21
Reference: BID:1971
Reference: URL:http://www.securityfocus.com/bid/1971

Description:
bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows remote attackers to determine the existence of files and user ID's by specifying the target file in the HISTFILE parameter.

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:bb-cgi-brute-force(5560)


CAN-2000-1183

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001115 socks5 remote exploit / linux x86
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0219.html

Description:
Buffer overflow in socks5 server on Linux allows attackers to execute arbitrary commands via a long connection request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:linux-socks5-connection-bo(8376)


CAN-2000-1185

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001113 Rideway PN Telnet DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0201.html
Reference: BID:1938
Reference: URL:http://www.securityfocus.com/bid/1938

Description:
The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:rideway-pn-proxy-dos(5525)


CAN-2000-1186

Phase: Modified (20010122-01)
Reference: BUGTRAQ:20001115 Exploit: phf buffer overflow (CGI)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0221.html
Reference: XF:phf-cgi-bo(5970)
Reference: URL:http://xforce.iss.net/static/5970.php

Description:
Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:phf-cgi-bo(5970)


CAN-2000-1188

Phase: Proposed (20001219)
Reference: BUGTRAQ:20001120 Cgisecurity Quickstore Shopping cart
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-11/0283.html

Description:
Directory traversal vulnerability in Quikstore shopping cart program allows rmeote attackers to read arbitrary files via a .. (dot dot) attack in the "page" parameter.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:quikstore-cgi-read-files(5561)
 Armstrong> in Description: change rmeote to remote.


CAN-2000-1191

Phase: Proposed (20010912)
Reference: MISC:http://www.securiteam.com/exploits/htDig_reveals_web_server_configuration_paths.html

Description:
htsearch program in htDig 3.2 beta, 3.1.5, and earlier allows remote attackers to determine the physical path of the server by requesting a non-existent configuration file using the config parameter, which generates an error message that includes the full path.

Votes:

   ACCEPT(1) Stracener
   MODIFY(1) Frech
   NOOP(4) Williams, Wall, Foat, Cole
Voter Comments:
 Frech> XF:htdig-htsearch-path-disclosure(7367)
   MISC reference should be
   http://www.securiteam.com/exploits/5YQ0C000IU.html.


CAN-2000-1192

Phase: Proposed (20010912)
Reference: MISC:http://www.securiteam.com/windowsntfocus/5ZP0C000KC.html
Reference: MISC:http://www.bttsoftware.co.uk/snmptrap.html
Reference: XF:snmp-trapwatcher-string-dos
Reference: BID:985
Reference: URL:http://www.securityfocus.com/bid/985

Description:
Buffer overflow in BTT Software SNMP Trap Watcher 1.16 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string trap.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Williams, Wall, Foat, Cole, Stracener

CAN-2000-1194

Phase: Proposed (20010912)
Reference: MISC:http://www.mdma.za.net/fk/FK9.zip
Reference: BID:1227
Reference: URL:http://www.securityfocus.com/bid/1227

Description:
Argosoft FRP server 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to the (1) USER or (2) CWD commands.

Votes:

   ACCEPT(1) Williams
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Stracener
Voter Comments:
 Frech> XF:argosoft-ftp-bo(6553)
 Williams> %s/FRP/FTP
 CHANGE> [Williams changed vote from MODIFY to ACCEPT]


CAN-2000-1197

Phase: Proposed (20010912)
Reference: BUGTRAQ:20000420 pop3d/imap DOS (while we're on the subject)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95624629924545&w=2
Reference: FREEBSD:FreeBSD-SA-00:15
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:15.imap-uw.asc
Reference: BID:1132
Reference: URL:http://www.securityfocus.com/bid/1132

Description:
POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.

Votes:

   ACCEPT(4) Baker, Foat, Cole, Stracener
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Foat> ACKNOWLEDGED-BY-VENDOR
 Frech> XF:freebsd-imap-uw(4335)
 Frech> Please change XF:freebsd-imap-uw(4335) to XF:pop-predictable-lockfile(4335)


CAN-2000-1198

Phase: Proposed (20010912)
Reference: BUGTRAQ:20000420 pop3
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95634229925906&w=2
Reference: BUGTRAQ:20000420 pop3d/imap DOS (while we're on the subject)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95624629924545&w=2
Reference: BID:1132
Reference: URL:http://www.securityfocus.com/bid/1132

Description:
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.

Votes:

   ACCEPT(3) Baker, Cole, Stracener
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:pop-predictable-lockfile(4335)


CAN-2000-1199

Phase: Proposed (20010912)
Reference: BUGTRAQ:20000423 Postgresql cleartext password storage
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=95659987018649&w=2
Reference: XF:postgresql-plaintext-passwords(4364)
Reference: URL:http://xforce.iss.net/static/4364.php
Reference: BID:1139
Reference: URL:http://www.securityfocus.com/bid/1139

Description:
PostgreSQL stores usernames and passwords in plaintext in (1) pg_shadow and (2) pg_pwd, which allows attackers with sufficient privileges to gain access to databases.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Williams, Wall, Foat, Cole, Stracener

CAN-2000-1201

Phase: Proposed (20010912)
Reference: BUGTRAQ:20000707 Re: CheckPoint FW1 BUG
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-07/0085.html

Description:
Check Point FireWall-1 allows remote attackers to cause a denial of service (high CPU) via a flood of packets to port 264.

Votes:

   MODIFY(1) Frech
   NOOP(5) Williams, Wall, Foat, Cole, Stracener
Voter Comments:
 Frech> XF:fw1-portflood-dos(7368)


CAN-2000-1202

Phase: Proposed (20010912)
Reference: BUGTRAQ:20000405 minor issue with IBM HTTPD and /usr/bin/ikeyman
Reference: URL:http://www.securityfocus.com/archive/1/54073
Reference: BID:1092
Reference: URL:http://www.securityfocus.com/bid/1092
Reference: XF:ibm-ikeyman(4235)
Reference: URL:http://xforce.iss.net/static/4235.php

Description:
ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.

Votes:

   ACCEPT(2) Frech, Williams
   NOOP(4) Wall, Foat, Cole, Stracener
Voter Comments:
 Williams> :%s/IBMHSSSB/IBMHSSB


CAN-2000-1203

Phase: Modified (20030325-01)
Reference: VULN-DEV:20000520 Infinite loop in LOTUS NOTE 5.0.3. SMTP SERVER
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=95886062521327&w=2
Reference: BUGTRAQ:20010820 Lotus Domino DoS
Reference: URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-01-21&end=2002-01-27&mid=209116&threads=1
Reference: BUGTRAQ:20010823 Lotus Domino DoS solution
Reference: URL:http://www.securityfocus.com/archive/1/209754
Reference: BID:3212
Reference: URL:http://www.securityfocus.com/bid/3212
Reference: XF:lotus-domino-bounced-message-dos(7012)
Reference: URL:http://www.iss.net/security_center/static/7012.php

Description:
Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.

Votes:

   ACCEPT(3) Baker, Armstrong, Green
   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Christey
Voter Comments:
 Green> Since a work around involving configuration settings exists the presenting problem should also exist.
 Frech> XF:lotus-domino-bounced-message-dos(7012)
   CONFIRM:
   http://www-1.ibm.com/support/docview.wss?rs=0&org=sims&doc=DA18AA221C3
   B982085256B84000033EB
 Christey> The CONFIRM URL provided by Andre is broken


CAN-2000-1204

Phase: Proposed (20020830)
Reference: CONFIRM:http://www.apacheweek.com/issues/00-10-13

Description:
Vulnerability in the mod_vhost_alias virtual hosting module for Apache 1.3.9, 1.3.11 and 1.3.12 allows remote attackers to obtain the source code for CGI programs if the cgi-bin directory is under the document root.

Votes:

   ACCEPT(5) Baker, Cox, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:apache-modvhostalias-source-disclosure(11088)


CAN-2000-1205

Phase: Proposed (20020830)
Reference: CONFIRM:http://httpd.apache.org/info/css-security/apache_specific.html

Description:
Cross site scripting vulnerabilities in Apache 1.3.0 through 1.3.11 allow remote attackers to execute script as other web site visitors via (1) the printenv CGI, which does not encode its output, (2) pages generated by the ap_send_error_response function such as a default 404, which does not add an explicit charset, or (3) various messages that are generated by certain Apache modules or core code.

Votes:

   ACCEPT(7) Baker, Cox, Wall, Foat, Cole, Armstrong, Green
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:apache-printenv-xss(10938)


CAN-2000-1206

Phase: Proposed (20020830)
Reference: CONFIRM:http://www.apacheweek.com/issues/00-01-07#status

Description:
Vulnerability in Apache httpd before 1.3.11, when configured for mass virtual hosting using mod_rewrite, or mod_vhost_alias in Apache 1.3.9, allows remote attackers to retrieve arbitrary files.

Votes:

   ACCEPT(6) Baker, Cox, Wall, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:apache-virtualhosting-obtain-files(11139)


CAN-2000-1207

Phase: Proposed (20020830)
Reference: BUGTRAQ:20000930 glibc and userhelper - local root
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97034397026473&w=2
Reference: REDHAT:RHSA-2000:075
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-075.html
Reference: MANDRAKE:MDKSA-2000:059
Reference: URL:http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-059.php3
Reference: BUGTRAQ:20001003 SuSE: userhelper/usermode
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97063854808796&w=2

Description:
userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844).

Votes:

   ACCEPT(6) Baker, Cox, Wall, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:usermode-userhelper-bypass-security(11089)


CAN-2000-1208

Phase: Proposed (20020830)
Reference: BUGTRAQ:20000925 Format strings: bug #1: BSD-lpr
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96994604300675&w=2
Reference: REDHAT:RHSA-2000:066
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-066.html
Reference: MANDRAKE:MDKSA-2000:054
Reference: CONECTIVA:CLSA-2000:321
Reference: BUGTRAQ:20001004 Immunix OS Security Update for lpr
Reference: URL:http://online.securityfocus.com/archive/1/137555
Reference: XF:lpr-checkremote-format-string(5286)
Reference: URL:http://www.iss.net/security_center/static/5286.php
Reference: BID:1711
Reference: URL:http://online.securityfocus.com/bid/1711

Description:
Format string vulnerability in startprinting() function of printjob.c in BSD-based lpr lpd package may allow local users to gain privileges via an improper syslog call that uses format strings from the checkremote() call.

Votes:

   ACCEPT(6) Baker, Frech, Cox, Cole, Armstrong, Green
   NOOP(2) Wall, Foat

CAN-2000-1209

Phase: Proposed (20020830)
Reference: BUGTRAQ:20000710 MSDE / Re: Default Password Database
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96333895000350&w=2
Reference: BUGTRAQ:20000810 Tumbleweed Worldsecure (MMS) BLANK 'sa' account password
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96593218804850&w=2
Reference: BUGTRAQ:20000815 MS-SQL 'sa' user exploit code
Reference: URL:http://security-archive.merton.ox.ac.uk/bugtraq-200008/0233.html
Reference: BUGTRAQ:20000816 Released Patch: Tumbleweed Worldsecure (MMS) BLANK 'sa' account password
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=96644570412692&w=2
Reference: BUGTRAQ:20020522 Opty-Way Enterprise includes MSDE with sa <blank>
Reference: URL:http://online.securityfocus.com/archive/1/273639
Reference: MSKB:Q313418
Reference: URL:http://support.microsoft.com/default.aspx?scid=kb;[LN];Q313418
Reference: MSKB:Q321081
Reference: URL:http://support.microsoft.com/default.aspx?scid=kb;EN-US;q321081
Reference: CONFIRM:http://www.microsoft.com/security/security_bulletins/ms02020_sql.asp
Reference: ISS:20020521 Microsoft SQL Spida Worm Propagation
Reference: CERT-VN:VU#635463
Reference: URL:http://www.kb.cert.org/vuls/id/635463
Reference: COMPAQ:SSRT2195
Reference: BID:4797
Reference: URL:http://online.securityfocus.com/bid/4797
Reference: XF:mssql-no-sapassword(1459)
Reference: URL:http://www.iss.net/security_center/static/1459.php

Description:
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight Manager, and (6) Visio 2000, are installed with a default "sa" account with a null password, which allows remote attackers to gain privileges, including worms such as Voyager Alpha Force and Spida.

Votes:

   ACCEPT(5) Baker, Wall, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(2) Cox, Foat
Voter Comments:
 Frech> XF:tumbleweed-mms-blank-password(5072)
   XF:msde-mssql-default-password(9154)
   May overlap with CAN-2000-0772.


CAN-2000-1213

Phase: Proposed (20020830)
Reference: BUGTRAQ:20001025 Immunix OS Security Update for ping package
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97249980727834&w=2
Reference: BUGTRAQ:20001030 Trustix Security Advisory - ping gnupg ypbind
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97292944103571&w=2
Reference: REDHAT:RHSA-2000:087
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-087.html

Description:
ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.

Votes:

   ACCEPT(7) Baker, Cox, Wall, Foat, Cole, Armstrong, Green
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:iputils-ping-privileges(11090)


CAN-2000-1214

Phase: Proposed (20020830)
Reference: BUGTRAQ:20001025 Immunix OS Security Update for ping package
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97249980727834&w=2
Reference: BUGTRAQ:20001020 Re: [RHSA-2000:087-02] Potential security problems in ping fixed.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97208562830613&w=2
Reference: BUGTRAQ:20001030 Trustix Security Advisory - ping gnupg ypbind
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97292944103571&w=2
Reference: REDHAT:RHSA-2000:087
Reference: URL:http://www.redhat.com/support/errata/RHSA-2000-087.html
Reference: BID:1813
Reference: URL:http://online.securityfocus.com/bid/1813
Reference: XF:ping-buf-bo(5431)
Reference: URL:http://www.iss.net/security_center/static/5431.php

Description:
Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.

Votes:

   ACCEPT(8) Baker, Frech, Cox, Wall, Foat, Cole, Armstrong, Green

CAN-2001-0019

Phase: Proposed (20010202)
Reference: ATSTAKE:A013101-1
Reference: URL:http://www.atstake.com/research/advisories/2001/a013101-1.txt
Reference: CISCO:20010131 Cisco Content Services Switch Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml

Description:
Arrowpoint (aka Cisco Content Services, or CSS) allows local users to cause a denial of service via a long argument to the "show script," "clear script," "show archive," "clear archive," "show log," or "clear log" commands.

Votes:

   ACCEPT(4) Cole, Prosser, Baker, Ziese
   MODIFY(1) Frech
   NOOP(2) Christey, Wall
Voter Comments:
 Frech> XF:cisco-ccs-cli-dos(6030)
   I could not find anything in the Cisco reference that
   indicates that this is a local-only vulnerability. Suggest dropping
   the description of "local users" unless further information is
   available.
 Christey> XF:cisco-ccs-cli-dos
 Christey> BID:2330
   URL:http://www.securityfocus.com/bid/2330
 Prosser> CISCO:20010131 Cisco Content Services Switch Vulnerability
   http://www.cisco.com/warp/public/707/arrowpoint-cli-filesystem-pub.shtml


CAN-2001-0022

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001213 Re: Insecure input validation in simplestmail.cgi
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0168.html
Reference: BID:2106
Reference: URL:http://www.securityfocus.com/bid/2106
Reference: XF:http-cgi-simplestguest
Reference: URL:http://xforce.iss.net/static/5743.php

Description:
simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the guestbook parameter.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0023

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001211 Insecure input validation in everythingform.cgi (remote command execution)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0137.html
Reference: BID:2101
Reference: URL:http://www.securityfocus.com/bid/2101
Reference: XF:http-cgi-everythingform
Reference: URL:http://xforce.iss.net/static/5736.php

Description:
everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the config parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0024

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001211 Insecure input validation in simplestmail.cgi (remote command execution)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0136.html
Reference: BID:2102
Reference: URL:http://www.securityfocus.com/bid/2102
Reference: XF:http-cgi-simplestmail
Reference: URL:http://xforce.iss.net/static/5739.php

Description:
simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the MyEmail parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0025

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001211 Insecure input validation in ad.cgi
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0143.html
Reference: BID:2103
Reference: URL:http://www.securityfocus.com/bid/2103
Reference: XF:http-cgi-ad
Reference: URL:http://xforce.iss.net/static/5741.php

Description:
ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0027

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001211 mod_sqlpw Password Caching Bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0139.html
Reference: XF:proftpd-modsqlpw-unauth-access
Reference: URL:http://xforce.iss.net/static/5737.php

Description:
mod_sqlpw module in ProFTPD does not reset a cached password when a user uses the "user" command to change accounts, which allows authenticated attackers to gain privileges of other users.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0029

Phase: Modified (20020222-01)
Reference: BUGTRAQ:20001212 Stack too ;) Re: [pkc] remote heap buffer overflow in oops
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0158.html
Reference: BID:2099
Reference: URL:http://www.securityfocus.com/bid/2099
Reference: MISC:http://zipper.paco.net/~igor/oops/ChangeLog
Reference: XF:oops-dns-bo(6122)
Reference: URL:http://xforce.iss.net/static/6122.php

Description:
Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(3) Christey, Ziese, Wall
Voter Comments:
 Frech> XF:oops-dns-bo(6122)
 Christey> This looks like a different overflow than the one described
   in the original post at:
   http://archives.neohapsis.com/archives/bugtraq/2000-12/0127.html
   The vendor does acknowledge *that* problem in the 1.5.0
   comments of
   http://zipper.paco.net/~igor/oops/ChangeLog
 Christey> Vendor fixed this problem between 1.4.22 and 1.5.5, based
   on a source code comparison.
   CD:SF-LOC says that bugs of the same type, that appear in
   different versions, must be SPLIT.  Therefore this should
   stay separate from CVE-2001-0028.
   
   Change MISC to CONFIRM.  The comments for version 1.5.4
   say "more sprintf/strncpy fixes" and that's the type of
   changes that were made in lib.c, the code that was listed
   in the Bugtraq post for this CAN.


CAN-2001-0030

Phase: Proposed (20010202)
Reference: BID:2089
Reference: URL:http://www.securityfocus.com/bid/2089
Reference: XF:foolproof-security-bypass
Reference: URL:http://xforce.iss.net/static/5758.php

Description:
FoolProof 3.9 allows local users to bypass program execution restrictions by downloading the restricted executables from another source and renaming them.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Cole, Christey, Ziese, Wall
Voter Comments:
 Christey> ADDREF BUGTRAQ:20001208 Foolproof Security Vulnerability
   http://www.securityfocus.com/archive/1/149952


CAN-2001-0031

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001207 BroadVision One-To-One Enterprise Path Disclosure Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0074.html
Reference: XF:broadvision-bv1to1-reveal-path
Reference: URL:http://xforce.iss.net/static/5661.php

Description:
BroadVision One-To-One Enterprise allows remote attackers to determine the physical path of server files by requesting a .JSP file name that does not exist.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0032

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001208 format string in ssl dump
Reference: URL:http://www.securityfocus.com/archive/1/149917
Reference: BID:2096
Reference: URL:http://www.securityfocus.com/bid/2096
Reference: XF:ssldump-format-strings
Reference: URL:http://xforce.iss.net/static/5717.php

Description:
Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain root privileges via malicious format string specifiers in a URL.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0037

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001207 HomeSeer Directory Traversal Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0082.html
Reference: BID:2085
Reference: URL:http://www.securityfocus.com/bid/2085
Reference: MISC:http://www.keware.com/hsbetachanges.htm
Reference: XF:homeseer-directory-traversal
Reference: URL:http://xforce.iss.net/static/5663.php

Description:
Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL containing .. (dot dot) specifiers.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0038

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001207 MetaProducts Offline Explorer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0078.html
Reference: BID:2084
Reference: URL:http://www.securityfocus.com/bid/2084
Reference: XF:offline-explorer-reveal-files
Reference: URL:http://xforce.iss.net/static/5728.php

Description:
Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive letter (e.g. C:) in the requested URL.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0042

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001206 CHINANSL Security Advisory(CSA-200011)
Reference: URL:http://www.securityfocus.com/archive/1/149210
Reference: BID:2060
Reference: URL:http://www.securityfocus.com/bid/2060
Reference: XF:apache-php-disclose-files
Reference: URL:http://xforce.iss.net/static/5659.php

Description:
PHP3 running on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack.

Votes:

   ACCEPT(3) Cole, Baker, Frech
   NOOP(1) Wall
   REVIEWING(1) Ziese

CAN-2001-0044

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001206 (SRADV00007) Local root compromise through Lexmark MarkVision printer drivers
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0064.html
Reference: BID:2075
Reference: URL:http://www.securityfocus.com/bid/2075
Reference: XF:markvision-printer-driver-bo
Reference: URL:http://xforce.iss.net/static/5651.php

Description:
Multiple buffer overflows in Lexmark MarkVision printer driver programs allows local users to gain privileges via long arguments to the cat_network, cat_paraller, and cat_serial commands.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0045

Phase: Proposed (20010202)
Reference: MS:MS00-095
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-095.asp
Reference: BID:2064
Reference: URL:http://www.securityfocus.com/bid/2064
Reference: XF:nt-ras-reg-perms
Reference: URL:http://xforce.iss.net/static/5671.php

Description:
The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.

Votes:

   ACCEPT(5) Cole, Baker, Frech, Ziese, Wall

CAN-2001-0046

Phase: Proposed (20010202)
Reference: MS:MS00-095
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-095.asp
Reference: BID:2066
Reference: URL:http://www.securityfocus.com/bid/2066
Reference: XF:nt-snmp-reg-perms
Reference: URL:http://xforce.iss.net/static/5672.php

Description:
The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.

Votes:

   ACCEPT(4) Cole, Baker, Frech, Wall
   NOOP(1) Ziese

CAN-2001-0047

Phase: Proposed (20010202)
Reference: MS:MS00-095
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-095.asp
Reference: BID:2065
Reference: URL:http://www.securityfocus.com/bid/2065
Reference: XF:nt-mts-reg-perms
Reference: URL:http://xforce.iss.net/static/5673.php

Description:
The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.

Votes:

   ACCEPT(4) Cole, Baker, Frech, Wall
   NOOP(1) Ziese

CAN-2001-0048

Phase: Proposed (20010202)
Reference: MS:MS00-099
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS00-099.asp
Reference: BID:2133
Reference: URL:http://www.securityfocus.com/bid/2133

Description:
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.

Votes:

   ACCEPT(4) Cole, Baker, Ziese, Wall
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:win2k-directory-service-restore-password(5936)


CAN-2001-0049

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001207 WatchGuard SOHO v2.2.1 DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0079.html
Reference: BID:2082
Reference: URL:http://www.securityfocus.com/bid/2082
Reference: XF:watchguard-soho-get-dos
Reference: URL:http://xforce.iss.net/static/5665.php

Description:
WatchGuard SOHO FireWall 2.2.1 and earlier allows remote attackers to cause a denial of service via a large number of GET requests.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(2) Cole, Wall
   REVIEWING(1) Ziese

CAN-2001-0051

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001205 IBM DB2 default account and password Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/149222
Reference: BID:2068
Reference: URL:http://www.securityfocus.com/bid/2068
Reference: XF:ibm-db2-gain-access
Reference: URL:http://xforce.iss.net/static/5662.php

Description:
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote attackers to gain access to the databasse.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> In description, "database", not "databasse".


CAN-2001-0052

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001205 IBM DB2 SQL DOS
Reference: URL:http://www.securityfocus.com/archive/1/149207
Reference: BID:2067
Reference: URL:http://www.securityfocus.com/bid/2067
Reference: XF:ibm-db2-dos
Reference: URL:http://xforce.iss.net/static/5664.php

Description:
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0064

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001219 def-2000-03: MDaemon 3.5.0 DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0315.html
Reference: BID:2134
Reference: URL:http://www.securityfocus.com/bid/2134

Description:
Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> XF:mdaemon-imap-dos(5805)


CAN-2001-0065

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001213 Potential Buffer Overflow vulnerability in bftpd-1.0.13
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0189.html
Reference: XF:bftpd-site-chown-bo
Reference: URL:http://xforce.iss.net/static/5775.php

Description:
Buffer overflow in bftpd 1.0.13 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long SITE CHOWN command.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0067

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001214 J-Pilot Permissions Vulnerability
Reference: URL:http://www.securityfocus.com/templates/archive.pike?mid=150957&end=2001-02-03&fromthread=1&start=2001-01-28&threads=0&list=1&
Reference: MANDRAKE:MDKSA-2000:081
Reference: URL:http://www.linux-mandrake.com/en/security/2000/MDKSA-2000-081.php3
Reference: XF:jpilot-perms
Reference: URL:http://xforce.iss.net/static/5762.php

Description:
The installation of J-Pilot creates the .jpilot directory with the user's umask, which could allow local attackers to read other users' PalmOS backup information if their umasks are not securely set.

Votes:

   ACCEPT(3) Cole, Baker, Frech
   NOOP(2) Ziese, Wall

CAN-2001-0068

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001215 Security Hole of MRJ 2.2.3 (Mac OS Runtime for Java) - Inconsistent Use of CODEBASE and ARCHIVE Attributes -
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0241.html
Reference: XF:mrj-runtime-malicious-applets
Reference: URL:http://xforce.iss.net/static/5784.php

Description:
Mac OS Runtime for Java (MRJ) 2.2.3 allows remote attackers to use malicious applets to read files outside of the CODEBASE context via the ARCHIVE applet parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0070

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001226 1st Up Mail Server v4.1 Buffer Overflow Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0143.html
Reference: BID:2152
Reference: URL:http://www.securityfocus.com/bid/2152
Reference: XF:1stup-mail-server-bo
Reference: URL:http://xforce.iss.net/static/5808.php

Description:
Buffer overflow in 1st Up Mail Server 4.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long MAIL FROM command.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0073

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001226 buffer overflow in libsecure (NSA Security-enhanced Linux)
Reference: URL:http://www.securityfocus.com/archive/1/153188
Reference: BID:2154
Reference: URL:http://www.securityfocus.com/bid/2154

Description:
Buffer overflow in the find_default_type function in libsecure in NSA Security-enhanced Linux, which may allow attackers to modify critical data in memory.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> slinux-libsecure-bo(5820)


CAN-2001-0074

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001223 Technote
Reference: URL:http://www.securityfocus.com/archive/1/153007
Reference: BID:2155
Reference: URL:http://www.securityfocus.com/bid/2155

Description:
Directory traversal vulnerability in print.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the board parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> XF:http-cgi-technote-print(5815)
   Contrary to current references, product is spelled TECH-NOTE
   (see http://www.technote.co.kr/)


CAN-2001-0075

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001227 [Ksecurity Advisory] main.cgi in technote
Reference: URL:http://www.securityfocus.com/archive/1/153212
Reference: BID:2156
Reference: URL:http://www.securityfocus.com/bid/2156

Description:
Directory traversal vulnerability in main.cgi in Technote allows remote attackers to read arbitrary files via a .. (dot dot) attack in the filename parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> XF:http-cgi-technote-main(5813)
   Contrary to current references, product is spelled TECH-NOTE
   (see http://www.technote.co.kr/)


CAN-2001-0076

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001228 Remote vulnerability in Ikonboard upto version 2.1.7b
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0483.html
Reference: BID:2157
Reference: URL:http://www.securityfocus.com/bid/2157
Reference: XF:http-cgi-ikonboard
Reference: URL:http://xforce.iss.net/static/5819.php

Description:
register.cgi in Ikonboard 2.1.7b and earlier allows remote attackers to execute arbitrary commands via the SEND_MAIL parameter, which overwrites an internal program variable that references a program to be executed.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0079

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001213 STM symlink Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0174.html

Description:
Support Tools Manager (STM) A.22.00 for HP-UX allows local users to overwrite arbitrary files via a symlink attack on the tool_stat.txt log file.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> XF:stm-log-files-symlink(6126)
   BID-2158


CAN-2001-0082

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001218 FireWall-1 Fastmode Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0271.html

Description:
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> XF:fw1-bypass-rules(6000)
   BID-2143


CAN-2001-0084

Phase: Proposed (20010202)
Reference: BUGTRAQ:20010102 gtk+ security hole.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0498.html
Reference: BUGTRAQ:20010103 Claimed vulnerability in GTK_MODULES
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0027.html
Reference: BID:2165
Reference: URL:http://www.securityfocus.com/bid/2165
Reference: MISC:http://www.gtk.org/setuid.html

Description:
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(5) Cole, Christey, Prosser, Ziese, Wall
Voter Comments:
 Frech> XF:gtk-module-execute-code(5832)
 Christey> XF:gtk-module-execute-code
   URL:http://xforce.iss.net/static/5832.php
 Christey> TURBO:TLSA2001026
   URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000440.html


CAN-2001-0086

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001212 Security Advisory: Subscribe Me Lite 1.0 - 2.0 Unix or 1.0 - 2.0 NT and below.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0160.html
Reference: BID:2108
Reference: URL:http://www.securityfocus.com/bid/2108
Reference: XF:subscribemelite-gain-admin-access
Reference: URL:http://xforce.iss.net/static/5735.php

Description:
CGI Script Center Subscribe Me LITE 2.0 and earlier allows remote attackers to delete arbitrary mailing list users without authentication by directly calling subscribe.pl with the target address as a parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0087

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001219 itetris[v1.6.2] local root exploit (system()+../ protection)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0295.html
Reference: BID:2139
Reference: URL:http://www.securityfocus.com/bid/2139
Reference: XF:itetris-svgalib-path
Reference: URL:http://xforce.iss.net/static/5795.php

Description:
itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which allows local users to gain root privileges by changing their PATH so that it points to a malicious gunzip program.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0088

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001202 Bypassing admin authentication in phpWebLog
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0025.html
Reference: BID:2047
Reference: URL:http://www.securityfocus.com/bid/2047
Reference: XF:phpweblog-bypass-authentication
Reference: URL:http://xforce.iss.net/static/5625.php

Description:
common.inc.php in phpWebLog 0.4.2 does not properly initialize the $CONF array, which inadvertently sets the password to a single character, allowing remote attackers to easily guess the SiteKey and gain administrative privileges to phpWebLog.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0093

Phase: Proposed (20010202)
Reference: NETBSD:NetBSD-SA2000-017
Reference: URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-017.txt.asc

Description:
Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.

Votes:

   ACCEPT(3) Cole, Baker, Ziese
   MODIFY(2) Prosser, Frech
   NOOP(1) Wall
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:kerberos4-arbitrary-proxy(9733)
   Description states FreeBSD, but advisory is for NetBSD.
 Prosser> http://www.linuxsecurity.com/advisories/netbsd_advisory-1007.html
 CHANGE> [Prosser changed vote from ACCEPT to MODIFY]
 Prosser> The operating system in this CAN should also be NetBSD vice FreeBSD, same as in 0094.  FreeBSD 3.5 STABLE and 4.2 STABLE are vulnerable as well.  See ref
   FreeBSD-SA-01:25
   http://www.linuxsecurity.com/advisories/freebsd_advisory-1153.html
   or http://www.freebsd.org/security/security.html#adv
 Christey> This description does not explicitly mention that the problem is
   in a kerberized telnet.  Need to verify that there aren't
   already other CVE's that describe this.


CAN-2001-0097

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001221 Infinite InterChange DoS
Reference: URL:http://www.securityfocus.com/archive/1/152403
Reference: BID:2140
Reference: URL:http://www.securityfocus.com/bid/2140
Reference: XF:infinite-interchange-dos
Reference: URL:http://xforce.iss.net/static/5798.php

Description:
The Web interface for Infinite Interchange 3.6.1 allows remote attackers to cause a denial of service (application crash) via a large POST request.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall
Voter Comments:
 Frech> Version is listed as 3.61 (see
   http://support.infinite.com/kb/648.asp)
   Also, vendor seems to have issued a verification (see above
   document):
   - - WebMail: Fix for an exception error triggered by a POST request
   with
   an extremely long garbage URL. (v3.61.08)


CAN-2001-0098

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001219 def-2000-04: Bea WebLogic Server dotdot-overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0331.html
Reference: BID:2138
Reference: URL:http://www.securityfocus.com/bid/2138
Reference: XF:weblogic-dot-bo
Reference: URL:http://xforce.iss.net/static/5782.php

Description:
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL that begins with a ".." string.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Cole, Ziese, Wall

CAN-2001-0101

Phase: Modified (20020222-01)
Reference: TURBO:TLSA2000024-1
Reference: URL:http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html
Reference: REDHAT:RHBA-2000:106-04
Reference: URL:http://www.redhat.com/support/errata/RHBA-2000-106.html
Reference: XF:fetchmail-authenticate-gssapi(7455)
Reference: URL:http://xforce.iss.net/static/7455.php

Description:
Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.

Votes:

   ACCEPT(4) Cole, Prosser, Baker, Ziese
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Prosser> TURBO:TLSA2000024-1
   http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:fetchmail-authenticate-gssapi(7455)


CAN-2001-0102

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001229 Mac OS 9 Multiple Users Control Panel Password Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0497.html
Reference: XF:macos-multiple-users
Reference: URL:http://xforce.iss.net/static/5830.php

Description:
"Multiple Users" Control Panel in Mac OS 9 allows Normal users to gain Owner privileges by removing the Users & Groups Data File, which effectively removes the Owner password and allows the Normal user to log in as the Owner account without a password.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
Voter Comments:
 Christey> The following post claims that Apple fixed the problem.
   However, the web page is broken, and the new page requires
   user registration.
   BUGTRAQ:20010420 [FYI] Mac OS 9 Multiple Users weakness fixed (was: Mac OS 9 Multiple Users Control Panel Password Vulnerability)
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98793967806147&w=2


CAN-2001-0103

Phase: Proposed (20010202)
Reference: BID:2107
Reference: URL:http://www.securityfocus.com/bid/2107
Reference: XF:coffeecup-ftp-weak-encryption
Reference: URL:http://xforce.iss.net/static/5744.php

Description:
CoffeeCup Direct and Free FTP clients useas weak encryption to store passwords in the FTPServers.ini file, which could allow attackers to easily decrypt the passwords.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Cole, Ziese

CAN-2001-0104

Phase: Proposed (20010202)
Reference: BUGTRAQ:20001214 Bypass MDaemon 3.5.1 "Lock Server" Protection
Reference: URL:http://www.securityfocus.com/archive/1/151156
Reference: BID:2115
Reference: URL:http://www.securityfocus.com/bid/2115
Reference: XF:mdaemon-lock-bypass-password
Reference: URL:http://xforce.iss.net/static/5763.php

Description:
MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Cole, Ziese

CAN-2001-0107

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010115 Veritas BackupExec (remote DoS)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97958921407182&w=2
Reference: BID:2204
Reference: URL:http://www.securityfocus.com/bid/2204

Description:
Veritas Backup agent on Linux allows remote attackers to cause a denial of service by establishing a connection without sending any data, which causes the process to hang.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:veritas-backupexec-dos
   URL:http://xforce.iss.net/static/5941.php
 Frech> XF:veritas-backupexec-dos(5941)
 Christey> BUGTRAQ:19990903 DOS in Backup Exec Agent
   http://marc.theaimsgroup.com/?l=bugtraq&m=93685651407299&w=2


CAN-2001-0112

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010114 [MSY] Multiple vulnerabilities in splitvt
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97958269320974&w=2
Reference: DEBIAN:DSA-014-2
Reference: URL:http://www.debian.org/security/2001/dsa-014
Reference: BID:2210
Reference: URL:http://www.securityfocus.com/bid/2210

Description:
Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:splitvt-bo(6210)


CAN-2001-0113

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010116 Vulnerabilities in OmniHTTPd default installation
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html
Reference: BID:2211
Reference: URL:http://www.securityfocus.com/bid/2211

Description:
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:omnihttpd-statsconfig-execute-code
   URL:http://xforce.iss.net/static/5956.php
 Frech> XF:omnihttpd-statsconfig-execute-code(5956)


CAN-2001-0114

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010116 Vulnerabilities in OmniHTTPd default installation
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0248.html
Reference: BID:2211
Reference: URL:http://www.securityfocus.com/bid/2211

Description:
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:omnihttpd-statsconfig-corrupt-files
   URL:http://xforce.iss.net/static/5955.php
 Frech> XF:omnihttpd-statsconfig-corrupt-files(5955)
 Christey> MISC:http://www.omnicron.ca/httpd/docs/release.html
   May be vague acknowledgement; need to ask
   mailto:support@omnicron.ca?subject=OmniHTTPd Technical Support
   (and ask them about the other OmniHTTP issues as well)


CAN-2001-0127

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010115 Flash plugin write-overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0236.html
Reference: BID:2214
Reference: URL:http://www.securityfocus.com/bid/2214

Description:
Buffer overflow in Olivier Debon Flash plugin (not the Macromedia plugin) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long DefineSound tag.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:flash-module-bo
 Frech> XF:flash-module-bo(5952)


CAN-2001-0131

Phase: Modified (20010430-01)
Reference: BUGTRAQ:20010110 Immunix OS Security update for lots of temp file problems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97916374410647&w=2
Reference: DEBIAN:DSA-021
Reference: URL:http://www.debian.org/security/2001/dsa-021
Reference: BID:2182
Reference: URL:http://www.securityfocus.com/bid/2182
Reference: XF:linux-apache-symlink(5926)
Reference: URL:http://xforce.iss.net/static/5926.php

Description:
htpasswd and htdigest in Apache 2.0a9, 1.3.14, and others allows local users to overwrite arbitrary files via a symlink attack.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Christey, Magdych
Voter Comments:
 Frech> XF:linux-apache-symlink(5926)
 Christey> XF:linux-apache-symlink
   URL:http://xforce.iss.net/static/5926.php
 Christey> http://archives.neohapsis.com/archives/vendor/2001-q1/0019.html
 Christey> This item may have been re-introduced into the Apache source
   code sometime during 2002; CAN-2002-1233 has been created for
   that version, which affects Apache 1.3.27 and other versions.
 Christey> As a further clarification, CAN-2002-1233 is *only* for the
   Debian-specific regression error.
 Christey> DEBIAN:DSA-195
   URL:http://www.debian.org/security/2002/dsa-195


CAN-2001-0132

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010114 Trend Micro's VirusWall: Multiple vunerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html
Reference: BID:2213
Reference: URL:http://www.securityfocus.com/bid/2213

Description:
Interscan VirusWall 3.6.x and earlier follows symbolic links when uninstalling the product, which allows local users to overwrite arbitrary files via a symlink attack.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:interscan-viruswall-symlink
   URL:http://xforce.iss.net/static/5947.php
 Frech> XF:interscan-viruswall-symlink(5947)


CAN-2001-0133

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010114 Trend Micro's VirusWall: Multiple vunerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0235.html
Reference: BID:2212
Reference: URL:http://www.securityfocus.com/bid/2212

Description:
The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET requests that contain base64 encoded usernames and passwords.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:interscan-viruswall-weak-authentication(5946)


CAN-2001-0134

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010116 iXsecurity.20001120.compaq-authbo.a
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97967435023835&w=2
Reference: COMPAQ:SSRT0705
Reference: URL:http://www5.compaq.com/products/servers/management/agentsecurity.html
Reference: BID:2200
Reference: URL:http://www.securityfocus.com/bid/2200

Description:
Buffer overflow in cpqlogin.htm in web-enabled agents for various Compaq management software products such as Insight Manager and Management Agents allows remote attackers to execute arbitrary commands via a long user name.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:compaq-web-management-bo(5935)
 Christey> XF:compaq-web-management-bo
   URL:http://xforce.iss.net/static/5935.php


CAN-2001-0135

Phase: Proposed (20010214)
Reference: BUGTRAQ:20010112 UltraBoard cgi directory permission problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97933458505857&w=2
Reference: BID:2197
Reference: URL:http://www.securityfocus.com/bid/2197

Description:
The default installation of Ultraboard 2000 2.11 creates the Skins, Database, and Backups directories with world-writeable permissions, which could allow local users to modify sensitive information or possibly insert and execute CGI programs.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Christey> XF:ultraboard-cgi-perm
   URL:http://xforce.iss.net/static/5931.php
 Frech> XF:ultraboard-cgi-perm(5931)
   In description, "writeable": from
   http://www.dictionary.com/cgi-bin/dict.pl?term=Writable: Writable
   \Writ"a*ble\, a. Capable of, or suitable for, being written down. 
 Christey> Yeah yeah yeah, Andre, I knew you'd catch my bad spelling :-)


CAN-2001-0145

Phase: Proposed (20010404)
Reference: MS:MS01-012
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms01-012.asp
Reference: ATSTAKE:A022301-1
Reference: URL:http://www.atstake.com/research/advisories/2001/a022301-1.txt

Description:
Buffer overflow in VCard handler in Outlook 2000 and 98, and Outlook Express 5.x, allows an attacker to execute arbitrary commands via a malformed vCard birthday field.

Votes:

   ACCEPT(4) Wall, Cole, Baker, Balinsky
   MODIFY(1) Frech
   REVIEWING(3) Christey, Bishop, Ziese
Voter Comments:
 Christey> In a post to Bugtraq, Joel Moses notes that this is a
   duplicate of CAN-2000-0756:
   http://marc.theaimsgroup.com/?l=bugtraq&m=98322714210100&w=2
   
   As of this writing, it is not certain which candidate
   should be preferred: the candidate that has been publicly
   known longer (i.e. CAN-2000-0756), or the more "official"
   candidate, which has probably been publicized more (i.e.
   CAN-2001-0145).
 Balinsky> It seems that this is a more specific case of
   CAN-2000-0756. The reference for 2000-0756 states that there is a
   buffer overflow in the birthday AND the e-mail field, as well as other
   suspected fields. As this current candidate only addresses the
   birthday field, it seems that there are likely different lines of code
   involved.
   Microsoft is not specific about what specifically the patch
   addresses. It is possible that the other overflows in 2000-0756 are
   still vulnerable and that the @stake group just didn't bother to test
   them.
   We will not know the answer until someone retests those other
   fields to see if they are still vulnerable.
   If they are, then 2000-0756 might deserve being split up.
 Frech> XF:outlook-vcard-dos(5175)
 Christey> Consider adding BID:2459


CAN-2001-0146

Phase: Proposed (20010309)
Reference: MS:MS01-014
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-014.asp

Description:
IIS 5.0 and Microsoft Exchange 2000 allow remote attackers to cause a denial of service (memory allocation error) by repeatedly sending a series of specially formatted URL's.

Votes:

   ACCEPT(4) Cole, Baker, Ziese, Lawler
   NOOP(1) Christey
   RECAST(1) Frech
Voter Comments:
 Frech> (SF-EXEC)
   XF:iis-malformed-url-dos(6171)
   XF:exchange-malformed-url-dos(6172)
   Not only is this two applications, but it is fixed by two patches.
   Quoting Microsoft:
   Because the flaw occurs in two different code modules, one of which installs
   as part of IIS 5.0 and both of which install as part of Exchange 2000, it is
   important for Exchange 2000 administrators to install both the IIS and
   Exchange patches below. 
   Also, in the description, avoid using an apostrophe on "URLs" when it is
   simply plural and not possessive (aka the "grocer's apostrophe").
 Christey> Consider adding BID:2440
 Christey> Consider adding BID:2441


CAN-2001-0158

Phase: Assigned (20010301)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0159

Phase: Assigned (20010301)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0160

Phase: Assigned (20010301)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0161

Phase: Assigned (20010301)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0162

Phase: Assigned (20010306)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0163

Phase: Assigned (20010306)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0167

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010129 [CORE SDI ADVISORY] WinVNC client buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98088315825366&w=2
Reference: BID:2305
Reference: URL:http://www.securityfocus.com/bid/2305
Reference: XF:winvnc-client-bo
Reference: URL:http://xforce.iss.net/static/6025.php

Description:
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long rfbConnFailed packet with a long reason string.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0168

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010129 [CORE SDI ADVISORY] WinVNC server buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=vnc-list&m=98080763005455&w=2
Reference: BID:2306
Reference: URL:http://www.securityfocus.com/bid/2306
Reference: XF:winvnc-server-bo
Reference: URL:http://xforce.iss.net/static/6026.php

Description:
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute arbitrary commands via a long HTTP GET request when the DebugLevel registry key is greater than 0.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0171

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010130 DOS Vulnerability in SlimServe HTTPd
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0505.html
Reference: XF:slimserve-httpd-dos
Reference: URL:http://xforce.iss.net/static/6028.php
Reference: BID:2318
Reference: URL:http://www.securityfocus.com/bid/2318

Description:
Buffer overflow in SlimServe HTTPd 1.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long GET request.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Christey, Ziese
   REVIEWING(1) Lawler
Voter Comments:
 Christey> Apparently, the original discoverer re-posted an advisory
   saying that version 1.1 was also affected (everything else is
   a carbon copy of the original post, so it took me a minute to
   see what the deal was :-)
   BUGTRAQ:20010228 DOS Vulnerability in SlimServe HTTPd
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0509.html


CAN-2001-0172

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010109 major security bug in reiserfs (may affect SuSE Linux)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0127.html
Reference: XF:suse-reiserfs-long-filenames
Reference: URL:http://xforce.iss.net/static/5910.php
Reference: BID:2180
Reference: URL:http://www.securityfocus.com/bid/2180

Description:
Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0173

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010130 Nobreak Tecnologies CrazyWWWBoard Remote Buffer Overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0486.html
Reference: BID:2329
Reference: URL:http://www.securityfocus.com/bid/2329
Reference: XF:crazywwwboard-qdecoder-bo
Reference: URL:http://xforce.iss.net/static/6033.php

Description:
Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, allows remote attackers to execute arbitrary commands via a long MIME Content-Type header.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0177

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010110 Vulnerable: Conference Room Professional-Developer Edititon.
Reference: URL:http://www.securityfocus.com/archive/1/155388
Reference: BID:2178
Reference: URL:http://www.securityfocus.com/bid/2178
Reference: XF:conferenceroom-developer-dos
Reference: URL:http://xforce.iss.net/static/5909.php

Description:
WebMaster ConferenceRoom 1.8.1 allows remote attackers to cause a denial of service via a buddy relationship between the IRC server and a server clone.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0180

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010129 Remote Command Execution in guestserver.cgi + exploit
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0471.html
Reference: XF:guestserver-cgi-execute-commands
Reference: URL:http://xforce.iss.net/static/6027.php

Description:
Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0181

Phase: Proposed (20010309)
Reference: CALDERA:CSSA-2001-003.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-003.0.txt
Reference: BID:2215
Reference: URL:http://www.securityfocus.com/bid/2215
Reference: XF:dhcp-format-string
Reference: URL:http://xforce.iss.net/static/5953.php

Description:
Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(4) Baker, Frech, Ziese, Lawler

CAN-2001-0184

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010121 eEye Iris the Network traffic analyser DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0343.html
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0352.html
Reference: BID:2278
Reference: URL:http://www.securityfocus.com/bid/2278
Reference: XF:eeye-iris-dos
Reference: URL:http://xforce.iss.net/static/5981.php

Description:
eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.

Votes:

   ACCEPT(4) Baker, Frech, Ziese, Lawler

CAN-2001-0186

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010204 Vulnerability in Free Java Web Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0061.html

Description:
Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   MODIFY(1) Frech
   NOOP(2) Ziese, Lawler
Voter Comments:
 Lawler> Very little info available.
 Frech> XF:free-java-directory-traversal(6064)


CAN-2001-0188

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010122 def-2001-03: GoodTech Systems FTP Connection DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0350.html
Reference: BID:2270
Reference: URL:http://www.securityfocus.com/bid/2270
Reference: XF:goodtech-ftp-dos
Reference: URL:http://xforce.iss.net/static/5984.php

Description:
GoodTech FTP server 3.0.1.2.1.0 and earlier allows remote attackers to cause a denial of service via a flood of connections to the server, which causes it to crash.

Votes:

   ACCEPT(2) Frech, Oliver
   NOOP(2) Ziese, Lawler
Voter Comments:
 Oliver> Identified in Hotfix


CAN-2001-0192

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010201 XMail CTRLServer remote buffer overflow vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0047.html
Reference: CONFIRM:http://xmailserver.org/XMail-Readme.txt

Description:
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.

Votes:

   ACCEPT(2) Baker, Lawler
   MODIFY(1) Frech
   NOOP(1) Ziese
Voter Comments:
 Lawler> http://xmailserver.org/xmaildoc.htm
 Frech> XF:xmail-ctrlserver-bo(6060)


CAN-2001-0198

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010131 [SPSadvisory#41]Apple Quick Time Plug-in Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98096678523370&w=2
Reference: XF:quicktime-embedded-tag-bo
Reference: URL:http://xforce.iss.net/static/6040.php
Reference: BID:2328
Reference: URL:http://www.securityfocus.com/bid/2328

Description:
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF paramater in an EMBED tag.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Christey, Ziese, Lawler
Voter Comments:
 Christey> Fix typo: "paramater"


CAN-2001-0199

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010204 Vulnerability in SEDUM HTTP Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0064.html
Reference: BID:2335
Reference: URL:http://www.securityfocus.com/bid/2335

Description:
Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack in the HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(2) Ziese, Lawler
Voter Comments:
 Frech> XF:sedum-directory-traversal(6063)


CAN-2001-0200

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010204 Web root exposure in HSWeb Webserver
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0052.html
Reference: BID:2336
Reference: URL:http://www.securityfocus.com/bid/2336

Description:
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ directory, which will list the path if directory browsing is enabled.

Votes:

   ACCEPT(1) Lawler
   MODIFY(1) Frech
   NOOP(1) Ziese
Voter Comments:
 Frech> XF:hsweb-directory-browsing(6061)


CAN-2001-0201

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010117 Postaci allows arbitrary SQL query execution
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0287.html
Reference: BID:2230
Reference: URL:http://www.securityfocus.com/bid/2230
Reference: XF:postaci-sql-command-injection
Reference: URL:http://xforce.iss.net/static/5972.ph p

Description:
The Postaci frontend for PostgreSQL does not properly filter characters such as semicolons, which could allow remote attackers to execute arbitrary SQL queries via the deletecontact.php program.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Ziese, Lawler, Oliver

CAN-2001-0202

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010205 Vulnerability in Picserver
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0073.html
Reference: BID:2339
Reference: URL:http://www.securityfocus.com/bid/2339

Description:
Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(2) Ziese, Lawler
Voter Comments:
 Frech> XF:picserver-directory-traversal(6065)


CAN-2001-0205

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010206 Vulnerability in AOLserver
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98148759123258&w=2
Reference: BUGTRAQ:20010208 Vulnerability in AOLserver
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98168216003867&w=2
Reference: BID:2343
Reference: URL:http://www.securityfocus.com/bid/2343

Description:
Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by inserting "..." into the requested pathname, a modified .. (dot dot) attack.

Votes:

   ACCEPT(1) Lawler
   MODIFY(1) Frech
   NOOP(2) Ziese, Oliver
Voter Comments:
 Frech> XF:aolserver-directory-traversal(6069)


CAN-2001-0206

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010207 Vulnerability in Soft Lite ServerWorx
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0137.html
Reference: BID:2346
Reference: URL:http://www.securityfocus.com/bid/2346

Description:
Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by inserting a .. (dot dot) or ... into the requested pathname of an HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Lawler
Voter Comments:
 Frech> XF:serverworx-directory-traversal(6081)


CAN-2001-0208

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010211 Security Hole in Microfocus Cobol
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0205.html
Reference: BID:2359
Reference: URL:http://www.securityfocus.com/bid/2359

Description:
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.

Votes:

   ACCEPT(1) Lawler
   MODIFY(1) Frech
   NOOP(2) Cole, Ziese
Voter Comments:
 Frech> XF:cobol-apptrack-nolicense-symlink(6094)
   Company name is Micro Focus, a subsidiary of Merant
   (http://www.merant.com/products/microfocus/)


CAN-2001-0209

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010118 Shoutcast Server Buffer Crashes Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0305.html
Reference: XF:shoutcast-description-bo
Reference: URL:http://xforce.iss.net/static/5965.php

Description:
Buffer overflow in Shoutcast Distributed Network Audio Server (DNAS) 1.7.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long description.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0210

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010212 Commerce.cgi Directory Traversal
Reference: URL:http://www.securityfocus.com/archive/1/162259
Reference: BID:2361
Reference: URL:http://www.securityfocus.com/bid/2361

Description:
Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (dot dot) attack in the page parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Lawler
Voter Comments:
 Frech> XF:commerce-cgi-view-files(6095)


CAN-2001-0211

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010212 WebSPIRS CGI script "show files" Vulnerability.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0217.html
Reference: BID:2362
Reference: URL:http://www.securityfocus.com/bid/2362

Description:
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack on the sp.nextform parameter.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cole, Christey, Ziese, Lawler
Voter Comments:
 Frech> XF:webspirs-cgi-view-files(6101)
 Christey> ADDREF BUGTRAQ:20010331 Webspirs remote script explotation
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98608561912120&w=2
 Christey> Mention the webspirs.cgi program specifically; also, should
   the version be 3.3.1?


CAN-2001-0212

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010212 HIS Auktion 1.62: "show files" vulnerability and remote command execute.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0218.html
Reference: BID:2367
Reference: URL:http://www.securityfocus.com/bid/2367

Description:
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot) in the menue parameter, and possibly execute commands via shell metacharacters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Lawler
Voter Comments:
 Frech> XF:his-auktion-cgi-url(6090)


CAN-2001-0213

Phase: Proposed (20010309)
Reference: BUGTRAQ:200101125 [SAFER] Security Bulletin 010125.EXP.1.12
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0421.html
Reference: XF:planetintra-pi-bo
Reference: URL:http://xforce.iss.net/static/6002.php

Description:
Buffer overflow in pi program in PlanetIntra 2.5 allows remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(2) Frech, Lawler
   NOOP(2) Christey, Ziese
Voter Comments:
 Christey> CHANGEREF BUGTRAQ [normalize date]


CAN-2001-0214

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010212 Way board: "show files" Vulnerability with null bite bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0212.html
Reference: BID:2370
Reference: URL:http://www.securityfocus.com/bid/2370

Description:
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and terminating the filename with a null byte.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Lawler
Voter Comments:
 Frech> XF:wayboard-cgi-view-files(6091)


CAN-2001-0216

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010212 PALS Library System "show files" Vulnerability and remote command execution
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html
Reference: BID:2372
Reference: URL:http://www.securityfocus.com/bid/2372

Description:
PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in the documentName parameter.

Votes:

   ACCEPT(2) Baker, Lawler
   MODIFY(1) Frech
   NOOP(2) Cole, Ziese
Voter Comments:
 Frech> XF:webpals-library-cgi-url(6102)


CAN-2001-0217

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010212 PALS Library System "show files" Vulnerability and remote command execution
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0220.html
Reference: BID:2372
Reference: URL:http://www.securityfocus.com/bid/2372

Description:
Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the documentName parameter.

Votes:

   ACCEPT(1) Baker
   MODIFY(2) Frech, Lawler
   NOOP(2) Cole, Ziese
Voter Comments:
 Lawler> Combine with CAN-2001-0216
 Frech> XF:webpals-library-cgi-url(6102)


CAN-2001-0220

Phase: Proposed (20010309)
Reference: FREEBSD:FreeBSD-SA-01:21
Reference: URL:http://archives.neohapsis.com/archives/freebsd/2001-02/0082.html

Description:
Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.

Votes:

   ACCEPT(4) Cole, Baker, Ziese, Lawler
   RECAST(1) Frech
Voter Comments:
 Frech> XF:ja-elvis-elvrec-bo(6074)
   XF:ko-helvis-elvrec-bo(6075)
   MODIFY/RECAST(SF-EXEC)


CAN-2001-0223

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010117 numerous holes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97984174724339&w=2
Reference: XF:wwwwais-cgi-dos
Reference: URL:http://xforce.iss.net/static/5980.php

Description:
Buffer overflow in wwwwais allows remote attackers to execute arbitrary commands via a long QUERY_STRING (HTTP GET request).

Votes:

   ACCEPT(2) Frech, Lawler
   NOOP(1) Ziese

CAN-2001-0224

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010212 Vulnerability in Muscat Empower wich can print path to DB-dir.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0216.html
Reference: BID:2374
Reference: URL:http://www.securityfocus.com/bid/2374

Description:
Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request in the DB parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Lawler
Voter Comments:
 Frech> XF:muskat-empower-url-dir(6093)


CAN-2001-0225

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010207 Infobot 0.44.5.3/below remotely vulnerable (also in FreeBSD ports tree)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0127.html
Reference: BID:2349
Reference: URL:http://www.securityfocus.com/bid/2349

Description:
fortran math component in Infobot 0.44.5.3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cole, Ziese, Lawler
Voter Comments:
 Frech> XF:infobot-calc-gain-access(6078)


CAN-2001-0226

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010205 Vulnerabilities in BiblioWeb Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html

Description:
Directory traversal vulnerability in BiblioWeb web server 2.0 allows remote attackers tor ead arbitrary files via a .. (dot dot) or ... attack in an HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Christey, Ziese, Lawler
Voter Comments:
 Frech> XF:biblioweb-directory-traversal(6066)
 Christey> fix typo: "tor ead"


CAN-2001-0227

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010205 Vulnerabilities in BiblioWeb Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0075.html

Description:
Buffer overflow in BiblioWeb web server 2.0 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(2) Ziese, Lawler
Voter Comments:
 Frech> XF:biblioweb-get-dos(6068)


CAN-2001-0228

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010202 GoAhead Web Server Directory Traversal Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0022.html

Description:
Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files via a .. attack in an HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(2) Ziese, Lawler
Voter Comments:
 Frech> XF:goahead-directory-traversal(6046)


CAN-2001-0229

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010206 Security hole in ChiliSoft ASP on Linux.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0112.html

Description:
Chili!Soft ASP for Linux before 3.6 does not properly set group privileges when running in inherited mode, which could allow attackers to gain privileges via malicious scripts.

Votes:

   ACCEPT(1) Lawler
   MODIFY(1) Frech
   NOOP(1) Ziese
Voter Comments:
 Frech> XF:chilisoft-asp-elevate-privileges(6072)


CAN-2001-0231

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010103 News Desk 1.2 CGI Vulnerbility
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html
Reference: BID:2172
Reference: URL:http://www.securityfocus.com/bid/2172
Reference: XF:newsdesk-cgi-read-files
Reference: URL:http://xforce.iss.net/static/5898.php

Description:
Directory traversal vulnerability in newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via a .. in the "t" parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Ziese, Lawler

CAN-2001-0232

Phase: Proposed (20010309)
Reference: BUGTRAQ:20010103 News Desk 1.2 CGI Vulnerbility
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0042.html

Description:
newsdesk.cgi in News Desk 1.2 allows remote attackers to read arbitrary files via shell metacharacters.

Votes:

   MODIFY(1) Frech
   NOOP(2) Ziese, Lawler
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:newsdesk-metacharacter-command-execution(8377)


CAN-2001-0242

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010502 Microsoft Media Player ASX Parser buffer overflow vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/181419
Reference: BUGTRAQ:20010506 Re: Microsoft Media Player ASX Parser buffer overflow vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/183906
Reference: MS:MS01-029
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms01-029.asp
Reference: BID:2677
Reference: URL:http://www.securityfocus.com/bid/2677
Reference: BID:2686
Reference: URL:http://www.securityfocus.com/bid/2686

Description:
Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:MS00-090.

Votes:

   ACCEPT(6) Wall, Cole, Baker, Ziese, Magdych, Williams
   MODIFY(1) Frech
   NOOP(1) Renaud
Voter Comments:
 Frech> XF:mediaplayer-asx-bo(5574)


CAN-2001-0246

Phase: Proposed (20010524)
Reference: MS:MS01-027
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-027.asp

Description:
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain, aka a variant of the "Frame Domain Verification" vulnerability.

Votes:

   ACCEPT(5) Wall, Cole, Baker, Magdych, Williams
   MODIFY(1) Frech
   NOOP(2) Ziese, Renaud
   REVIEWING(1) Christey
Voter Comments:
 Christey> See comments for CAN-2001-0332; may need to be merged because
   of CD:SF-LOC.
 Frech> XF:ie-frame-verification-variant(6748)


CAN-2001-0247

Phase: Modified (20010910-01)
Reference: NAI:20010409 Globbing Vulnerabilities in Multiple FTP Daemons
Reference: URL:http://www.nai.com/research/covert/advisories/048.asp
Reference: CERT:CA-2001-07
Reference: URL:http://www.cert.org/advisories/CA-2001-07.html
Reference: NETBSD:NetBSD-SA2000-018
Reference: URL:ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-018.txt.asc
Reference: FREEBSD:FreeBSD-SA-01:33
Reference: URL:http://archives.neohapsis.com/archives/freebsd/2001-04/0466.html
Reference: SGI:20010802-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20010802-01-P
Reference: BID:2548
Reference: URL:http://www.securityfocus.com/bid/2548
Reference: XF:ftp-glob-expansion(6332)
Reference: URL:http://xforce.iss.net/static/6332.php

Description:
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.

Votes:

   ACCEPT(5) Cole, Baker, Ziese, Renaud, Oliver
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:ftp-glob-expansion(6332)
 Christey> ADDREF SGI:20010802-01-P
 Christey> COMPAQ:SSRT-547
   URL:http://archives.neohapsis.com/archives/tru64/2002-q3/0017.html


CAN-2001-0248

Phase: Interim (20010911)
Reference: NAI:20010409 Globbing Vulnerabilities in Multiple FTP Daemons
Reference: URL:http://www.nai.com/research/covert/advisories/048.asp
Reference: CERT:CA-2001-07
Reference: URL:http://www.cert.org/advisories/CA-2001-07.html
Reference: BID:2552
Reference: URL:http://www.securityfocus.com/bid/2552
Reference: XF:ftp-glob-expansion(6332)
Reference: URL:http://xforce.iss.net/static/6332.php

Description:
Buffer overflow in FTP server in HPUX 11 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the STAT command, which uses glob to generate long strings.

Votes:

   ACCEPT(5) Cole, Prosser, Baker, Ziese, Renaud
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:ftp-glob-expansion(6332)
 Prosser> HPSBUX0107-162.  Probably should change description to add the HP-UX 10.01, 10.10, 10.20, 10.24 (VVOS), 11.04 (VVOS) and 11.11 versions of the operating system as well. Patches for all systems referenced in the advisory.


CAN-2001-0249

Phase: Interim (20010911)
Reference: NAI:20010409 Globbing Vulnerabilities in Multiple FTP Daemons
Reference: URL:http://www.nai.com/research/covert/advisories/048.asp
Reference: CERT:CA-2001-07
Reference: URL:http://www.cert.org/advisories/CA-2001-07.html
Reference: BID:2550
Reference: URL:http://www.securityfocus.com/bid/2550
Reference: XF:ftp-glob-expansion(6332)
Reference: URL:http://xforce.iss.net/static/6332.php

Description:
Heap overflow in FTP daemon in Solaris 8 allows remote attackers to execute arbitrary commands by creating a long pathname and calling the LIST command, which uses glob to generate long strings.

Votes:

   ACCEPT(5) Cole, Dik, Baker, Ziese, Renaud
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:ftp-glob-expansion(6332)
 Dik> sun bug: 4436988
 Dik> sun bug: 4436988


CAN-2001-0250

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010124 [SAFER] Security Bulletin 010124.EXP.1.11
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0396.html
Reference: BID:2285
Reference: URL:http://www.securityfocus.com/bid/2285
Reference: XF:netscape-enterprise-list-directories
Reference: URL:http://xforce.iss.net/static/5997.php

Description:
The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories under the web server root via the INDEX command.

Votes:

   ACCEPT(4) Cole, Baker, Frech, Bishop
   NOOP(2) Wall, Ziese
Voter Comments:
 Bishop> This is a problem if the policy says it is. It may not be a security
   problem in general, though. I voted accept because it may be a problem.


CAN-2001-0251

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010125 [SAFER] Security Bulletin 010125.DOS.1.5
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0422.html
Reference: BID:2294
Reference: URL:http://www.securityfocus.com/bid/2294
Reference: XF:netscape-enterprise-revlog-dos
Reference: URL:http://xforce.iss.net/static/6003.php

Description:
The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG command.

Votes:

   ACCEPT(4) Cole, Baker, Frech, Bishop
   NOOP(2) Wall, Ziese
Voter Comments:
 CHANGE> [Bishop changed vote from REVIEWING to ACCEPT]


CAN-2001-0253

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010128 Hyperseek 2000 Search Engine - "show directory & files" bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0463.html
Reference: BID:2314
Reference: URL:http://www.securityfocus.com/bid/2314
Reference: XF:hyperseek-cgi-reveal-info
Reference: URL:http://xforce.iss.net/static/6012.php

Description:
Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary files and directories via a .. (dot dot) attack in the show parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0254

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98021181215325&w=2

Description:
FaSTream FTP++ Server 2.0 allows remote attackers to obtain the real pathname of the server via the "pwd" command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:fastream-ftp-path-disclosure(5977)


CAN-2001-0255

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98021181215325&w=2
Reference: BID:2267
Reference: URL:http://www.securityfocus.com/bid/2267
Reference: XF:fastream-ftp-path-disclosure
Reference: URL:http://xforce.iss.net/static/5977.php

Description:
FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including the drive letter name (e.g. C:) in the requested pathname.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0256

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010119 Multiple Vulnerabilities In FaSTream FTP++ (+ ICS Tftpserver DoS)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98021181215325&w=2
Reference: BID:2261
Reference: URL:http://www.securityfocus.com/bid/2261
Reference: XF:fastream-ftp-server-dos
Reference: URL:http://xforce.iss.net/static/5976.php

Description:
FaSTream FTP++ Server 2.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long username.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0257

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html
Reference: BID:2291
Reference: URL:http://www.securityfocus.com/bid/2291
Reference: XF:easycom-safecom-url-bo
Reference: URL:http://xforce.iss.net/static/5988.php

Description:
Buffer overflow in Easycom/Safecom Print Server Web service, version 404.590 and earlier, allows remote attackers to execute arbitrary commands via (1) a long URL or (2) a long HTTP header field such as "Host:".

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(3) Wall, Bishop, Ziese

CAN-2001-0258

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010123 def-2001-06: Easycom/Safecom 10/100 Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0375.html
Reference: XF:easycom-safecom-printguide-dos
Reference: URL:http://xforce.iss.net/static/5989.php

Description:
The Easycom/Safecom Print Server (firmware 404.590) PrintGuide server allows remote attackers to cause a denial of service via a large number of connections that send null characters.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Cole, Bishop, Ziese

CAN-2001-0261

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010119 BugTraq: EFS Win 2000 flaw
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97992179925715&w=2
Reference: BUGTRAQ:20010123 Reply to EFS note on Bugtraq
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98027311214976&w=2
Reference: BID:2243
Reference: URL:http://www.securityfocus.com/bid/2243
Reference: XF:win2k-efs-recover-data
Reference: URL:http://xforce.iss.net/static/5973.php

Description:
Microsoft Windows 2000 Encrypted File System does not properly destroy backups of files that are encrypted, which allows a local attacker to recover the text of encrypted files.

Votes:

   ACCEPT(3) Baker, Frech, Bishop
   NOOP(3) Cole, Christey, Ziese
   REJECT(1) LeBlanc
   REVIEWING(1) Wall
Voter Comments:
 Bishop> Sounds like Microsoft just confirmed it!
 Christey> The description should make the point that the original files
   are in plaintext.
 LeBlanc> The preconditions needed to obtain the clear-text backup file
   are that the user must be able to read the raw disk. Only administrators
   or those with physical access can read the raw disk. An admin could
   alter the operating system such that anything a user did would be
   available, even EFS information (since the admin can cause processes to
   run as any user who is logged on currently). Thus even if this issue
   were not present, the same set of preconditions would lead to access to
   the same information. In the case of physical access, scrubbing the disk
   should be viewed only as raising the bar - information can be recovered
   even from overwritten sectors. Additionally, coverage of a file might
   not be complete - in the case where a file is truncated, then encrypted,
   there could be sectors with file information that the operating system
   would have no knowledge of at the time the encryption occurred, and
   there is no practical way to wipe these. Considering all the realities
   of the situation, the only real-world solution is to create files you'd
   like encrypted in a directory marked for encryption.
 CHANGE> [Baker changed vote from REVIEWING to ACCEPT]


CAN-2001-0262

Phase: Proposed (20010524)
Reference: ATSTAKE:A041301-1
Reference: URL:http://www.atstake.com/research/advisories/2001/a041301-1.txt

Description:
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.

Votes:

   ACCEPT(3) Cole, Baker, Williams
   MODIFY(1) Frech
   NOOP(4) Wall, Christey, Ziese, Renaud
Voter Comments:
 Frech> XF:netscape-smartdownload-sdph20-bo(6403)
 Christey> BUGTRAQ:20010418 Netscape SmartDownload 1.3 Buffer Overflow Vulnerability
   URL:http://www.securityfocus.com/archive/1/177589
   Add sdph20.dll as affected component in description, as
   indicated by above post.
 Christey> Consider adding BID:2615


CAN-2001-0263

Phase: Modified (20010222-02)
Reference: ATSTAKE:A040301-1
Reference: URL:http://www.atstake.com/research/advisories/2001/a040301-1.txt
Reference: BID:2537
Reference: URL:http://online.securityfocus.com/bid/2537
Reference: XF:bpftp-obtain-credentials(6330)
Reference: URL:http://xforce.iss.net/static/6330.php

Description:
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows attackers to read file attributes outside of the web root via the (1) SIZE and (2) MDTM commands when the "show relative paths" option is not enabled.

Votes:

   ACCEPT(3) Cole, Baker, Renaud
   MODIFY(1) Frech
   NOOP(3) Wall, Ziese, Oliver
Voter Comments:
 Frech> XF:bpftp-obtain-credentials(6330)


CAN-2001-0264

Phase: Proposed (20010524)
Reference: ATSTAKE:A040301-1
Reference: URL:http://www.atstake.com/research/advisories/2001/a040301-1.txt
Reference: BID:2534
Reference: URL:http://www.securityfocus.com/bid/2534

Description:
Gene6 G6 FTP Server 2.0 (aka BPFTP Server 2.10) allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Oliver
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:bpftp-obtain-credentials(6330)


CAN-2001-0270

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010219 Denial of Service Condition exists in Fore/Marconi ASX Switches
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0349.html
Reference: BID:2400
Reference: URL:http://www.securityfocus.com/bid/2400

Description:
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:asx-remote-dos(6133)
 Christey> A rediscovery or closely related vulnerability is in CAN-2001-0994.


CAN-2001-0271

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010218 mailnews.cgi
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0347.html

Description:
mailnews.cgi 1.3 and earlier allows remote attackers to execute arbitrary commands via a user name that contains shell metacharacters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:http-cgi-mailnews-username(6139)


CAN-2001-0272

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010212 W3.ORG sendtemp.pl
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0259.html

Description:
Directory traversal vulnerability in sendtemp.pl in W3.org Anaya Web development server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the templ parameter.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:sendtemp-pl-read-files(6104)
   Amaya, not Anaya


CAN-2001-0273

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010220 [CryptNET Advisory] pgp4pine-1.75-6 - expired public keys
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0367.html

Description:
pgp4pine Pine/PGP interface version 1.75-6 does not properly check to see if a public key has expired when obtaining the keys via Gnu Privacy Guard (GnuPG), which causes the message to be sent in cleartext.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:pgp4pine-expired-keys(6135)


CAN-2001-0275

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010219 NetSuite 1.02 web server vulnerabilty
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0346.html

Description:
Moby Netsuite Web Server 1.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:moby-netsuite-bo(6132)


CAN-2001-0277

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010217 BadBlue Web Server Ext.dll Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98263019502565&w=2
Reference: BID:2392
Reference: URL:http://www.securityfocus.com/bid/2392

Description:
Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP GET request.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:badblue-ext-dos(6131)
 Christey> CONFIRM:http://www.badblue.com/p010219.htm


CAN-2001-0281

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010221 NT drivers are potentially vulnerable to format string bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0379.html

Description:
Format string vulnerability in DbgPrint function, used in debug messages for some Windows NT drivers (possibly when called through DebugMessage), may allow local users to gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(2) Cole, Ziese
   REVIEWING(2) Wall, Bishop
Voter Comments:
 Frech> XF:dbgprint-format-string(6441)


CAN-2001-0282

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010223 SEDUM v2.1 HTTPd - Denial of Service
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0419.html

Description:
SEDUM 2.1 HTTP server allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:sedum-http-dos(6152)


CAN-2001-0283

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010302 Sunftp build9(1) - ftp server Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0523.html

Description:
Directory traversal vulnerability in SunFTP build 9 allows remote attackers to read arbitrary files via .. (dot dot) characters in various commands, including (1) GET, (2) MKDIR, (3) RMDIR, (4) RENAME, or (5) PUT.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:sunftp-gain-access(6195)


CAN-2001-0285

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010226 A1 Server v1.0a HTTPd (DoS & Dir Traversal)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html

Description:
Buffer overflow in A1 HTTP server 1.0a allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:a1-server-dos(6161)


CAN-2001-0286

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010226 A1 Server v1.0a HTTPd (DoS & Dir Traversal)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0457.html

Description:
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> a1-server-directory-traversal(6162)


CAN-2001-0291

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010305 Remote buffer overflow condition in post-query (CGI).
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0003.html

Description:
Buffer overflow in post-query sample CGI program allows remote attackers to execute arbitrary commands via an HTTP POST request that contains at least 10001 parameters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:postquery-http-post-bo(6510)


CAN-2001-0292

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010302 PHPNUKE4.4.1a Advisory
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0525.html

Description:
PHP-Nuke 4.4.1a allows remote attackers to modify a user's email address and obtain the password by guessing the user id (UID) and calling user.php with the saveuser operator.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:phpnuke-saveuser-obtain-password(6511)


CAN-2001-0293

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010228 Vulnerability in FtpXQ Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0508.html
Reference: BID:2426
Reference: URL:http://www.securityfocus.com/bid/2426

Description:
Directory traversal vulnerability in FtpXQ FTP server 2.0.93 allows remote attackers to read arbitrary files via a .. (dot dot) in the GET command.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:ftpxq-directory-traversal(6166)
 Christey> Email inquiry sent to support@datawizard.net on March 10, 2002.
 Christey> Acknowledgement received from rmawji@datawizard.net on March
   11, 2002: "that was fixed in the next version (2.0.94)."


CAN-2001-0294

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010228 Vulnerability in TYPSoft FTP Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0511.html

Description:
Directory traversal vulnerability in TYPSoft FTP Server 0.85 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in a GET command, or (2) a ... in a CWD command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(2) Christey, Bishop
Voter Comments:
 Frech> XF:typsoft-ftp-directory-traversal(6165)
 Christey> BID:2489
   
   The CWD... may have been rediscovered for version 0.95 in:
   BUGTRAQ:20010507 Vulnerabilty in TYPsoft FTP server
   URL:http://online.securityfocus.com/archive/1/183917
   
   However, this CWD uses ".../" whereas the initial post
   used just "..." and said that the vendor had fixed the issue.
   So, this is probably just an incomplete fix by the vendor.


CAN-2001-0296

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010303 WFTPD Pro 3.00 R1 Buffer Overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0531.html

Description:
Buffer overflow in WFTPD Pro 3.00 allows remote attackers to execute arbitrary commands via a long CWD command.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Ziese
   RECAST(1) Prosser
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:wftpd-pro-cwd-bo(6184)
 Prosser> See http://www.mail-archive.com/bugtraq@securityfocus.com/msg05671.html for additional info on this one.  It looks like Can-2001-0296 may be a continuation of CVE 1999-0950.  Appears from ref that this problem has been in every version since the 2.40 problem reported Oct 1999 (CVE 1999-0950).  Just managed to change the code so it requires more characters to overflow the buffer.  I haven't tested this, but just from the available documentation, these problems look like a continuation of the early one.


CAN-2001-0297

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010224 The Simple Server HTTPd Directory Traversal
Reference: URL:http://www.securityfocus.com/archive/1/165523
Reference: BID:2415
Reference: URL:http://www.securityfocus.com/bid/2415

Description:
Directory traversal vulnerability in Simple Server HTTPd 1.0 (originally Free Java Server) allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

Votes:

   ACCEPT(1) Cole
   NOOP(2) Wall, Ziese
   REJECT(1) Frech
   REVIEWING(1) Bishop
Voter Comments:
 Frech> Dupe of CAN-2001-0186


CAN-2001-0298

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010227 WebReflex 1.55 HTTPd DoS
Reference: URL:http://www.securityfocus.com/archive/1/165671
Reference: BID:2425
Reference: URL:http://www.securityfocus.com/bid/2425

Description:
Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP GET request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:webreflex-http-get-dos(6163)


CAN-2001-0300

Phase: Proposed (20010404)
Reference: BUGTRAQ:20001222 vulnerability #2 in Oracle Internet Directory 2.1.1.1 in Oracle 8.1.7
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2000-12/0434.html

Description:
oidldapd 2.1.1.1 in Oracle 8.1.7 records log files in a directory (ldaplog) that has world-writable permissions, which may allow local users to delete logs and/or overwrite other files via a symlink attack.

Votes:

   NOOP(3) Wall, Cole, Ziese
   REJECT(1) Frech
   REVIEWING(1) Bishop
Voter Comments:
 Frech> Validity threshold is not met by the references cited. Would
   be willing to reassess and change vote if more information is
   forthcoming.


CAN-2001-0302

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010215 Vulnerabilities in Pi3Web Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html
Reference: BID:2381
Reference: URL:http://www.securityfocus.com/bid/2381

Description:
Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:pi3web-isapi-bo(6113)
 Christey> CONFIRM:http://sourceforge.net/tracker/index.php?func=detail&aid=410354&group_id=17753&atid=117753


CAN-2001-0303

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010215 Vulnerabilities in Pi3Web Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0316.html
Reference: BID:2381
Reference: URL:http://www.securityfocus.com/bid/2381

Description:
tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to determine the physical path of the server via a URL that requests a non-existent file.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:pi3web-reveal-path(6114)
 Christey> This issue was rediscovered a year later, in version 2.0.0.
   Since it's a default configuration problem, it is likely that
   the vendor did not fix it.
   BUGTRAQ:20020310 Pi3Web/2.0.0 File-Disclosure/Path Disclosure vuln
   URL:http://online.securityfocus.com/archive/1/260734
   BID:4261
   XF:pi3web-error-disclosure(8428)


CAN-2001-0304

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010216 Vulnerability in Resin Webserver
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98229372610440&w=2
Reference: BID:2384
Reference: URL:http://www.securityfocus.com/bid/2384

Description:
Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot dot) in a URL request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:resin-directory-traversal(6118)


CAN-2001-0305

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010216 Thinking Arts Store.cgi Directory Traversal
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0324.html
Reference: BID:2385
Reference: URL:http://www.securityfocus.com/bid/2385

Description:
Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary files via a .. (dot dot) in the StartID parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:esone-cgi-directory-traversal(6124)


CAN-2001-0306

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010216 WEBactive HTTP Server 1.0 Directory Traversal
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0332.html
Reference: BID:2386
Reference: URL:http://www.securityfocus.com/bid/2386

Description:
Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:webactive-directory-traversal(6121)


CAN-2001-0307

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010216 Vulnerabilities in Bajie Http JServer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html

Description:
Bajie HTTP JServer 0.78 allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:bajie-execute-shell(6117)


CAN-2001-0308

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010216 Vulnerabilities in Bajie Http JServer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0314.html
Reference: BID:2388
Reference: URL:http://www.securityfocus.com/bid/2388

Description:
UploadServlet in Bajie HTTP JServer 0.78 allows remote attackers to execute arbitrary commands by calling the servlet to upload a program, then using a ... (modified ..) to access the file that was created for the program.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Bishop, Ziese
Voter Comments:
 Frech> XF:bajie-directory-traversal(6115)


CAN-2001-0312

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010125 Yet Another IBM WebSphere Showcode Vulerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-01/0446.html

Description:
IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.

Votes:

   MODIFY(1) Frech
   NOOP(2) Cole, Ziese
   REVIEWING(2) Wall, Bishop
Voter Comments:
 Frech> XF:websphere-plugin-view-source(6435)


CAN-2001-0313

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010126 Borderware v6.1.2 ping DoS vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98053139231392&w=2
Reference: XF:borderware-ping-dos
Reference: URL:http://xforce.iss.net/static/6004.php

Description:
Borderware Firewall Server 6.1.2 allows remote attackers to cause a denial of service via a ping to the broadcast address of the public network on which the server is placed, which causes the server to continuously send pings (echo requests) to the network.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(2) Wall, Ziese
   REVIEWING(1) Bishop

CAN-2001-0314

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010125 America Online 5.0 contains a buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98053366805491&w=2
Reference: XF:aol-malformed-url-dos
Reference: URL:http://xforce.iss.net/static/6009.php

Description:
Buffer overflow in www.tol module in America Online (AOL) 5.0 may allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long URL in a link.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Cole, Ziese
   REVIEWING(2) Wall, Bishop

CAN-2001-0315

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010125 mIRC allows password protection to be bypassed
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98053777917287&w=2
Reference: XF:mirc-bypass-password
Reference: URL:http://xforce.iss.net/static/6013.php

Description:
The locking feature in mIRC 5.7 allows local users to bypass the password mechanism by modifying the LockOptions registry key.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0320

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010223 Yet another hole in PHP-Nuke
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0425.html

Description:
bb_smilies.php and bbcode_ref.php in PHP-Nuke 4.4 allows remote attackers to read arbitrary files and gain PHP administrator privileges by inserting a null character and .. (dot dot) sequences into a malformed username argument.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Bishop, Ziese
Voter Comments:
 Frech> XF:php-nuke-elevate-privileges(6183)
 CHANGE> [Bishop changed vote from REVIEWING to NOOP]


CAN-2001-0322

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010115 Stack Overflow in MSHTML.DLL
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97958685100219&w=2
Reference: BID:2202
Reference: URL:http://www.securityfocus.com/bid/2202
Reference: XF:ie-mshtml-dos
Reference: URL:http://xforce.iss.net/static/5938.php

Description:
MSHTML.DLL HTML parser in Internet Explorer 4.0, and other versions, allows remote attackers to cause a denial of service (application crash) via a script that creates and deletes an object that is associated with the browser window object.

Votes:

   ACCEPT(1) Frech
   NOOP(2) Cole, Ziese
   REJECT(1) LeBlanc
   REVIEWING(2) Wall, Bishop
Voter Comments:
 LeBlanc> I don't believe that EX-CLIENT-DOS issues should be included
   in CVE.


CAN-2001-0323

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010115 ICMP fragmentation required but DF set problems.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=97958349623450&w=2
Reference: XF:icmp-pmtu-dos
Reference: URL:http://xforce.iss.net/static/5975.php

Description:
The ICMP path MTU (PMTU) discovery feature in various UNIX systems allows remote attackers to cause a denial of service by spoofing "ICMP Fragmentation needed but Don't Fragment (DF) set" packets between two target hosts, which could cause one host to lower its MTU when transmitting to the other host.

Votes:

   ACCEPT(2) Meunier, Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Christey> (prompted from Pascal Meunier) should this be treated
   as a general design issue with ICMP?  Or is it a specific
   implementation flaw that only affects Reliant?
 Meunier> It seems obvious that if one sets the MTU to just one byte
   above the size of a IP header (let's say 21 bytes), data transmission
   is not going to go anywhere fast, as the overhead will be 20 times the
   payload...  As I said for another candidate, ICMP messages should not
   be acted upon without access control.  I'm not sure that references to
   UNIX should be kept.  It seems that this should work with any OS.  It
   would be nasty if some OSes accepted an MTU of 20, as you could not
   transmit any IP data.


CAN-2001-0324

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010206 Windows client UDP exhaustion denial of service
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2001-q1/0060.html
Reference: BID:2340
Reference: URL:http://www.securityfocus.com/bid/2340

Description:
Windows 98 and Windows 2000 Java clients allow remote attackers to cause a denial of service via a Java applet that opens a large number of UDP sockets, which prevents the host from establishing any additional UDP connections, and possibly causes a crash.

Votes:

   MODIFY(1) Frech
   NOOP(2) Cole, Ziese
   RECAST(1) LeBlanc
   REVIEWING(3) Wall, Baker, Bishop
Voter Comments:
 LeBlanc> Sun's Java specification does not provide for limits on the
   number of sockets that can be opened. We didn't write the spec, we just
   implemented it. Aside from the issue of EX-CLIENT-DOS issues noted in my
   comments on CAN-2001-0322, the vuln would need to be recast to show that
   the actual problem lies in Java. If the description is recast to show
   that the issue is in Sun's Java specification, then please change my
   vote to NOOP, as per the "don't vote on issues with other vendors" rule.
 Frech> XF:win-udp-dos(6070)


CAN-2001-0325

Phase: Proposed (20010404)
Reference: BUGTRAQ:20010202 QNX RTP ftpd stack overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0031.html
Reference: BID:2342
Reference: URL:http://www.securityfocus.com/bid/2342

Description:
Buffer overflow in QNX RTP 5.60 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a large number of arguments to the stat command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:qnx-rtp-ftpd-bo(6442)


CAN-2001-0328

Phase: Proposed (20010524)
Reference: CERT:CA-2001-09
Reference: URL:http://www.cert.org/advisories/CA-2001-09.html

Description:
TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform session hijacking or disruption by injecting a flood of packets with a range of ISN values, one of which may match the expected ISN.

Votes:

   ACCEPT(7) Wall, Cole, Baker, Ziese, Renaud, Magdych, Williams
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:tcp-seq-predict(139)
 Christey> It could be argued that this is a "class" of vulnerability in which
   several stacks have the problem.
   Also need to add references.
 Christey> Consider adding BID:2682
 Christey> HP:HPSBUX0207-205
   URL:http://archives.neohapsis.com/archives/hp/2002-q3/0031.html
 Christey> COMPAQ:SSRT-547
   URL:http://archives.neohapsis.com/archives/tru64/2002-q3/0017.html
   HP:HPSBUX0207-205
   URL:http://archives.neohapsis.com/archives/hp/2002-q3/0031.html


CAN-2001-0329

Phase: Modified (20011130)
Reference: ATSTAKE:A043001-1
Reference: URL:http://www.atstake.com/research/advisories/2001/a043001-1.txt
Reference: CONFIRM:http://www.mozilla.org/projects/bugzilla/security2_12.html
Reference: BID:1199
Reference: URL:http://www.securityfocus.com/bid/1199

Description:
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzilla_login cookie in post_bug.cgi, or (2) the who parameter in process_bug.cgi.

Votes:

   ACCEPT(4) Cole, Baker, Renaud, Williams
   MODIFY(1) Frech
   NOOP(2) Wall, Ziese
   RECAST(1) Christey
Voter Comments:
 Christey> CONFIRM:http://www.mozilla.org/projects/bugzilla/security2_12.html
 Frech> XF:bugzilla-email-shell-characters(6488)
 CHANGE> [Christey changed vote from NOOP to RECAST]
 Christey> This needs to be MERGED with CVE-2000-0421.
   CVE-2000-0421 documents a problem in the "who" parameter of
   the process_bug.cgi program.  This is a duplicate of one of the
   problems being identified by CAN-2001-0329.  The other problem 
   in CAN-2001-0329, the Bugzilla_login cookie, is fixed in
   the same version as the who problem is.  CD:SF-EXEC
   suggests merging multiple executables in the same package
   that have the same problem that is present in the same version.
   Both the "who" and "Bugzilla_login" problems were fixed in
   version 2.12.  Therefore CVE-2000-0241 and CAN-2001-0329
   need to be MERGED.
   
   CHANGEREF BID:1199


CAN-2001-0332

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010330 Security bug in Internet Explorer - MSScriptControl.ScriptControl
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98609031517525&w=2
Reference: MS:MS01-027
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-027.asp

Description:
Internet Explorer 5.5 and earlier does not properly verify the domain of a frame within a browser window, which allows remote web site operators to read certain files on the client by sending information from a local frame to a frame in a different domain using MSScriptControl.ScriptControl and GetObject, aka a variant of the "Frame Domain Verification" vulnerability.

Votes:

   ACCEPT(4) Wall, Cole, Baker, Ziese
   MODIFY(1) Frech
   NOOP(1) Renaud
   RECAST(1) Williams
   REJECT(1) Magdych
   REVIEWING(1) Christey
Voter Comments:
 Magdych> Duplicate of CAN-0246
 Christey> While it may look like CAN-2001-0332 is a duplicate of
   CAN-2001-0246, Microsoft specifically identifies two separate
   variants of the same problem in its advisory, namely 0332 and
   0246.  However, CD:SF-LOC currently suggests merging problems
   of the same type that appear and are fixed in the same
   software versions, and thus these 2 candidates *might*
   in fact be duplicates - relative to CD:SF-LOC.  Microsoft
   needs to be consulted on this.
 Williams> merge with CAN-0246
 Frech> XF:ie-frame-verification-read-files(6086)
   XF:ie-frame-verification-variant(6748)
   CAN-2001-0092 is also assigned to the
   ie-frame-verification-files(6086), but shouldn't be considered a
   duplicate.


CAN-2001-0337

Phase: Proposed (20010524)
Reference: MS:MS01-026
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-026.asp

Description:
The Microsoft MS01-014 and MS01-016 patches for IIS 5.0 and earlier introduce a memory leak which allows attackers to cause a denial of service via a series of requests.

Votes:

   ACCEPT(6) Wall, Cole, Baker, Ziese, Renaud, Williams
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:iis-webdav-lock-dos(6549)
 Christey> ADDREF? BID:2736
   URL:http://www.securityfocus.com/bid/2736
   ADDREF? BUGTRAQ:20010517 def-2001-26: IIS WebDav Lock Method Memory Leak DoS 
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0170.html


CAN-2001-0342

Phase: Assigned (20010516)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0343

Phase: Assigned (20010516)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0349

Phase: Proposed (20010727)
Reference: MS:MS01-031
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp

Description:
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.

Votes:

   ACCEPT(7) Wall, Foat, Cole, Armstrong, Stracener, Ziese, Balinsky
   MODIFY(1) Frech
   REVIEWING(1) Christey
Voter Comments:
 CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT]
 Balinsky> Need to decide whether this and 2001-350 one or two vuls, but it is definitely valid.
 Frech> XF:win2k-telnet-pipe-privileges(6664)
 Christey> CIAC:L-092
   URL:http://www.ciac.org/ciac/bulletins/l-092.shtml
 Christey> Consider adding BID:2849
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> CERT-VN:VU#587587
   URL:http://www.kb.cert.org/vuls/id/587587
   BID:2849
   Microsoft identifies two separate vulnerabilities that are extremely
   similar, but the security bulletin states that "The two
   vulnerabilities differ primarily in the way they exploit the
   underlying problem regarding named pipe creation."  So, it may be
   necessary to merge CAN-2001-0350 with CAN-2001-0349.
   
   If one issue is because of predictable names, and another
   issue is because pipe ownership isn't properly verified, then
   these could stay SPLIT, and the descriptions should be
   modified accordingly.


CAN-2001-0350

Phase: Proposed (20010727)
Reference: MS:MS01-031
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp

Description:
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Ziese, Balinsky
   MODIFY(1) Frech
   RECAST(1) Stracener
   REVIEWING(2) Wall, Christey
Voter Comments:
 Wall> Perhaps merge 0349 and 0350 unless there is a bigger difference.
 Stracener> Merge this with 0349.
 Frech> XF:win2k-telnet-pipe-privileges(6664)
 Christey> CIAC:L-092
   URL:http://www.ciac.org/ciac/bulletins/l-092.shtml
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> CERT-VN:VU#587587
   URL:http://www.kb.cert.org/vuls/id/587587
   BID:2849
   Microsoft identifies two separate vulnerabilities that are extremely
   similar, but the security bulletin states that "The two
   vulnerabilities differ primarily in the way they exploit the
   underlying problem regarding named pipe creation."  So, it may be
   necessary to merge CAN-2001-0350 with CAN-2001-0349.
   
   If one issue is because of predictable names, and another
   issue is because pipe ownership isn't properly verified, then
   these could stay SPLIT, and the descriptions should be
   modified accordingly.


CAN-2001-0352

Phase: Proposed (20010727)
Reference: ISS:20010620 Wired-side SNMP WEP key exposure in 802.11b Access Points

Description:
SNMP agents in 3Com AirConnect AP-4111 and Symbol 41X1 Access Point allow remote attackers to obtain the WEP encryption key by reading it from a MIB when the value should be write-only, via (1) dot11WEPDefaultKeyValue in the dot11WEPDefaultKeysTable of the IEEE 802.11b MIB, or (2) ap128bWepKeyValue in the ap128bWEPKeyTable in the Symbol MIB.

Votes:

   ACCEPT(3) Cole, Stracener, Ziese
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Armstrong, Christey
Voter Comments:
 Frech> XF:3com-ap-wep-key(6232)
 Christey> BID:2899
   URL:http://www.securityfocus.com/bid/2899


CAN-2001-0354

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010420 CheckBO Win9x memo overflow
Reference: URL:http://www.securityfocus.com/archive/1/178061
Reference: BID:2634
Reference: URL:http://www.securityfocus.com/bid/2634

Description:
TheNet CheckBO 1.56 allows remote attackers to cause a denial of service via a flood of characters to the TCP ports which it is listening on.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:checkbo-tcp-bo(6436)


CAN-2001-0355

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010210 Novell Groupwise Client Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98185226715517&w=2

Description:
Novell Groupwise 5.5 (sp1 and sp2) allows a remote user to access arbitrary files via an implementation error in Groupwise system policies.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Wall, Ziese, Oliver
Voter Comments:
 Frech> XF:novell-groupwise-bypass-policies(6089)


CAN-2001-0357

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010310 CORRECTION to CODE: FormMail.pl can be used to send anonymous email
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98433523520344&w=2
Reference: XF:formmail-anonymous-flooding
Reference: URL:http://xforce.iss.net/static/6242.php

Description:
FormMail.pl in FormMail 1.6 and earlier allows a remote attacker to send anonymous email (spam) by modifying the recipient and message paramaters.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(6) Wall, Foat, Cole, Christey, Bishop, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Baker> http://www.securityfocus.com/archive/1/168177
   http://www.securityfocus.com/archive/1/168292
   http://www.securityfocus.com/archive/1/168366
   http://www.securityfocus.com/archive/1/168345
   http://www.securityfocus.com/archive/1/168302
   http://www.securityfocus.com/archive/1/168360
   http://www.securityfocus.com/archive/1/168633
   
   I think from the discussion on the Bugtraq list, there is sufficient verfication that this
   is a real problem, and well-known.  There are a couple of work arounds
   described in the posts, so this should be accepted.
 Christey> Fix typo: "paramaters"
 Christey> Fix typo: "paramater"
 Christey> The following references discuss this problem and/or later
   variants of it, up to version 1.9.
   MISC:http://www.softwolves.pp.se/misc/formmail_hall_of_shame
   MISC:http://www.monkeys.com/anti-spam/formmail-advisory.pdf
   MISC:http://www.scriptarchive.com/readme/formmail.html


CAN-2001-0358

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html
Reference: XF:halflife-config-file-bo
Reference: URL:http://xforce.iss.net/static/6221.php
Reference: XF:halflife-map-bo
Reference: URL:http://xforce.iss.net/static/6218.php

Description:
Buffer overflows in Sierra Half-Life build 1573 and earlier allow remote attackers to execute arbitrary code via (1) a long map command, (2) a long exec command, or (3) long input in a configuration file.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(3) Wall, Ziese, Oliver

CAN-2001-0359

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010309 Advisory: Half-life server buffer overflows and formatting vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0111.html
Reference: XF:halflife-map-format-string
Reference: URL:http://xforce.iss.net/static/6220.php

Description:
Format string vulnerability in Sierra Half-Life build 1573 and earlier allows a remote attacker to execute arbitrary code via the map command.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(3) Wall, Ziese, Oliver

CAN-2001-0360

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010311 Ikonboard v2.1.7b "show files" vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0124.html
Reference: BID:2471
Reference: URL:http://www.securityfocus.com/bid/2471
Reference: XF:ikonboard-cgi-read-files
Reference: URL:http://xforce.iss.net/static/6216.php

Description:
Directory traversal vulnerability in help.cgi in Ikonboard 2.1.7b and earlier allows a remote attacker to read arbitary files via a .. (dot dot) attack in the helpon parameter.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(3) Wall, Ziese, Oliver

CAN-2001-0367

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010428 Mirabilis ICQ WebFront Plug-in Denial of Service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98847544303438&w=2
Reference: BID:2664
Reference: URL:http://www.securityfocus.com/bid/2664

Description:
Mirabilis ICQ WebFront Plug-in ICQ2000b Build 3278 allows a remote attacker to create a denial of service via HTTP URL requests containing a large number of % characters.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Ziese, Oliver
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:icq-webfront-dos(6474)
   In description, product name is spelled "Web Front" (2
   words). See http://www.icq.com/hpf/


CAN-2001-0369

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010319 DGUX lpsched buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98511407131984&w=2
Reference: XF:dgux-lpsched-bo
Reference: URL:http://xforce.iss.net/static/6258.php

Description:
Buffer overflow in lpsched on DGUX version R4.20MU06 and MU02 allows a local attacker to obtain root access via a long command line argument (non-existent printer name).

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Cole, Ziese, Oliver

CAN-2001-0370

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010320 fcheck prior to 2.07.59 - vulnerability - improper use of perl 'magic open'
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98521301510554&w=2
Reference: XF:fcheck-open-execute-commands
Reference: URL:http://xforce.iss.net/static/6256.php

Description:
fcheck prior to 2.57.59 calls the file signature checking program insecurely, which can allow a local user to run arbitrary commands via a file name that contains shell metacharacters.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Cole, Ziese, Oliver

CAN-2001-0372

Phase: Modified (20010910-01)
Reference: BUGTRAQ:20010323 FW: Akopia Interchange E-commerce Package Demo Files Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0337.html
Reference: CONFIRM:http://lists.akopia.com/pipermail/interchange-announce/2001/000009.html
Reference: BID:2499
Reference: URL:http://www.securityfocus.com/bid/2499
Reference: XF:akopia-interchange-gain-access(6273)
Reference: URL:http://xforce.iss.net/static/6273.php

Description:
Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.

Votes:

   ACCEPT(4) Cole, Baker, Frech, Ziese
   NOOP(2) Wall, Oliver

CAN-2001-0374

Phase: Proposed (20010524)
Reference: COMPAQ:SSRT0715
Reference: URL:http://www.compaq.com/products/servers/management/mgtsw-advisory.html
Reference: BUGTRAQ:20010322 Compaq Insight Manager Proxy Vuln
Reference: URL:http://archives.neohapsis.com/archives/vuln-dev/2001-q1/0779.html
Reference: XF:compaq-wbm-bypass-proxy
Reference: URL:http://xforce.iss.net/static/6264.php

Description:
The HTTP server in Compaq web-enabled management software for (1) Foundation Agents, (2) Survey, (3) Power Manager, (4) Availability Agents, (5) Intelligent Cluster Administrator, and (6) Insight Manager can be used as a generic proxy server, which allows remote attackers to bypass access restrictions via the management port, 2301.

Votes:

   ACCEPT(4) Cole, Baker, Frech, Ziese
   NOOP(2) Wall, Oliver

CAN-2001-0375

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010406 PIX Firewall 5.1 DoS Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98658271707833&w=2

Description:
Cisco PIX Firewall 515 and 520 with 5.1.4 OS running aaa authentication to a TACACS+ server allows a remote attacker to cause a denial of service via a large number (approximately 426) of authentication requests.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:cisco-pix-tacacs-dos(6353)
 Christey> CISCO:20011003 Cisco PIX Firewall Authentication Denial of Service Vulnerability
   URL:http://www.cisco.com/warp/public/707/pixfirewall-authen-flood-pub.shtml


CAN-2001-0376

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010327 SonicWall IKE pre-shared key length bug and security concern
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0403.html
Reference: XF:sonicwall-ike-shared-keys
Reference: URL:http://xforce.iss.net/static/6304.php

Description:
SonicWALL Tele2 and SOHO firewalls with 6.0.0.0 firmware using IPSEC with IKE pre-shared keys do not allow for the use of full 128 byte IKE pre-shared keys, which is the intended design of the IKE pre-shared key, and only support 48 byte keys. This allows a remote attacker to brute force attack the pre-shared keys with significantly less resources than if the full 128 byte IKE pre-shared keys were used.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Cole, Ziese

CAN-2001-0380

Phase: Proposed (20010524)
Reference: BUGTRAQ:200103 ILMI community in olicom/crosscomm routers
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0364.html

Description:
Crosscom/Olicom XLT-F running XL 80 IM Version 5.5 Build Level 2 allows a remote attacker SNMP read and write access via a default, undocumented community string 'ILMI'.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
Voter Comments:
 Frech> XF:cisco-ios-modify-snmp(6169)
 Christey> Fix the date of the Bugtraq post
 Christey> The Bugtraq poster didn't provide many details, but said that
   the vendor was out of business.  It's possible that this ILMI
   community string has no relationship with the Cisco ILMI
   problem, in which case this should remain a separate CAN.


CAN-2001-0381

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010319 Have they found a serious PGP vulnerability?!
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0252.html
Reference: BUGTRAQ:20010320 Yes, they have found a serious PGP vulnerability...sort of
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0274.html
Reference: BUGTRAQ:20010322 Re: Yes, they have found a serious PGP vulnerability...sort of
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0311.html

Description:
The OpenPGP PGP standard allows an attacker to determine the private signature key via a cryptanalytic attack in which the attacker alters the encrypted private key file and captures a single message signed with the signature key.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Oliver
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:openpgp-private-key-disclosure(6558)
 Christey> Consider CALDERA:CSSA-2001-017.0
   URL:http://www.caldera.com/support/security/advisories/CSSA-2001-017.0.txt
   Also http://www.redhat.com/support/errata/RHSA-2001-063.html
   Add that gnupg before 1.0.5-3 is affected.
   TURBO:TLSA2001028
   http://www.turbolinux.com/pipermail/tl-security-announce/2001-June/000439.html


CAN-2001-0382

Phase: Proposed (20010524)
Reference: NTBUGTRAQ:20010327 CA CCC\Harvest exploit
Reference: URL:http://archives.neohapsis.com/archives/ntbugtraq/2001-q2/0001.html

Description:
Computer Associates CCC\Harvest 5.0 for Windows NT/2000 uses weak encryption for passwords, which allows a remote attacker to gain privileges on the application.

Votes:

   MODIFY(1) Frech
   NOOP(2) Cole, Ziese
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:cccharvest-weak-encryption(6314)
   Product name is CCC/Harvest (forward slash); see
   http://ca.com/products/descriptions/ccc_harvest.pdf.


CAN-2001-0384

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010414 Re: Reliant Unix 5.43 / 5.44 ICMP port unreachable problem
Reference: URL:http://www.securityfocus.com/archive/1/176709
Reference: BID:2606
Reference: URL:http://www.securityfocus.com/bid/2606

Description:
ppd in Reliant Sinix allows local users to corrupt arbitrary files via a symlink attack in the /tmp/ppd.trace file.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Ziese, Renaud
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:reliant-unix-ppd-symlink(6408)


CAN-2001-0385

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010417 Advisory for GoAhead Webserver v2.1
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0281.html
Reference: BID:2607
Reference: URL:http://www.securityfocus.com/bid/2607

Description:
GoAhead webserver 2.1 allows remote attackers to cause a denial of service via an HTTP request to the /aux directory.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:goahead-aux-dos(6400)


CAN-2001-0389

Phase: Proposed (20010524)
Reference: BID:2587
Reference: URL:http://www.securityfocus.com/bid/2587
Reference: BUGTRAQ:20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.
Reference: URL:http://www.securityfocus.com/archive/1/176100

Description:
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:ibm-websphere-reveals-path(6371)


CAN-2001-0390

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010413 [LoWNOISE] IBM Websphere/NetCommerce3 DoS and one more.
Reference: URL:http://www.securityfocus.com/archive/1/176100
Reference: BID:2588
Reference: URL:http://www.securityfocus.com/bid/2588

Description:
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:ibm-websphere-macro-dos(6372)


CAN-2001-0391

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010417 Advisory for Xitami 2.4d7, 2.5d4
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0277.html

Description:
Xitami 2.5d4 and earlier allows remote attackers to crash the server via an HTTP request to the /aux directory.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:xitami-server-dos(6389)
 Christey> Consider adding BID:2622


CAN-2001-0392

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010403 def-2001-17: Navision Financials Server DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98633100728473&w=2
Reference: BID:2539
Reference: URL:http://www.securityfocus.com/bid/2539

Description:
Navision Financials Server 2.60 and earlier allows remote attackers to cause a denial of service by sending a null character and a long string to the server port (2407), which causes the server to crash.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:navision-server-dos(6318)


CAN-2001-0393

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010404 Re: def-2001-17: Navision Financials Server DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637870623514&w=2

Description:
Navision Financials Server 2.0 allows remote attackers to cause a denial of service via a series of connections to the server without providing a username/password combination, which consumes the license limits.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:navision-license-dos(6624)


CAN-2001-0395

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010410 Console 3200 telnetd problem.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html
Reference: BID:2578
Reference: URL:http://www.securityfocus.com/bid/2578

Description:
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:lightwave-consoleserver-brute-force(6345)


CAN-2001-0396

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010410 Console 3200 telnetd problem.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0170.html
Reference: BID:2578
Reference: URL:http://www.securityfocus.com/bid/2578

Description:
The pre-login mode in the System Administrator interface of Lightwave ConsoleServer 3200 allows remote attackers to obtain sensitive information such as system status, configuration, and users.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:lightwave-consoleserver-brute-force(6345)


CAN-2001-0397

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010329 Silent Runner Collector - HELO buffer overflow vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0454.html

Description:
Buffer overflow in Silent Runner Collector (SRC) 1.6.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long SMTP HELO command.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:silent-runner-helo-bo(6309)
   In description, product is called SilentRunner (no space).
   See http://www.silentrunner.com/index.html.


CAN-2001-0398

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010402 ~..~!guano
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0013.html
Reference: BID:2530
Reference: URL:http://www.securityfocus.com/bid/2530

Description:
The BAT! mail client allows remote attackers to bypass user warnings of an executable attachment and execute arbitrary commands via an attachment whose file name contains many spaces, which also causes the BAT! to misrepresent the attachment's type with a different icon.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Wall, Christey, Ziese
Voter Comments:
 Frech> XF:thebat-masked-file-type(6324)
 Christey> Add affected version: 1.51 was reported in the original post.


CAN-2001-0399

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010403 CHINANSL Security Advisory(CSA-200111)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98633597813833&w=2
Reference: BID:2533
Reference: URL:http://www.securityfocus.com/bid/2533

Description:
Caucho Resin 1.3b1 and earlier allows remote attackers to read source code for Javabean files by inserting a .jsp before the WEB-INF specifier in an HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:resin-view-javabean(6320)


CAN-2001-0400

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010410 CGI - nph-maillist.pl vulnerability...
Reference: URL:http://www.securityfocus.com/archive/1/175506
Reference: BID:2563
Reference: URL:http://www.securityfocus.com/bid/2563

Description:
nph-maillist.pl allows remote attackers to execute arbitrary commands via shell metacharacters ("`") in the email address.

Votes:

   ACCEPT(1) Williams
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:nph-maillist-execute-code(6363)


CAN-2001-0401

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010327 Solaris /usr/bin/tip Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0394.html
Reference: XF:solaris-tip-bo
Reference: URL:http://xforce.iss.net/static/6284.php

Description:
Buffer overflow in tip in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.

Votes:

   ACCEPT(2) Dik, Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Dik> sun bug: 4330475


CAN-2001-0403

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010323 [ Hackerslab bug_paper ] SunOS application perfmon vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0326.html
Reference: XF:solaris-perfmon-create-files
Reference: URL:http://xforce.iss.net/static/6267.php

Description:
/opt/JSparm/bin/perfmon program in Solaris allows local users to create arbitrary files as root via the Logging File option in the GUI.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(3) Wall, Cole, Ziese

CAN-2001-0404

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010328 CHINANSL Security Advisory(CSA-200106)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98583089425166&w=2

Description:
Directory traversal vulnerability in JavaServer Web Dev Kit (JSWDK) 1.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request to the WEB-INF directory.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:jswdk-directory-traversal(6312)


CAN-2001-0406

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010417 Samba 2.0.8 security fix
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0305.html
Reference: DEBIAN:DSA-048
Reference: URL:http://www.debian.org/security/2001/dsa-048
Reference: CALDERA:CSSA-2001-015.0
Reference: URL:http://www.caldera.com/support/security/advisories/CSSA-2001-015.0.txt
Reference: BUGTRAQ:20010418 TSLSA-#2001-0005 - samba
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0319.html
Reference: BUGTRAQ:20010418 PROGENY-SA-2001-05: Samba /tmp vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0326.html
Reference: CONECTIVA:CLA-2001:395
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000395
Reference: FREEBSD:FreeBSD-SA-01:36
Reference: URL:http://archives.neohapsis.com/archives/freebsd/2001-04/0608.html
Reference: MANDRAKE:MDKSA-2001:040
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-040.php3

Description:
Samba before 2.2.0 allows local attackers to overwrite arbitrary files via a symlink attack using (1) a printer queue query, (2) the more command in smbclient, or (3) the mput command in smbclient.

Votes:

   ACCEPT(5) Cole, Prosser, Baker, Ziese, Williams
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:samba-tmpfile-symlink(6396)
 Christey> note to self: double-check related submissions to ensure that
   all references are complete
 Christey> ADDREF RHSA-2001:044 (per Mark Cox of Red Hat)
 Christey> Add "2.0.8 and earlier" to description; problem was fixed in
   2 different versions, and initial 2.0.8 fixes were incorrect.
   BUGTRAQ:20010508 Samba 2.0.9 released - 2.0.8 did NOT fix the hole
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0061.html
   IMMUNIX:IMNX-2001-70-019-01
   BUGTRAQ:20010525 TSLSA-2001-0006: Samba
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0242.html
   CALDERA:CSSA-2001-018.0
   URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-018.0.txt


CAN-2001-0410

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010330 Virus Buster 2001(ver8.02) Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98593642520755&w=2

Description:
Buffer overflow in Trend Micro Virus Buster 2001 8.02 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long "From" header.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:virusbuster-mua-bo(6034)
   Possible
   CONFIRM:http://www.securityfocus.com/archive/1/173231, but Trend URL
   in message was currently down.
   Possible close-match or duplicate with CAN-2001-0174 (most likely
   this is a level-of-abstraction issue).


CAN-2001-0411

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010406 Reliant Unix 5.43 / 5.44 ICMP port unreachable problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98658209505849&w=2

Description:
Reliant Unix 5.44 and earlier allows remote attackers to cause a denial of service via an ICMP port unreachable packet, which causes Reliant to drop all connections to the source address of the packet.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REJECT(1) Meunier
Voter Comments:
 Frech> XF:reliant-unix-ppd-symlink(6408)
 Frech> Change to reliant-unix-icmp-dos(6646)
 Christey> (prompted from Pascal Meunier) should this be treated
   as a general design issue with ICMP?  Or is it a specific
   implementation flaw that only affects Reliant?
 Meunier> lower level (more precise) duplicate or sub-class of high
   level description CVE-1999-0214


CAN-2001-0415

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010320 Password stored in clear text vulnerability in real time stock trading program
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0275.html
Reference: BID:2495
Reference: URL:http://www.securityfocus.com/bid/2495
Reference: XF:rediplus-weak-security
Reference: URL:http://xforce.iss.net/static/6276.php

Description:
REDIPlus program, REDI.exe, stores passwords and user names in cleartext in the StartLog.txt log file, which allows local users to gain access to other accounts.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(3) Oliver, Wall, Ziese

CAN-2001-0417

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010307 Security advisory: Unsafe temporary file handling in krb4
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0078.html
Reference: REDHAT:RHSA-2001:025
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-025.html

Description:
Kerberos 4 (aka krb4) allows local users to overwrite arbitrary files via a symlink attack on new ticket files.

Votes:

   ACCEPT(3) Cole, Baker, Ziese
   NOOP(1) Wall
   REJECT(3) Oliver, Christey, Frech
Voter Comments:
 Frech> DUPLICATE OF CAN-2001-0036: KTH Kerberos IV allows local users to
   overwrite arbitrary files via a symlink attack on a ticket file. 
 Oliver> Appears to be a subset of CVE-2001-036.
 Christey> Change description to point out that the Kerberos 5 package is
   affected.
   FREEBSD:FreeBSD-SA-01:25
   Also ensure that the other problems described in the FreeBSD
   advisory have CANs/CVEs.
 CHANGE> [Christey changed vote from NOOP to REJECT]
 Christey> Agree that these are dupes.  Since CVE-2001-0036 is already
   an official CVE entry, this candidate will be rejected.
   This CAN's references will be added to CVE-2001-0036.


CAN-2001-0418

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010413 Exploitable NCM.at - Content Management System
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0223.html
Reference: BID:2584
Reference: URL:http://www.securityfocus.com/bid/2584

Description:
content.pl script in NCM Content Management System allows remote attackers to read arbitrary contents of the content database by inserting SQL characters into the id parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:ncm-content-database-access(6386)


CAN-2001-0419

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010410 Oracle Application Server shared library buffer overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98692227816141&w=2
Reference: BID:2569
Reference: URL:http://www.securityfocus.com/bid/2569

Description:
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:oracle-appserver-ndwfn4-bo(6334)
 Christey> At http://otn.oracle.com/deploy/security/alerts.htm,
   in an item titled "Oracle Application Server Buffer Overflow,"
   Oracle says that it was "Unable to reproduce vulnerability"


CAN-2001-0420

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010409 talkback.cgi vulnerability may allow users to read any file
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0128.html
Reference: BID:2547
Reference: URL:http://www.securityfocus.com/bid/2547

Description:
Directory traversal vulnerability in talkback.cgi program allows remote attackers to read arbitrary files via a .. (dot dot) in the article parameter.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
Voter Comments:
 Frech> XF:talkback-cgi-read-files(6340)
 Christey> BID:2547
   URL:http://www.securityfocus.com/bid/2547


CAN-2001-0421

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010417 Re: SUN SOLARIS 5.6/5.7 FTP Globbing Exploit !
Reference: URL:http://www.securityfocus.com/archive/1/177200
Reference: BID:2601
Reference: URL:http://www.securityfocus.com/bid/2601

Description:
FTP server in Solaris 8 and earlier allows local and remote attackers to cause a core dump in the root directory, possibly with world-readable permissions, by providing a valid username with an invalid password followed by a CWD ~ command, which could release sensitive information such as shadowed passwords, or fill the disk partition.

Votes:

   ACCEPT(1) Cole
   MODIFY(2) Dik, Frech
   NOOP(1) Wall
   REVIEWING(2) Ziese, Williams
Voter Comments:
 Frech> XF:solaris-ftp-shadow-recovery(6422)
 Dik> sun bug ids: 4436988
   
   The "world-readable" core dump problem does not exist in
   Solaris 8 and other Solaris releases which have been patched
   to include the "coreadm" command and possibly earlier (many release
   have been patched to avoid core dumps in more situations and
   always make them mode 0600)
   
   Solaris 8 was the first release to contain coreadm initially
   (backported and include in 2.6 & 7)
   Solaris 7 was the first release to make core dumps mode 0600.
   (fix backported to 2.6 and earlier)


CAN-2001-0423

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010412 Solaris ipcs vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0217.html
Reference: BID:2581
Reference: URL:http://www.securityfocus.com/bid/2581

Description:
Buffer overflow in ipcs in Solaris 7 x86 allows local users to execute arbitrary commands via a long TZ (timezone) environmental variable.

Votes:

   ACCEPT(1) Dik
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
   REVIEWING(2) Ziese, Williams
Voter Comments:
 Frech> XF:solaris-ipcs-bo(6369)
 Dik> sun bug: 4448598
 Christey> This might be a duplicate of CAN-2002-0093, which is for
   Compaq IPCS.


CAN-2001-0424

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010415 BubbleMon 1.31
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98744422105430&w=2
Reference: BID:2609
Reference: URL:http://www.securityfocus.com/bid/2609

Description:
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:bubblemon-elevate-privileges(6378)


CAN-2001-0425

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010219 Adcycle 0.78b Authentication
Reference: URL:http://www.securityfocus.com/archive/1/163942
Reference: BID:2393
Reference: URL:http://www.securityfocus.com/bid/2393

Description:
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the HTTP request, which is inserted into a resulting SQL query that is used to verify login information.

Votes:

   MODIFY(1) Frech
   NOOP(4) Oliver, Wall, Cole, Ziese
Voter Comments:
 Frech> XF:adcycle-adlibrarypm-unauthorized-access(6618)


CAN-2001-0426

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010411 [LSD] Solaris kcsSUNWIOsolf.so and dtsession vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0203.html

Description:
Buffer overflow in dtsession on Solaris, and possibly other operating systems, allows local users to gain privileges via a long LANG environmental variable.

Votes:

   ACCEPT(1) Dik
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:solaris-dtsession-bo(6366)
 Dik> sun bug: 4448598


CAN-2001-0431

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010417 iPlanet Web Server 4.x Product Alert
Reference: URL:http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html
Reference: CONFIRM:http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert4.16.html

Description:
Vulnerability in iPlanet Web Server Enterprise Edition 4.x.

Votes:

   ACCEPT(3) Cole, Baker, Ziese
   NOOP(1) Wall
   REJECT(1) Frech
Voter Comments:
 Frech> Duplicate of CAN-2001-0327.


CAN-2001-0432

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010413 Trend Micro Interscan VirusWall 3.01 vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0218.html
Reference: BID:2579
Reference: URL:http://www.securityfocus.com/bid/2579

Description:
Buffer overflows in various CGI programs in the remote administration service for Trend Micro Interscan VirusWall 3.01 allow remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(1) Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:interscan-viruswall-isadmin-bo(6368)


CAN-2001-0433

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010405 Savant 3.0 Denial Of Service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98655083231635&w=2

Description:
Buffer overflow in Savant 3.0 web server allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long Host HTTP header.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:savant-get-bo(4901)
 Christey> Should CAN-2002-0099 and/or CAN-2001-0433 be MERGED with
   CVE-2000-0641?  All describe slightly different overflows
   that, perhaps, should be merged according to CD:SF-LOC.
   It depends on which versions are affected, which would require
   some vendor acknowledgement or consultation.
   
   A vague changelog for version 3.1 at
   http://sourceforge.net/project/shownotes.php?release_id=75333 says
   "security fixes" but it's not clear *which* security fixes
   were made.
   
   The description for CVE-2000-0641 is slightly incorrect.  The
   exploit is clearly due to a large number of headers, not
   arguments to the GET request itself.  So, CVE-2000-0641
   clearly overlaps with CAN-2001-0433.
   
   The exploit for CAN-2001-0433 also doesn't really have
   anything to do with a "cgi-test.pl" program (which isn't in
   the distribution).  The discloser simply used that as an
   example program of a long request.


CAN-2001-0435

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010410 [wsir-01/02-03] PGP 7.0 Split Key/Cached Passphrase Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98691775527457&w=2

Description:
The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REVIEWING(1) Ziese
Voter Comments:
 Frech> XF:nai-pgp-split-keys(6341)


CAN-2001-0436

Phase: Interim (20010911)
Reference: BUGTRAQ:20010416 qDefense Advisory: DCForum allows remote read/write/execute
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html
Reference: CONFIRM:http://www.dcscripts.com/FAQ/sec_2001_03_31.html
Reference: XF:dcforum-az-expr(6392)
Reference: URL:http://xforce.iss.net/static/6392.php
Reference: BID:2611
Reference: URL:http://www.securityfocus.com/bid/2611

Description:
dcboard.cgi in DCForum 2000 1.0 allows remote attackers to execute arbitrary commands by uploading a Perl program to the server and using a .. (dot dot) in the AZ parameter to reference the program.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:dcforum-az-expr(6392)


CAN-2001-0437

Phase: Interim (20010911)
Reference: BUGTRAQ:20010416 qDefense Advisory: DCForum allows remote read/write/execute
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0269.html
Reference: CONFIRM:http://www.dcscripts.com/FAQ/sec_2001_03_31.html
Reference: BID:2611
Reference: URL:http://www.securityfocus.com/bid/2611
Reference: XF:dcforum-az-file-upload(6393)
Reference: URL:http://xforce.iss.net/static/6393.php

Description:
upload_file.pl in DCForum 2000 1.0 allows remote attackers to upload arbitrary files without authentication by setting the az parameter to upload_file.

Votes:

   ACCEPT(3) Cole, Baker, Ziese
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:dcforum-az-file-upload(6393)


CAN-2001-0438

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010418 Hole in Netopia's Mac OS X Timbuktu
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0337.html

Description:
Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:netopia-timbuktu-gain-access(6452)


CAN-2001-0441

Phase: Proposed (20010524)
Reference: DEBIAN:DSA-040
Reference: URL:http://www.debian.org/security/2001/dsa-040
Reference: MANDRAKE:MDKSA-2001:028
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-028.php3
Reference: CONECTIVA:CLA-2001:383
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000383
Reference: REDHAT:RHSA-2001:028
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-028.html
Reference: FREEBSD:FreeBSD-SA-01:37
Reference: URL:http://archives.neohapsis.com/archives/freebsd/2001-04/0610.html
Reference: BUGTRAQ:20010316 Immunix OS Security update for slrn
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98471253131191&w=2
Reference: BID:2493
Reference: URL:http://www.securityfocus.com/bid/2493
Reference: XF:slrn-wrapping-bo
Reference: URL:http://xforce.iss.net/static/6213.php

Description:
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.

Votes:

   ACCEPT(5) Oliver, Cole, Baker, Frech, Ziese
   NOOP(1) Wall

CAN-2001-0443

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010413 QPC POPd Buffer Overflow Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0227.html

Description:
Buffer overflow in QPC QVT/Net Popd 4.20 in QVT/Net 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via (1) a long username, or (2) a long password.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:qpc-popd-bo(6374)


CAN-2001-0446

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010328 CHINANSL Security Advisory(CSA-200107)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98583082225053&w=2

Description:
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:ibm-wcs-view-jsp(6308)
   CONFIRM:http://www-4.ibm.com/software/webservers/appserv/doc/
   v3024/EfixWeb3024.html
   Comments are cryptic.


CAN-2001-0447

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010326 602Pro Lansuite Denial Of Service 1.0.34
Reference: URL:http://www.securityfocus.com/archive/1/171418
Reference: BID:2514
Reference: URL:http://www.securityfocus.com/bid/2514

Description:
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" (dot dot) characters.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
Voter Comments:
 Frech> XF:software602-lan-suite-bo(5583)
   Possible duplicate or close similarity with
   BID-1979/CAN-2000-1115.
 Christey> The BID doesn't look quite like this; I think it's for
   CAN-2001-0448


CAN-2001-0448

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010326 602Pro Lansuite Denial Of Service 1.0.34
Reference: URL:http://www.securityfocus.com/archive/1/171418

Description:
Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service via an HTTP GET HTTP request to the aux directory, and possibly other directories with legacy DOS device names.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
Voter Comments:
 Frech> XF:software602-lan-suite-bo(5583)
 Christey> This should be BID:2514 (and CAN-2001-0447 should have
   BID:2514 removed from its set of references)


CAN-2001-0450

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010303 Broker Ftp Server 5.0 Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0533.html
Reference: CONFIRM:http://www.ftp-broker.com/cgibin/Pageexe.exe?H=4143&P=0&C=0
Reference: XF:broker-ftp-delete-files
Reference: URL:http://xforce.iss.net/static/6190.php
Reference: XF:broker-ftp-list-directories
Reference: URL:http://xforce.iss.net/static/6189.php

Description:
Directory traversal vulnerability in Transsoft FTP Broker before 5.5 allows attackers to (1) delete arbitrary files via DELETE, or (2) list arbitrary directories via LIST, via a .. (dot dot) in the file name.

Votes:

   ACCEPT(5) Oliver, Cole, Baker, Frech, Ziese
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> Change "LIST" to "DIR" - see original post.  The problem with
   LIST (and NLST) occurred in Broker 3.0, not 5.0.
   
   The CONFIRM link is dead.
   
   Thanks to John Segura of secureinfo.com for noticing this.


CAN-2001-0451

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010307 INDEXU Authentication By-Pass
Reference: URL:http://www.securityfocus.com/archive/1/167172
Reference: XF:indexu-gain-access
Reference: URL:http://xforce.iss.net/static/6202.php

Description:
INDEXU 2.0 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the cookie_admin_authenticated cookie value to 1.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Oliver, Wall, Cole, Ziese

CAN-2001-0452

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010428 Vulnerabilities in BRS WebWeaver
Reference: URL:http://www.securityfocus.com/archive/1/180506
Reference: CONFIRM:http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html
Reference: BID:2676
Reference: URL:http://www.securityfocus.com/bid/2676

Description:
BRS WebWeaver FTP server before 0.64 Beta allows remote attackers to obtain the real pathname of the server via a "CD *" command followed by an ls command.

Votes:

   ACCEPT(4) Cole, Baker, Ziese, Williams
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:webweaver-ftp-path-disclosure(6477)


CAN-2001-0453

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010428 Vulnerabilities in BRS WebWeaver
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0519.html
Reference: CONFIRM:http://members.nbci.com/_XMCM/BSoutham/WebWeaver/WebWeaverHistory.html
Reference: BID:2675
Reference: URL:http://www.securityfocus.com/bid/2675

Description:
Directory traversal vulnerability in BRS WebWeaver HTTP server allows remote attackers to read arbitrary files via a .. (dot dot) attack in the (1) syshelp, (2) sysimages, or (3) scripts directories.

Votes:

   ACCEPT(3) Baker, Balinsky, Williams
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:webweaver-web-directory-traversal(6476)


CAN-2001-0454

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010303 SlimServe HTTPd ver. 1.1a Directory Traversal
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0532.html
Reference: XF:slimserve-httpd-directory-traversal
Reference: URL:http://xforce.iss.net/static/6186.php

Description:
Directory traversal vulnerability in SlimServe HTTPd 1.1a allows remote attackers to read arbitrary files via a ... (modified dot dot) in the HTTP request.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(3) Oliver, Wall, Ziese

CAN-2001-0458

Phase: Proposed (20010524)
Reference: DEBIAN:DSA-034
Reference: URL:http://www.debian.org/security/2001/dsa-034
Reference: MANDRAKE:MDKSA-2001:027
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-027.php3
Reference: SUSE:SuSE-SA:2001:08
Reference: URL:http://www.suse.de/de/support/security/2001_008_eperl.txt
Reference: BID:2464
Reference: URL:http://www.securityfocus.com/bid/2464
Reference: XF:linux-eperl-bo
Reference: URL:http://xforce.iss.net/static/6198.php

Description:
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(5) Oliver, Cole, Baker, Frech, Ziese
   NOOP(1) Wall

CAN-2001-0459

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010308 ascdc Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98408897106411&w=2
Reference: XF:ascdc-afterstep-bo
Reference: URL:http://xforce.iss.net/static/6204.php

Description:
Buffer overflows in ascdc Afterstep while running setuid allows local users to gain root privileges via a long (1) -d option, (2) -m option, or (3) -f option.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Oliver, Wall, Cole, Ziese

CAN-2001-0460

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010308 def-2001-10: Websweeper Infinite HTTP Request DoS
Reference: URL:http://www.securityfocus.com/archive/1/167406
Reference: XF:websweeper-http-dos
Reference: URL:http://xforce.iss.net/static/6214.php

Description:
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Oliver, Wall, Cole, Ziese

CAN-2001-0464

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010417 Cyberscheduler remote root compromise
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98761402029302&w=2

Description:
Buffer overflow in websync.exe in Cyberscheduler allows remote attackers to execute arbitrary commands via a long tzs (timezone) parameter.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Christey, Ziese
Voter Comments:
 Frech> XF:cyberscheduler-timezone-bo(6401)
 Christey> BUGTRAQ:20010420 Apology: Advisory numbering confusion
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98779423227844&w=2


CAN-2001-0466

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010403 new advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98633176230748&w=2

Description:
Directory traversal vulnerability in ustorekeeper 1.61 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Ziese
Voter Comments:
 Frech> XF:ustorekeeper-retrieve-files(6319)


CAN-2001-0468

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010313 Buffer oveflow in FTPFS (linux kernel module)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0163.html
Reference: XF:ftpfs-bo
Reference: URL:http://xforce.iss.net/static/6234.php

Description:
Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Oliver, Wall, Cole, Ziese

CAN-2001-0470

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010313 Solaris 5.8 snmpd Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0160.html
Reference: BUGTRAQ:20010315 Re: Solaris 5.8 snmpd Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0181.html
Reference: XF:snmpd-argv-bo
Reference: URL:http://xforce.iss.net/static/6239.php

Description:
Buffer overflow in SNMP proxy agent snmpd in Solaris 8 may allow local users to gain root privileges by calling snmpd with a long program name.

Votes:

   ACCEPT(2) Dik, Frech
   NOOP(4) Oliver, Wall, Cole, Ziese
Voter Comments:
 Dik> sun bug: 4425460


CAN-2001-0471

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010205 SSHD-1 Logging Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/160648
Reference: BID:2345
Reference: URL:http://www.securityfocus.com/bid/2345

Description:
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via a brute force attack.

Votes:

   MODIFY(1) Frech
   NOOP(2) Wall, Cole
   REVIEWING(2) Oliver, Ziese
Voter Comments:
 Frech> XF:ssh-daemon-failed-login(6071)
 Oliver> Not clear how much of this is a vulnerability and how much a
   problem with site policy.


CAN-2001-0472

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010320 def-2001-12: Hursley Software Laboratories Consumer Transaction Framework DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0243.html
Reference: XF:hslctf-http-dos
Reference: URL:http://xforce.iss.net/static/6250.php

Description:
Hursley Software Laboratories Consumer Transaction Framework (HSLCTF) HTTP object allows remote attackers to cause a denial of service (crash) via an extremely long HTTP request.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Oliver, Wall, Cole, Ziese

CAN-2001-0476

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010318 Aspseek Buffer Overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0233.html
Reference: BID:2492
Reference: URL:http://www.securityfocus.com/bid/2492
Reference: CONFIRM:http://www.aspseek.org/changes.html
Reference: XF:aspseek-scgi-bo
Reference: URL:http://xforce.iss.net/static/6248.php

Description:
Multiple buffer overflows in s.cgi program in Aspseek search engine 1.03 and earlier allow remote attackers to execute arbitrary commands via (1) a long HTTP query string, or (2) a long tmpl paramater.

Votes:

   ACCEPT(5) Oliver, Cole, Baker, Frech, Ziese
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> Fix typo: "paramater"


CAN-2001-0477

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010423 (SRPRE00004) WebCalendar 0.9.26
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0392.html
Reference: BID:2639
Reference: URL:http://www.securityfocus.com/bid/2639

Description:
Vulnerability in WebCalendar 0.9.26 allows remote command execution.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Wall, Ziese, Balinsky
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF;webcalendar-execute-commands(6486)
 Balinsky> DNS domain of vendor site listed in the advisory no longer exists.
 CHANGE> [Balinsky changed vote from NOOP to REVIEWING]
 Balinsky> My mistake. It was the ADVISORY site that no longer exists. Not the vendor.
 CHANGE> [Balinsky changed vote from REVIEWING to NOOP]
 Balinsky> Could not find specific acknowledgement on vendor site. Only
   method of validation on the site is slogging through source code.


CAN-2001-0478

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html
Reference: BID:2642
Reference: URL:http://www.securityfocus.com/bid/2642

Description:
Directory traversal vulnerability in phpMyAdmin 2.2.0 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Christey, Ziese, Renaud
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:phpmyadmin-sqlphp-include-file(6483)
 Christey> Double-check the version number - is it 2.1.0 or 2.2.0?
   CONFIRM:http://phpmyadmin.sourceforge.net/ChangeLog.txt
   Item 2001-04-28 says "applied security patch from [Secure
   Reality]
   The patch implies that tbl_replace.php was also affected.


CAN-2001-0479

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010423 (SRPRE00001) phpMyAdmin 2.1.0 and phpPgAdmin 2.2.1
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0396.html
Reference: CONFIRM:http://www.greatbridge.org/project/phppgadmin/cvs/checkout.php/phpPgAdmin/ChangeLog?r=1.13
Reference: BID:2640
Reference: URL:http://www.securityfocus.com/bid/2640

Description:
Directory traversal vulnerability in phpPgAdmin 2.2.1 and earlier versions allows remote attackers to execute arbitrary code via a .. (dot dot) in an argument to the sql.php script.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(5) Wall, Cole, Ziese, Renaud, Balinsky
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:phppgadmin-sqlphp-include-file(6484)
 Balinsky> Advisory site no longer exists. There is not enough detail in the advisory, and the vendor does not acknowledge.


CAN-2001-0480

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010428 Vulnerabilities in Alex's FTP Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0523.html
Reference: BID:2668
Reference: URL:http://www.securityfocus.com/bid/2668

Description:
Directory traversal vulnerability in Alex's FTP Server 0.7 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the (1) GET or (2) CD commands.

Votes:

   ACCEPT(2) Cole, Williams
   MODIFY(1) Frech
   NOOP(3) Wall, Ziese, Balinsky
Voter Comments:
 Frech> XF:alex-ftp-directory-traversal(6475)


CAN-2001-0483

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010324 Raptor 6.5 http vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0359.html
Reference: BUGTRAQ:20010327 RE: Raptor 6.5 http vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/171953
Reference: BID:2517
Reference: URL:http://www.securityfocus.com/bid/2517

Description:
Configuration error in Axent Raptor Firewall 6.5 allows remote attackers to use the firewall as a proxy to access internal web resources when the http.noproxy Rule is not set.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Wall, Ziese
Voter Comments:
 Frech> XF:raptor-http-access-ports(6313)


CAN-2001-0484

Phase: Modified (20020223-01)
Reference: BUGTRAQ:20010425 Tektronix (Xerox) PhaserLink 850 Webserver Vulnerability (NEW)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0482.html
Reference: XF:tektronix-phaserlink-webserver-backdoor(6482)
Reference: URL:http://xforce.iss.net/static/6482.php

Description:
Tektronix PhaserLink 850 does not require authentication for access to configuration pages such as _ncl_subjects.shtml and _ncl_items.shtml, which allows remote attackers to modify configuration information and cause a denial of service by accessing the pages.

Votes:

   ACCEPT(1) Renaud
   MODIFY(2) Baker, Frech
   NOOP(6) Oliver, Wall, Cole, Ziese, Balinsky, Williams
   REVIEWING(1) Christey
Voter Comments:
 Williams> there was an issue with admin passwd storage for Tektronix Phaser 360, 740, 780, 840
 Frech> XF:tektronix-phaserlink-webserver-backdoor(6482)
 Baker> 750DP and 930 printers should be added
   http://www.securityfocus.com/archive/1/181007
 CHANGE> [Williams changed vote from REVIEWING to NOOP]
 Christey> CAN-1999-1508 covered the older versions discussed
   by Ken Williams.  These may be duplicates.
   This one is BID:2659
   http://www.securityfocus.com/bid/2659


CAN-2001-0485

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010426 IRIX /usr/lib/print/netprint local root symbols exploit.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0475.html
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0502.html

Description:
Vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attacker to execute arbitrary commands via the -n option.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(5) Wall, Cole, Christey, Ziese, Renaud
   REVIEWING(1) Williams
Voter Comments:
 Williams> Apply the following patch:  2022?
   See advisory 19961203-01-PX for more information?
 Frech> XF:irix-netprint-shared-library(6473)
 Christey> SGI:20010701-01-P
 Baker> SGI Patch 20010701-01-P
 Christey> ADDREF BID:2656


CAN-2001-0490

Phase: Proposed (20010524)
Reference: BUGTRAQ:20010429 Winamp 2.6x / 2.7x buffer overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0518.html

Description:
Buffer overflow in WINAMP 2.6x and 2.7x allows attackers to execute arbitrary code via a long string in an AIP file.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Ziese, Renaud
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:winamp-aip-bo(6479)


CAN-2001-0491

Phase: Modified (20010910-01)
Reference: BUGTRAQ:20010425 Vulnerabilities in RaidenFTPD Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0465.html
Reference: XF:raidenftpd-dot-directory-traversal(6455)
Reference: URL:http://xforce.iss.net/static/6455.php

Description:
Directory traversal vulnerability in RaidenFTPD Server 2.1 before build 952 allows attackers to access files outside the ftp root via dot dot attacks, such as (1) .... in CWD, (2) .. in NLST, or (3) ... in NLST.

Votes:

   ACCEPT(1) Williams
   MODIFY(2) Baker, Frech
   NOOP(4) Wall, Cole, Ziese, Renaud
Voter Comments:
 Frech> XF:raidenftpd-dot-directory-traversal(6455)
 Baker> Should probably modify description to say v2.1 prior to  build 952, since the interim builds also had similar problems until build 952 resolved this.


CAN-2001-0492

Phase: Modified (20030619-02)
Reference: BUGTRAQ:20010424 Advisory for Netcruiser
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0427.html
Reference: BID:2650
Reference: URL:http://www.securityfocus.com/bid/2650
Reference: XF:netcruiser-server-path-disclosure(6468)
Reference: URL:http://xforce.iss.net/static/6468.php

Description:
Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3.

Votes:

   ACCEPT(4) Oliver, Cole, Baker, Balinsky
   MODIFY(1) Frech
   NOOP(4) Wall, Christey, Ziese, Williams
Voter Comments:
 CHANGE> [Balinsky changed vote from REVIEWING to ACCEPT]
 Balinsky> Vendor acknowledged the problem in a personal communication.
 Frech> XF:netcruiser-server-path-disclosure(6468)
 CHANGE> [Williams changed vote from REVIEWING to NOOP]
 Christey> Fix typo (accidental URL insertion) in XF reference


CAN-2001-0496

Phase: Modified (20010910-01)
Reference: REDHAT:RHSA-2001:059
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-059.html
Reference: MANDRAKE:MDKSA-2001:046
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-046.php3
Reference: XF:kdelibs-kdesu-insecure-tmpfile(6856)
Reference: URL:http://xforce.iss.net/static/6856.php

Description:
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.

Votes:

   ACCEPT(4) Cole, Baker, Ziese, Williams
   MODIFY(1) Frech
   NOOP(2) Wall, Renaud
   REVIEWING(1) Christey
Voter Comments:
 Williams> kdesu is part of kdelibs package.  since entire kdelibs package must be upgraded, and since kdelibs (rather than kdesu) is referenced in most advisories related to this issue, we might want to reference kdelibs in this CAN.
 Frech> XF:kdelibs-kdesu-insecure-tmpfile(6856)
 Christey> Agree with Ken Williams.  The CVE descriptions in general
   should capture all "reasonable" keywords under which
   someone may know the vulnerability.
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> It's possible that this is the same vulnerability as CVE-2001-0178,
   but the description is written so differently from the others, that
   it's hard to be sure.  In addition, Mandrake released a separate
   advisory for CVE-2001-0178.
   BID:2669 addresses CVE-2001-0178.


CAN-2001-0498

Phase: Proposed (20010727)
Reference: NAI:20010627 Oracle 8i SQLNet Header Vulnerability
Reference: URL:http://www.nai.com/research/covert/advisories/049.asp

Description:
Transparent Network Substrate (TNS) over Net8 (SQLNet) in Oracle 8i 8.1.7 and earlier allows remote attackers to cause a denial of service via a malformed SQLNet connection request with a large offset in the header extension.

Votes:

   ACCEPT(5) Cole, Armstrong, Stracener, Prosser, Ziese
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Frech> XF:oracle-listener-offsettodata-dos(6713)
   CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_dos.pdf
   CAN-2001-0498 possible dupe of CAN-2001-0515, which is already
   assigned to oracle-listener-offsettodata-dos(6713)
 Prosser> Discover of issue (NAI) indicates that Oracle produced a patch for this issue.  Oracle patch site is restricted, but taking NAI's word as verification.
 Christey> Consider adding BID:2940


CAN-2001-0499

Phase: Proposed (20010727)
Reference: NAI:20010627 Vulnerability in Oracle 8i TNS Listener
Reference: URL:http://www.nai.com/research/covert/advisories/050.asp

Description:
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers to gain privileges via a long argument to the commands (1) STATUS, (2) PING, (3) SERVICES, (4) TRC_FILE, (5) SAVE_CONFIG, or (6) RELOAD.

Votes:

   ACCEPT(3) Cole, Armstrong, Ziese
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Frech> XF:oracle-tns-listener-bo(6758)
   CONFIRM:http://otn.oracle.com/deploy/security/pdf/nai_net8_bof.pdf
 Christey> CERT:CA-2001-16
   URL:http://www.cert.org/advisories/CA-2001-16.html
   CIAC:L-108
   URL:http://ciac.llnl.gov/ciac/bulletins/l-108.shtml
   CERT-VN:VU#620495
   URL:http://www.kb.cert.org/vuls/id/620495
   BID:2941
   URL:http://www.securityfocus.com/bid/2941
 Christey> Consider adding BID:2941
 Christey> BUGTRAQ:20021126 Oracle TNS SEH Exploit
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103833206805744&w=2


CAN-2001-0505

Phase: Proposed (20011012)
Reference: MS:MS01-039
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms01-039.asp
Reference: MSKB:Q294380
Reference: MSKB:Q301514

Description:
Memory leaks in Microsoft Services for Unix 2.0 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.

Votes:

   ACCEPT(6) Oliver, Wall, Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:sfu-telnet-dos(6883)
   XF:sfu-nfs-dos(6882)
 Christey> BID:3090
   URL:http://www.securityfocus.com/bid/3090
   BID:3089
   URL:http://www.securityfocus.com/bid/3089


CAN-2001-0509

Phase: Proposed (20010829)
Reference: MS:MS01-041
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-041.asp

Description:
Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.

Votes:

   ACCEPT(7) Wall, Foat, Cole, Armstrong, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:ms-malformed-rpc-dos(6914)
 Christey> BID:3104
   URL:http://www.securityfocus.com/bid/3104
   BUGTRAQ:20010730 Multiple Remote DoS vulnerabilities in Microsoft DCE/RPC deamons
   URL:http://online.securityfocus.com/archive/1/200450


CAN-2001-0515

Phase: Modified (20020223-01)
Reference: ISS:20010515 Multiple Oracle Listener Denial of Service Vulnerabilities
Reference: URL:http://xforce.iss.net/alerts/advise82.php
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf

Description:
Oracle Listener in Oracle 7.3 and 8i allows remote attackers to cause a denial of service via a malformed connection packet with a large offset_to_data value.

Votes:

   ACCEPT(4) Cole, Armstrong, Stracener, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:oracle-listener-offsettodata-dos(6713)
   CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf


CAN-2001-0516

Phase: Modified (20020223-01)
Reference: ISS:20010515 Multiple Oracle Listener Denial of Service Vulnerabilities
Reference: URL:http://xforce.iss.net/alerts/advise82.php
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf

Description:
Oracle listener between Oracle 9i and Oracle 8.0 allows remote attackers to cause a denial of service via a malformed connection packet that contains an incorrect requester_version value that does not match an expected offset to the data.

Votes:

   ACCEPT(4) Cole, Armstrong, Stracener, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:oracle-listener-incorrect-version-dos(6714)
   CONFIRM:http://otn.oracle.com/deploy/security/pdf/net8_dos_alert.pdf


CAN-2001-0519

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010529 Aladdin eSafe Gateway Filter Bypass - Updated Advisory
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0282.html
Reference: XF:esafe-gateway-bypass-filtering(6580)
Reference: URL:http://xforce.iss.net/static/6580.php

Description:
Aladdin eSafe Gateway versions 2.x allows a remote attacker to circumvent HTML SCRIPT filtering via a special arrangement of HTML tags which includes SCRIPT tags embedded within other SCRIPT tags.

Votes:

   ACCEPT(3) Foat, Cole, Frech
   NOOP(2) Wall, Ziese
   REVIEWING(1) Bishop

CAN-2001-0520

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010529 Aladdin eSafe Gateway Script-filtering Bypass through HTML tags
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0284.html
Reference: XF:esafe-gateway-bypass-filtering(6580)
Reference: URL:http://xforce.iss.net/static/6580.php

Description:
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent filtering of SCRIPT tags by embedding the scripts within certain HTML tags including (1) onload in the BODY tag, (2) href in the A tag, (3) the BUTTON tag, (4) the INPUT tag, or (5) any other tag in which scripts can be defined.

Votes:

   ACCEPT(3) Cole, Baker, Frech
   NOOP(3) Wall, Foat, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Baker> Found reference on their website, in the release notes, that appears
   to address the problem in this vulnerability:
   
   "15. Fixed a bug that used to cause the SmartStripping mechanism to miss some scripts in HTML pages."
   
   The release notes are available here:
   ftp://ftp.ealaddin.com/pub/manuals/ESG/ESG3.x/esg_rn.zip


CAN-2001-0521

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010529 Aladdin eSafe Gateway Script-filtering Bypass through Unicode Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0285.html
Reference: XF:esafe-gateway-bypass-filtering(6580)
Reference: URL:http://xforce.iss.net/static/6580.php

Description:
Aladdin eSafe Gateway versions 3.0 and earlier allows a remote attacker to circumvent HTML SCRIPT filtering via the UNICODE encoding of SCRIPT tags within the HTML document.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 CHANGE> [Frech changed vote from ACCEPT to MODIFY]
 Frech> DELREF:XF:esafe-gateway-bypass-filtering(6580) 
   ADDREF:XF:content-unicode-bypass-filter(6980)
 Baker> Found acknowledgement in the release notes for build 71, that said:
   
   "15. Fixed a bug that used to cause the SmartStripping mechanism to miss some scripts in HTML pages."
   
   Release notes are at the following url:
   ftp://ftp.ealaddin.com/pub/manuals/ESG/ESG3.x/esg_rn.zip


CAN-2001-0523

Phase: Modified (20020223-01)
Reference: BUGTRAQ:20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html
Reference: BUGTRAQ:20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0197.html
Reference: XF:eeye-secureiis-bypass-detection(6563)
Reference: URL:http://xforce.iss.net/static/6563.php
Reference: XF:eeye-secureiis-directory-traversal(6564)
Reference: URL:http://xforce.iss.net/static/6564.php

Description:
eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on vulnerable programs that would otherwise be protected.

Votes:

   ACCEPT(4) Cole, Frech, Bishop, Ziese
   NOOP(2) Wall, Foat

CAN-2001-0524

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010518 ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0185.html
Reference: BUGTRAQ:20010519 RE: ASLabs-2001-01: Multiple Security Problems in eEye SecureIIS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0197.html
Reference: XF:eeye-secureiis-http-header-bo(6574)
Reference: URL:http://xforce.iss.net/static/6574.php

Description:
eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.

Votes:

   ACCEPT(4) Cole, Frech, Bishop, Ziese
   NOOP(2) Wall, Foat

CAN-2001-0531

Phase: Assigned (20010619)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0532

Phase: Assigned (20010619)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0534

Phase: Proposed (20010727)
Reference: ISS:20010705 Remote Buffer Overflow in Multiple RADIUS Implementations
Reference: URL:http://xforce.iss.net/alerts/alerts.php

Description:
Multiple buffer overflows in RADIUS daemon radiusd in (1) Merit 3.6b and (2) Lucent 2.1-2 RADIUS allow remote attackers to cause a denial of service or execute arbitrary commands.

Votes:

   ACCEPT(2) Stracener, Baker
   MODIFY(2) Christey, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Frech> XF:merit-radius-authentication-bo(6812)
   XF:lucent-radius-authentication-bo(6794)
   Change ISS URL to http://xforce.iss.net/alerts/advise87.php
 Christey> BID:2989
   BID:2991


CAN-2001-0535

Phase: Proposed (20011012)
Reference: ISS:20010807 Remote Vulnerabilities in Macromedia ColdFusion Example Applications
Reference: URL:http://xforce.iss.net/alerts/advise92.php
Reference: ALLAIRE:MPSB01-08
Reference: URL:http://www.allaire.com/Handlers/index.cfm?ID=21700

Description:
Example applications (Exampleapps) in ColdFusion Server 4.x do not properly restrict prevent access from outside the local host's domain, which allows remote attackers to conduct upload, read, or execute files by spoofing the "HTTP Host" (CGI.Host) variable in (1) the "Web Publish" example script, and (2) the "Email" example script.

Votes:

   ACCEPT(3) Cole, Armstrong, Baker
   MODIFY(2) Foat, Frech
   NOOP(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:coldfusion-webpublish-execute-code(6790)
   XF:coldfusion-email-view-files(6791)
 Foat> Includes ColdFusion Server 4.x and earlier
 Christey> Consider adding BID:3154


CAN-2001-0539

Phase: Assigned (20010710)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0542

Phase: Proposed (20020131)
Reference: ATSTAKE:A122001-1
Reference: URL:http://www.atstake.com/research/advisories/2001/a122001-1.txt
Reference: BUGTRAQ:20011221 @stake advisory: Multiple overflow and format string vulnerabilities in in Microsoft SQL Server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100891252317406&w=2
Reference: MS:MS01-060
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-060.asp
Reference: XF:mssql-text-message-bo(7724)
Reference: URL:http://xforce.iss.net/static/7724.php
Reference: BID:3733
Reference: URL:http://www.securityfocus.com/bid/3733

Description:
Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CAN-2001-0879.

Votes:

   ACCEPT(5) Wall, Cole, Green, Baker, Frech
   NOOP(1) Foat

CAN-2001-0548

Phase: Modified (20020223-01)
Reference: BUGTRAQ:20010724 NSFOCUS SA2001-04 : Solaris dtmail Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99598918914068&w=2
Reference: XF:solaris-dtmail-bo(6879)
Reference: URL:http://xforce.iss.net/static/6879.php
Reference: BID:3081
Reference: URL:http://www.securityfocus.com/bid/3081

Description:
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.

Votes:

   ACCEPT(3) Foat, Armstrong, Stracener
   MODIFY(2) Frech, Balinsky
   NOOP(4) Wall, Cole, Christey, Ziese
Voter Comments:
 Frech> XF:solaris-dtmail-bo(6879)
 Balinsky> Delete "and possibly other operating systems" because that is not verifiable, and add the following references from Sun, which acknowledge the problem:
   http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches/105338
   http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches/105339
   http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches/107200
   http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fpatches/107201
 Christey> BID:3081
   URL:http://www.securityfocus.com/bid/3081
 Christey> It is not clear from the patch list whether these *particular*
   dtmail overflows have been addressed.


CAN-2001-0551

Phase: Proposed (20020131)
Reference: CERT-VN:VU#860296
Reference: URL:http://www.kb.cert.org/vuls/id/860296
Reference: AIXAPAR:IY21539
Reference: AIXAPAR:IY20917
Reference: HP:HPSBUX0105-151
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q2/0044.html

Description:
Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
   REVIEWING(2) Green, Christey
Voter Comments:
 Christey> There is some overlap between CAN-2001-0551 and CAN-2001-0772.
   CAN-2001-0551 describes a specific vulnerability in
   dtprintinfo.  HP acknowledges CAN-2001-0551 by stating
   that the problem is fixed in HP:HPSBUX0105-151, which
   is CAN-2001-0772.  But CAN-2001-0772 is a vague advisory
   that identifies other vulnerabilities (and vulnerability
   types) besides CAN-2001-0551.  Perhaps CAN-2001-0772 should
   be RECAST to "remove" the reference to dtprintinfo and
   leave the other vague descriptions.  CAN-2001-0772 and
   CAN-2001-0551 are very good examples of the problems that
   CVE faces in being consistent with respect to the level of
   abstraction, as documented in the CD:SF-CODEBASE, CD:SF-LOC,
   and CD:VAGUE content decisions.
 Baker> We should rewrite the candidate entry CAN-2001-0772 to address the other issues, and point the dtprintinfo issue to this entry.
 Frech> XF:cde-dtprintinfo-bo(8034)
 Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2406 - CDE dtprintinfo Help sea rch buffer overflow vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0036.html
   BID:4630
   URL:http://www.securityfocus.com/bid/4630
 Christey> CALDERA:CSSA-2002-SCO.30


CAN-2001-0552

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010608 HP Openview NNM6.1 ovactiond bin exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99201278704545&w=2
Reference: CERT:CA-2001-24
Reference: URL:http://www.cert.org/advisories/CA-2001-24.html
Reference: HP:HPSBUX0106-154
Reference: CERT-VN:VU#952171
Reference: URL:http://www.kb.cert.org/vuls/id/952171
Reference: BID:2845
Reference: URL:http://www.securityfocus.com/bid/2845

Description:
ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message.

Votes:

   ACCEPT(6) Cole, Armstrong, Prosser, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Prosser> HP:HPSBUX0106-154 and http://www.cert.org/advisories/CA-2001-24.html
 Frech> XF:openview-nnm-ovactiond-execution(6683)


CAN-2001-0555

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010613 ScreamingMedia SITEWare source code disclosure vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0166.html
Reference: BUGTRAQ:20010613 ScreamingMedia SITEWare arbitrary file retrieval vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0165.html
Reference: CONFIRM:http://www01.screamingmedia.com/en/security/sms1001.php

Description:
ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot dot) attack through (1) the SITEWare Editor's Desktop or (2) the template parameter in SWEditServlet.

Votes:

   ACCEPT(6) Foat, Cole, Armstrong, Stracener, Prosser, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> *********************************************************************
   Note that this candidate was inadvertently used in Microsoft bulletin
   MS01-044, for an unrelated vulnerability.  The ScreamingMedia
   SITEware problem is the correct vulnerability for
   CAN-2001-0555.  A different candidate will be used for the problem
   described in the Microsoft bulletin.
   *********************************************************************
 Frech> XF:siteware-dot-file-retrieval(6689)
 Prosser> http://www01.screamingmedia.com/en/security/sms1001.php
 Christey> Consider adding BID:3191
 Christey> CHANGEREF CONFIRM:http://www01.screamingmedia.com/en/security/security_notice.php?doc=sms1001
   CERT-VN:VU#795707
   URL:http://www.kb.cert.org/vuls/id/795707
   BID:2869
   URL:http://www.securityfocus.com/bid/2869
   XF:siteware-dot-file-retrieval(6689)
   URL:http://xforce.iss.net/static/6689.php
   
   *DON'T* add BID:3191 - that's for the Microsoft issue.


CAN-2001-0556

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010428 More nedit problems ? (was Re: PROGENY-SA-2001-10...)
Reference: URL:http://www.securityfocus.com/archive/1/180237
Reference: CONFIRM:http://www.nedit.org/archives/develop/2001-Feb/0391.html
Reference: SUSE:SuSE-SA:2001:14
Reference: URL:http://www.suse.de/de/support/security/2001_014_nedit.txt
Reference: MANDRAKE:MDKSA-2001:042
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-042.php3
Reference: DEBIAN:DSA-053
Reference: URL:http://www.debian.org/security/2001/dsa-053
Reference: REDHAT:RHSA-2001:061
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-061.html
Reference: BID:2667
Reference: URL:http://www.securityfocus.com/bid/2667

Description:
The Nirvana Editor (NEdit) 5.1.1 and earlier allows a local attacker to overwrite other users' files via a symlink attack on (1) backup files or (2) temporary files used when nedit prints a file or portions of a file.

Votes:

   ACCEPT(6) Williams, Foat, Cole, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> nedit-print-symlink(6424)
 Christey> SGI:20011105-01-P
   ftp://patches.sgi.com/support/free/security/advisories/20011105-01-P
   ADDREF BID:2627
   URL:http://www.securityfocus.com/bid/2627
   (there are different BID's for the different symlink issues)


CAN-2001-0557

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010507 Advisory for Jana server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0086.html
Reference: XF:jana-server-directory-traversal(6513)
Reference: URL:http://xforce.iss.net/static/6513.php
Reference: BID:2703
Reference: URL:http://www.securityfocus.com/bid/2703

Description:
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

Votes:

   ACCEPT(2) Frech, Ziese
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Bishop

CAN-2001-0561

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010507 Advisory for A1Stats
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html
Reference: BID:2705
Reference: URL:http://www.securityfocus.com/bid/2705
Reference: XF:a1stats-dot-directory-traversal(6503)
Reference: URL:http://xforce.iss.net/static/6503.php

Description:
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary files via a '..' (dot dot) attack in (1) a1disp2.cgi, (2) a1disp3.cgi, or (3) a1disp4.cgi.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(2) Wall, Foat
   REVIEWING(1) Bishop
Voter Comments:
 Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1
   5&t=000008
   Statement of fix is ambiguous: A major security flaw in the scripts
   has now been fixed. For obvious reasons the details of the flaw will
   not be posted here. 
   Site lists their product as A1-Stats, not A1Stats as in description.


CAN-2001-0562

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010507 Advisory for A1Stats
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0047.html
Reference: BID:2705
Reference: URL:http://www.securityfocus.com/bid/2705
Reference: XF:a1stats-a1admin-dos(6505)
Reference: URL:http://xforce.iss.net/static/6505.php

Description:
a1disp.cgi program in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to execute commands via a specially crafted URL which includes shell metacharacters.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(4) Wall, Foat, Christey, Bishop
Voter Comments:
 Frech> CONFIRM:http://www.gadnet.com/cgi-bin/ultimatebb.cgi?ubb=get_topic&f=1
   5&t=000008
   Statement of fix is ambiguous: A major security flaw in the scripts
   has now been fixed. For obvious reasons the details of the flaw will
   not be posted here. 
   Site lists their product as A1-Stats, not A1Stats as in description.
 CHANGE> [Bishop changed vote from REVIEWING to NOOP]
 Christey> The URL recommended by Andre is *probably* addressing this
   problem, but it's not quite certain.  There is insufficient
   detail to determine if the vendor has truly acknowledged the
   problem.  I have an email to a1stats@gadnet.com to see
   if I can confirm.
   
   This is affected by CD:SF-EXEC since multiple executables in the same
   package are affected (a1disp.cgi, a1disp2.cgi, a1disp4.cgi, and
   a1disp3.cgi).
 Christey> Received confirmation via email, 2/26/2002.


CAN-2001-0566

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010503 Cisco Catalyst 2900XL crashes with empty UDP packet when SNMP is disabled.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0040.html
Reference: XF:cisco-catalyst-udp-dos(6515)
Reference: URL:http://xforce.iss.net/static/6515.php

Description:
Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port 161 (SNMP) when SNMP is disabled.

Votes:

   ACCEPT(2) Frech, Ziese
   MODIFY(1) Bishop
   NOOP(2) Wall, Cole
   REJECT(1) Foat
   REVIEWING(1) Baker
Voter Comments:
 Bishop> Is the entire switch shut down or is traffic blocked for a 
   limited time?
 Foat> Unable to duplicate event
 Baker> Seems kind of strange that someone that works at Cisco would accept this vulnerability,
   yet someone else would reject it.  I was unable to find a reference on the Cisco
   web site, so perhaps we need some clarification about the accept vote, like what build
   of the OS is vulnerable, since the "fail to duplicate" may be a different build of the
   OS.


CAN-2001-0568

Phase: Proposed (20010727)
Reference: CONFIRM:http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23
Reference: MANDRAKE:MDKSA-2001:025
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-025.php3
Reference: DEBIAN:DSA-043
Reference: URL:http://www.debian.org/security/2001/dsa-043
Reference: REDHAT:RHSA-2001:021
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-021.html
Reference: CONECTIVA:CLA-2001:382
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000382

Description:
Digital Creations Zope 2.3.1 b1 and earlier allows a local attacker (Zope user) with through-the-web scripting capabilities to alter ZClasses class attributes.

Votes:

   ACCEPT(5) Williams, Cole, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:zope-zclass-modification(6247)


CAN-2001-0569

Phase: Proposed (20010727)
Reference: CONFIRM:http://www.zope.org/Products/Zope/Products/Zope/Products/Zope/Hotfix_2001-02-23
Reference: MANDRAKE:MDKSA-2001:025
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-025.php3
Reference: DEBIAN:DSA-043
Reference: URL:http://www.debian.org/security/2001/dsa-043
Reference: REDHAT:RHSA-2001:021
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-021.html
Reference: CONECTIVA:CLA-2001:382
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000382

Description:
Digital Creations Zope 2.3.1 b1 and earlier contains a problem in the method return values related to the classes (1) ObjectManager, (2) PropertyManager, and (3) PropertySheet.

Votes:

   ACCEPT(4) Williams, Cole, Baker, Ziese
   MODIFY(2) Frech, Bishop
   NOOP(2) Wall, Foat
Voter Comments:
 Bishop> the description is too vague; please specify the result of 
   the problem
 Frech> XF:zope-classes-return-value(6952)


CAN-2001-0570

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010503 minicom exploit
Reference: URL:http://www.securityfocus.com/archive/1/181922
Reference: REDHAT:RHSA-2001:067
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-067.html
Reference: CALDERA:CSSA-2001-016.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-016.0.txt
Reference: BUGTRAQ:20010517 Immunix OS Security update for minicom
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99014300904714&w=2
Reference: XF:minicom-xmodem-format-string(6498)
Reference: URL:http://xforce.iss.net/static/6498.php

Description:
minicom 1.83.1 and earlier allows a local attacker to gain additional privileges via numerous format string attacks.

Votes:

   ACCEPT(4) Wall, Cole, Prosser, Frech
   NOOP(2) Foat, Ziese
   REVIEWING(1) Bishop

CAN-2001-0571

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010323 Elron IM Products Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98538867727489&w=2
Reference: BUGTRAQ:20010326 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98567864203963&w=2
Reference: BUGTRAQ:20010406 http://archives.neohapsis.com/archives/bugtraq/2001-03/0345.html
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0382.html
Reference: BID:2519
Reference: URL:http://www.securityfocus.com/bid/2519
Reference: BID:2520
Reference: URL:http://www.securityfocus.com/bid/2520

Description:
Directory traversal vulnerability in the web server for (1) Elron Internet Manager (IM) Message Inspector and (2) Anti-Virus before 3.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the requested URL.

Votes:

   ACCEPT(5) Wall, Cole, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(1) Foat
   REVIEWING(1) Williams
Voter Comments:
 Frech> XF:elronim-antivirus-directory-traversal(6959)
   XF:elronim-inspector-directory-traversal(6960)
   CONFIRM:http://www.elronsw.com/connection/story194a.html


CAN-2001-0572

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010318 Passive Analysis of SSH (Secure Shell) Traffic
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0225.html
Reference: CONECTIVA:CLA-2001:391
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000391
Reference: REDHAT:RHSA-2001:033
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-033.html
Reference: MANDRAKE:MDKSA-2001:033
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-033.php3

Description:
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication is being used, (3) the number of authorized_keys in RSA authentication, or (4) the lengths of shell commands.

Votes:

   ACCEPT(3) Williams, Cole, Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:ssh-plaintext-length-field(6783)
 Christey> REDHAT:RHSA-2001:041
   (obsoletes REDHAT:RHSA-2001:033, according to Red Hat)
   TURBO:TLSA2001021
   URL:http://www.turbolinux.com/pipermail/tl-security-announce/2001-May/000309.html
 Christey> CISCO:20010627 Multiple SSH Vulnerabilities
   http://www.cisco.com/warp/public/707/SSH-multiple-pub.html


CAN-2001-0575

Phase: Modified (20020225-01)
Reference: BUGTRAQ:20010327 SCO 5.0.6 issues (lpshut)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0404.html
Reference: BUGTRAQ:20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes
Reference: URL:http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html
Reference: XF:sco-openserver-lpshut-bo(6290)
Reference: URL:http://xforce.iss.net/static/6290.php

Description:
Buffer overflow in lpshut in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a long first argument to lpshut.

Votes:

   ACCEPT(3) Williams, Baker, Frech
   MODIFY(1) Bishop
   NOOP(4) Wall, Foat, Cole, Ziese
Voter Comments:
 Bishop> recommend combining as stated in analysis
 Baker> http://support.caldera.com/caldera/solution?11=113723&130=0988647911&14=&2715=&15=&2716=&57=search&58=&2900=dckSSu3pru&25=6&3=SSE072B
   "What is SSE072B, the buffer overflow security patch for Openserver 5? (Ref. #113723)"
   Buffer overflows have been found in the following 19
   SCO OpenServer 5 utilities:
   
   /usr/bin/accept
   /usr/bin/cancel
   /usr/mmdf/bin/deliver
   /usr/bin/disable
   /usr/bin/enable
   /usr/lib/libcurses.a
   /usr/bin/lp
   /usr/lib/lpadmin
   /usr/lib/lpfilter
   /usr/lib/lpforms
   /usr/lib/lpmove
   /usr/lib/lpshut
   /usr/bin/lpstat
   /usr/lib/lpusers
   /usr/bin/recon
   /usr/bin/reject
   /usr/bin/rmail
   /usr/lib/sendmail
   /usr/bin/tput
   
   NOTE: the accept, reject, enable, and disable commands are
   symbolically linked to the same binary.
   
   Running any of the above utilities with a very large argument
   can result in a core dump.


CAN-2001-0576

Phase: Modified (20020225-01)
Reference: BUGTRAQ:20010327 SCO 5.0.6 issues (lpusers)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0407.html
Reference: BUGTRAQ:20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes
Reference: URL:http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html
Reference: XF:sco-openserver-lpusers-bo(6292)
Reference: URL:http://xforce.iss.net/static/6292.php

Description:
lpusers as included with SCO OpenServer 5.0 through 5.0.6 allows a local attacker to gain additional privileges via a buffer overflow attack in the '-u' command line parameter.

Votes:

   ACCEPT(2) Williams, Frech
   MODIFY(1) Bishop
   NOOP(4) Wall, Foat, Cole, Ziese
   RECAST(1) Baker
Voter Comments:
 Bishop> recommend combining as stated in analysis
 Baker> Merge with CAN-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem.
 Williams> re: Baker recast - why merge 19 separate vuln issues into one CAN?


CAN-2001-0577

Phase: Modified (20020225-01)
Reference: BUGTRAQ:20010327 SCO 5.0.6 issues (recon)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0410.html
Reference: BUGTRAQ:20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes
Reference: URL:http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html
Reference: XF:sco-openserver-recon-bo(6289)
Reference: URL:http://xforce.iss.net/static/6289.php

Description:
recon in SCO OpenServer 5.0 through 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first command line argument.

Votes:

   ACCEPT(2) Williams, Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   RECAST(1) Baker
   REVIEWING(1) Bishop
Voter Comments:
 Baker> Merge with CAN-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem.


CAN-2001-0578

Phase: Modified (20020225-01)
Reference: BUGTRAQ:20010327 SCO 5.0.6 issues (lpforms)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0416.html
Reference: BUGTRAQ:20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes
Reference: URL:http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html
Reference: XF:sco-openserver-lpforms-bo(6293)
Reference: URL:http://xforce.iss.net/static/6293.php

Description:
Buffer overflow in lpforms in SCO OpenServer 5.0-5.0.6 can allow a local attacker to gain additional privileges via a long first argument to the lpforms command.

Votes:

   ACCEPT(2) Williams, Frech
   MODIFY(1) Bishop
   NOOP(4) Wall, Foat, Cole, Ziese
   RECAST(1) Baker
Voter Comments:
 Bishop> recommend combining as stated in analysis
 Baker> Merge with CAN-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem.


CAN-2001-0579

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010327 SCO 5.0.6 issues (lpadmin)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0421.html
Reference: BUGTRAQ:20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes
Reference: URL:http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html
Reference: XF:sco-openserver-lpadmin-bo(6291)
Reference: URL:http://xforce.iss.net/static/6291.php

Description:
lpadmin in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow attack in the first argument to the command.

Votes:

   ACCEPT(2) Williams, Frech
   MODIFY(1) Bishop
   NOOP(4) Wall, Foat, Cole, Ziese
   RECAST(1) Baker
Voter Comments:
 Bishop> recommend combining as stated in analysis
 Baker> Merge with CAN-2001-0575, which has vendor acknowledgement, and includes this as one of the binaries with the same problem.


CAN-2001-0580

Phase: Proposed (20010727)
Reference: BUGTRAQ:200105007 Advisory for Vdns
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0050.html

Description:
Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting to port 6070, sending some data, and closing the connection.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Christey> BID:2700
   URL:http://www.securityfocus.com/bid/2700
 Christey> XF:vdns-default-closed-dos(6507)
 Frech> XF:vdns-default-closed-dos(6507)
   There is a 2.0 version at
   http://html.hughestech.com/index.html, but I could not find any
   mention of fixes.


CAN-2001-0581

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010507 Advisory for Spynet Chat
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0051.html
Reference: XF:spynet-connection-dos(6509)
Reference: URL:http://xforce.iss.net/static/6509.php
Reference: BID:2701
Reference: URL:http://www.securityfocus.com/bid/2701

Description:
Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large amount (> 100) of connections to port 6387.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(4) Wall, Foat, Christey, Bishop
Voter Comments:
 CHANGE> [Bishop changed vote from REVIEWING to NOOP]
 Christey> A followup claims that if the server runs on Windows 9x, that
   Windows 9x can't handle more than 100 sockets at once, which
   may be triggering the bug as opposed to the software.


CAN-2001-0582

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010503 Vulnerabilities in CrushFTP Server
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0036.html
Reference: XF:crushftp-directory-traversal(6495)
Reference: URL:http://xforce.iss.net/static/6495.php

Description:
Ben Spink CrushFTP FTP Server 2.1.6 and earlier allows a local attacker to access arbtrary files via a '..' (dot dot) attack, or variations, in (1) GET, (2) CD, (3) NLST, (4) SIZE, (5) RETR.

Votes:

   ACCEPT(4) Cole, Frech, Bishop, Ziese
   NOOP(2) Wall, Foat

CAN-2001-0583

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010315 def-2001-11: MDaemon 3.5.4 Dos-Device DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0188.html
Reference: XF:mdaemon-webservices-dos(6240)
Reference: URL:http://xforce.iss.net/static/6240.php
Reference: CONFIRM:http://ftp1.deerfield.com/pub/mdaemon/Archive/3.5.6/

Description:
Alt-N Technologies MDaemon 3.5.4 allows a remote attacker to create a denial of service via the URL request of a MS-DOS device (such as GET /aux) to (1) the Worldclient service at port 3000, or (2) the Webconfig service at port 3001.

Votes:

   ACCEPT(3) Williams, Baker, Frech
   NOOP(5) Wall, Foat, Cole, Bishop, Ziese
Voter Comments:
 Baker> ftp1.deerfield.com/pub/mdaemon/Archive/3.5.6/
   This is the site for downloading from Deerfield, the parent company.
   The release notes on the web site only apply to version 4.0 and higher.
   If you download the 3.5.6 version, you can then install the software,
   which will also install the release notes, named RelNotes.txt, in the
   docs sub-directory.  Inside this file is a vendor confirmation
   of sorts, at least close enough for me....
   I quote:
   "-----------------------------------------------------------------------------
   MDaemon Server v3.X Release Notes
   -----------------------------------------------------------------------------
   
   PLEASE READ THIS ENTIRE DOCUMENT.  IMPORTANT ISSUES RELATED TO THE RELEASE OF
   MDAEMON 3.X ARE LISTED TOWARD THE BOTTOM OF THIS DOCUMENT.  THEY ARE
   CRITICALLY IMPORTANT!  PLEASE READ THIS ENTIRE DOCUMENT.
   
   ----------------------------
   MDaemon v3.5.6 - Mar 9, 2001
   ----------------------------
   
   SPECIAL CONSIDERATIONS
   ----------------------
   
   o None (see 3.51 below)
   
   MAJOR NEW FEATURES
   ------------------
   
   o None
   
   
   ADDITIONAL CHANGES AND NEW FEATURES
   -----------------------------------
   
   o None
   
   FIXES
   -----
   
   o Fix to memory leak in IMAP server.
   o Fix to crash problem in WorldClient Standard and WebConfig web server.
   o Fix to 'Send As' address not being used as MAIL FROM when forwarding.
   o Fix to 'local only' restriction not being applied when mail collected
   via DomainPOP.
   
   -------------------------------
   MDaemon v3.5.4 - Feb 19th, 2001
   -------------------------------
   "
   This matches the described problems in the worldclient and webconfig servers
   which are part of the Mdaemon package.


CAN-2001-0584

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010325 MDaemon IMAP Denial Of Service
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0365.html
Reference: BID:2508
Reference: URL:http://www.securityfocus.com/bid/2508
Reference: XF:mdaemon-imap-command-dos(6279)
Reference: URL:http://xforce.iss.net/static/6279.php

Description:
IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE commands.

Votes:

   ACCEPT(3) Williams, Cole, Frech
   NOOP(4) Wall, Foat, Bishop, Ziese
Voter Comments:
 CHANGE> [Bishop changed vote from REVIEWING to NOOP]


CAN-2001-0587

Phase: Modified (20020225-01)
Reference: BUGTRAQ:20010327 SCO 5.0.6 MMDF issues (deliver)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0418.html
Reference: BUGTRAQ:20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes
Reference: URL:http://security-archive.merton.ox.ac.uk/bugtraq-200104/0221.html
Reference: XF:sco-openserver-deliver-bo(6302)
Reference: URL:http://xforce.iss.net/static/6302.php
Reference: BID:2583
Reference: URL:http://www.securityfocus.com/bid/2583

Description:
deliver program in MMDF 2.43.3b in SCO OpenServer 5.0.6 can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.

Votes:

   ACCEPT(4) Williams, Baker, Frech, Bishop
   NOOP(5) Wall, Foat, Cole, Christey, Ziese
Voter Comments:
 Frech> CONFIRM:ftp://ftp.sco.com/SSE/sse072b.ltr
 Christey> SCO fixed a number of mail-related issues.  This is affected
   by CD:SF-EXEC.  There may be related CANs.


CAN-2001-0588

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010327 SCO 5.0.6 MMDF issues (sendmail 8.9.3)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-03/0417.html
Reference: BUGTRAQ:20010412 SSE072B: SCO OpenServer revision of buffer overflow fixes
Reference: URL:http://online.securityfocus.com/archive/1/171935

Description:
sendmail 8.9.3, as included with the MMDF 2.43.3b package in SCO OpenServer 5.0.6, can allow a local attacker to gain additional privileges via a buffer overflow in the first argument to the command.

Votes:

   ACCEPT(1) Williams
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:sco-openserver-sendmail-bo(6303)


CAN-2001-0592

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010405 def-2001-18: Watchguard Firebox II Kernel DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0054.html
Reference: XF:firebox-kernel-dos(6327)
Reference: URL:http://xforce.iss.net/static/6327.php

Description:
Watchguard Firebox II prior to 4.6 allows a remote attacker to create a denial of service in the kernel via a large stream (>10,000) of malformed ICMP or TCP packets.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0597

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010410 Catastrophic failure of Strip password generation.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0169.html
Reference: BID:2567
Reference: URL:http://www.securityfocus.com/bid/2567
Reference: XF:strip-weak-passwords(6362)
Reference: URL:http://xforce.iss.net/static/6362.php

Description:
Zetetic Secure Tool for Recalling Important Passwords (STRIP) 0.5 and earlier for the PalmOS allows a local attacker to recover passwords via a brute force attack. This attack is made feasible by STRIP's use of SysRandom, which is seeded by TimeGetTicks, and an implementation flaw which vastly reduces the password 'search space'.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(2) Wall, Foat
   REVIEWING(1) Bishop
Voter Comments:
 Frech> CONFIRM:http://www.zetetic.net/docs/bugs/security_04-09-2001.
   html


CAN-2001-0598

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 def-2001-21: Ghost Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0175.html
Reference: XF:ghost-configuration-server-dos(6357)
Reference: URL:http://xforce.iss.net/static/6357.php
Reference: BID:2570
Reference: URL:http://www.securityfocus.com/bid/2570

Description:
Symantec Ghost 6.5 and earlier allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to the Ghost Configuration Server on port 1347, which triggers an error that is not properly handled.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(1) Foat
   REVIEWING(2) Wall, Bishop
Voter Comments:
 Frech> Vendor Acknowledgement: implicitly, via upgrade.


CAN-2001-0599

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 def-2001-21: Ghost Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0175.html
Reference: XF:ghost-database-engine-dos(6356)
Reference: URL:http://xforce.iss.net/static/6356.php
Reference: BID:2572
Reference: URL:http://www.securityfocus.com/bid/2572

Description:
Sybase Adaptive Server Anywhere Database Engine 6.0.3.2747 and earlier as included with Symantec Ghost 6.5 allows a remote attacker to create a denial of service by sending large (> 45Kb) amounts of data to port 2638.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(1) Foat
   REVIEWING(2) Wall, Bishop
Voter Comments:
 Frech> Vendor Acknowledgement: implicitly, via upgrade.


CAN-2001-0600

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 def-2001-20: Lotus Domino Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html
Reference: XF:lotus-domino-header-dos(6347)
Reference: URL:http://xforce.iss.net/static/6347.php

Description:
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated URL requests with the same HTTP headers, such as (1) Accept, (2) Accept-Charset, (3) Accept-Encoding, (4) Accept-Language, and (5) Content-Type.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> Vendor Acknowledgement: implicitly, via upgrade.


CAN-2001-0601

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 def-2001-20: Lotus Domino Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html
Reference: XF:lotus-domino-unicode-dos(6349)
Reference: URL:http://xforce.iss.net/static/6349.php

Description:
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via HTTP requests containing certain combinations of UNICODE characters.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> Vendor Acknowledgement: implicitly, via upgrade.


CAN-2001-0602

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 def-2001-20: Lotus Domino Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html
Reference: XF:lotus-domino-device-dos(6348)
Reference: URL:http://xforce.iss.net/static/6348.php

Description:
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated (>400) URL requests for DOS devices.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> Vendor Acknowledgement: implicitly, via upgrade.


CAN-2001-0603

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 def-2001-20: Lotus Domino Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html
Reference: XF:lotus-domino-corba-dos(6350)
Reference: URL:http://xforce.iss.net/static/6350.php

Description:
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> CONFIRM:Lotus SPR #CBRN4QWJUN at
   http://www.notes.net/qmrdown.nsf/QMRWelcome


CAN-2001-0604

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 def-2001-20: Lotus Domino Multiple DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0174.html
Reference: XF:lotus-domino-url-dos(6351)
Reference: URL:http://xforce.iss.net/static/6351.php

Description:
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of '/' characters.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> CONFIRM:http://www.notes.net/qmrdown.nsf/QMRWelcome; Lotus
   does not seem to wax prolific with their DoS explanations. For 5.0.7,
   any of these SPR#s have the explanation "Fixed a potential Denial of
   Service attack on HTTP.": JCHN4TQS2T, JCHN4RPKC2, JCHN4TQNL8,
   JCHN4JQKYQ, JCHN4TGN32.


CAN-2001-0605

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010226 My Getright Unsupervised File Download Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98321819112158&w=2

Description:
Headlight Software MyGetright prior to 1.0b allows a remote attacker to upload and/or overwrite arbitrary files via a malicious .dld (skins-data) file which contains long strings of random data.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Prosser, Ziese
   REVIEWING(2) Williams, Bishop
Voter Comments:
 Frech> XF:mygetright-skin-overwrite-file(6155)
   In description, product should be "My GetRight" (see
   http://www.mygetright.com/get.html)
 Prosser> According to Discover's Bulletin, the vendor, www.mygetright.com acknowledged the problem and fixed it in version 1.0b.  However, vendor page makes no mention of this issue.


CAN-2001-0606

Phase: Modified (20020225-01)
Reference: HP:HPSBUX0102-139
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q1/0041.html
Reference: XF:hp-virtualvault-iws-dos(6110)
Reference: URL:http://xforce.iss.net/static/6110.php

Description:
Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service.

Votes:

   ACCEPT(6) Williams, Wall, Cole, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:hp-virtualvault-iws-dos(6110)
 CHANGE> [Williams changed vote from REVIEWING to ACCEPT]


CAN-2001-0607

Phase: Proposed (20010727)
Reference: HP:HPSBUX0103-145
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q1/0080.html

Description:
asecure as included with HP-UX 10.01 through 11.00 can allow a local attacker to create a denial of service and gain additional privileges via unsafe permissions on the asecure program.

Votes:

   ACCEPT(5) Williams, Cole, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Frech> XF:hp-asecure-dos(6212)
   Possible duplicate of CAN-2000-0083: HP asecure creates the
   Audio Security File audio.sec with insecure permissions, which allows
   local users to cause a denial of service or gain additional
   privileges.
 Williams> Frech - this is not a dupe of CAN-2000-0083.
 Christey> While this advisory is vaguely worded, the fact that HP did an
   advisory for the other asecure problem (now CVE-2000-0083)
   indicates at the very least that this problem occurs in
   a different version than CVE-2000-0083, so CD:SF-LOC
   suggests a SPLIT.  However, the HP advisory says "10.X"
   and "11.X" are affected, so who knows what versions they
   *really* mean?


CAN-2001-0608

Phase: Modified (20020225-01)
Reference: HP:HPSBMP0103-011
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q1/0087.html
Reference: XF:hp-aif-gain-privileges(6951)
Reference: URL:http://xforce.iss.net/static/6951.php
Reference: CERT-VN:VU#895496
Reference: URL:http://www.kb.cert.org/vuls/id/895496

Description:
HP architected interface facility (AIF) as includes with MPE/iX 5.5 through 6.5 running on a HP3000 allows an attacker to gain additional privileges and gain access to databases via the AIF - AIFCHANGELOGON program.

Votes:

   ACCEPT(5) Williams, Cole, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:hp-aif-gain-privileges(6951)


CAN-2001-0609

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010411 CFINGERD remote vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0202.html
Reference: DEBIAN:DSA-048
Reference: URL:http://www.debian.org/security/2001/dsa-048
Reference: BID:2576
Reference: URL:http://www.securityfocus.com/bid/2576
Reference: XF:cfingerd-remote-format-string(6364)
Reference: URL:http://xforce.iss.net/static/6364.php

Description:
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.

Votes:

   ACCEPT(5) Cole, Baker, Frech, Bishop, Ziese
   NOOP(2) Wall, Foat
   REVIEWING(1) Christey
Voter Comments:
 Christey> A very similar vulnerability - which perhaps should be
   combined with this CAN according to CD:SF-LOC - is documented
   in the following references:
   
   BUGTRAQ:20010621 cfingerd local vulnerability (possibly root)
   URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0106212246190.31927-100000@ace
   BUGTRAQ:20010712 Happy 3 month anniversary cfingerd remote bug!
   URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0107120434070.10330-200000@clarity.local
   BID:2915
   URL:http://www.securityfocus.com/bid/2915


CAN-2001-0610

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010418 Insecure directory handling in KFM file manager
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0336.html
Reference: XF:kfm-tmpfile-symlink(6428)
Reference: URL:http://xforce.iss.net/static/6428.php

Description:
kfm as included with KDE 1.x can allow a local attacker to gain additional privileges via a symlink attack in the kfm cache directory in /tmp.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0612

Phase: Interim (20030326)
Reference: BUGTRAQ:20010516 Remote Desktop DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0158.html
Reference: XF:remote-desktop-dos(6547)
Reference: URL:http://xforce.iss.net/static/6547.php
Reference: BID:2726
Reference: URL:http://www.securityfocus.com/bid/2726

Description:
McAfee Remote Desktop 3.0 and earlier allows a remote attacker to create a denial of service (crash) via large amounts of packets to port 5045.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(3) Wall, Foat, Bishop
Voter Comments:
 CHANGE> [Bishop changed vote from REVIEWING to NOOP]


CAN-2001-0614

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010514 def-2001-25: Carello E-Commerce Arbitrary Command Execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98991352402073&w=2
Reference: XF:carello-url-code-execution(6532)
Reference: URL:http://xforce.iss.net/static/6532.php

Description:
Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary commands via a specially constructed URL.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Christey, Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Christey> Give the particular nature of the constructed URL, i.e. the
   command is specified in the VBEXE parameter.


CAN-2001-0617

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010514 Cable-Router AR220e Portmapper Security-Flaw
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0125.html
Reference: XF:telesyn-portmapper-access-services(6560)
Reference: URL:http://xforce.iss.net/static/6560.php

Description:
Allied Telesyn AT-AR220e cable/DSL router firmware 1.08a RC14 with the portmapper and the 'Virtual Server' enabled can allow a remote attacker to gain access to mapped services even though the single portmappings may be disabled.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0618

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010402 RG-1000 802.11 Residential Gateway default WEP key disclosure flaw
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0020.html
Reference: XF:orinoco-rg1000-wep-key(6328)
Reference: URL:http://xforce.iss.net/static/6328.php

Description:
Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occurs in the clear during communications, a remote attacker could determine the WEP key and decrypt RG-1000 traffic.

Votes:

   ACCEPT(1) Frech
   MODIFY(1) Ziese
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Bishop
Voter Comments:
 Ziese> vulnerability, per se, then why is this?  If WEP is delievred enabled, by
   any vendor, it must give the existing/default WEP-key somewhere.  Will every
   hardware product be flawed by his definition?


CAN-2001-0619

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010402 Design Flaw in Lucent/Orinoco 802.11 proprietary access control- closed network
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0015.html

Description:
The Lucent Closed Network protocol can allow remote attackers to join Closed Network networks which they do not have access to. The 'Network Name' or SSID, which is used as a shared secret to join the network, is transmitted in the clear.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REJECT(1) Ziese
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:orinoco-ap-plaintext-ssid(7005)


CAN-2001-0620

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010418 iplanet calendar server 5.0p2 exposes Netscape Admin Server master password
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-04/0320.html
Reference: XF:iplanet-calendar-plaintext-password(6402)
Reference: URL:http://xforce.iss.net/static/6402.php

Description:
iPlanet Calendar Server 5.0p2 and earlier allows a local attacker to gain access to the Netscape Admin Server (NAS) LDAP database and read arbitrary files by obtaining the cleartext administrator username and password from the configuration file, which has insecure permissions.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0623

Phase: Proposed (20010727)
Reference: DEBIAN:DSA-052
Reference: URL:http://www.debian.org/security/2001/dsa-052
Reference: XF:saft-sendfiled-execute-code(6430)
Reference: URL:http://xforce.iss.net/static/6430.php

Description:
sendfiled, as included with Simple Asynchronous File Transfer (SAFT), on various Linux systems does not properly drop privileges when sending notification emails, which allows local attackers to gain privileges.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(5) Wall, Foat, Cole, Bishop, Ziese
   REVIEWING(1) Christey
Voter Comments:
 CHANGE> [Bishop changed vote from REVIEWING to NOOP]
 Christey> Need to figure out if this is one or multiple problems.
   (See BIDs 2631, 2652, and 2645).


CAN-2001-0624

Phase: Proposed (20010727)
Reference: VULN-DEV:20010421 QNX FIle Read Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0266.html
Reference: XF:qnx-fat-file-read
Reference: URL:http://xforce.iss.net/static/6437.php

Description:
QNX 2.4 allows a local user to read arbitrary files by directly accessing the mount point for the FAT disk partition, e.g. /fs-dos.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Bishop

CAN-2001-0632

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html
Reference: BUGTRAQ:20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html

Description:
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.

Votes:

   ACCEPT(6) Williams, Cole, Prosser, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF: chilisoft-asp-unauthorized-access(6957)
 CHANGE> [Williams changed vote from ACCEPT to MODIFY]
 Williams> there are actually several issues here, not just the one mentioned in our description.  need to modify.
 CHANGE> [Williams changed vote from MODIFY to ACCEPT]
 Williams> NM my comments.  just saw the other CANs.  :/
 Prosser> 
   Vendor Response to issue:
   Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities
   http://www.securityfocus.com/archive/1/20010224172142.1888.qmail@securityfocus.com


CAN-2001-0633

Phase: Proposed (20010727)
Reference: BUGTRAQ:20010220 Advisory: Chili!Soft ASP Multiple Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0378.html
Reference: BUGTRAQ:20010224 Re: Advisory: Chili!Soft ASP Multiple Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-02/0443.html

Description:
Directory traversal vulnerability in Sun Chili!Soft ASP on multiple Unixes allows a remote attacker to read arbitrary files above the web root via a '..' (dot dot) attack in the sample script 'codebrws.asp'.

Votes:

   ACCEPT(4) Williams, Cole, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
   REVIEWING(1) Baker
Voter Comments:
 Frech> XF:chilisoft-asp-view-files(6137)


CAN-2001-0636

Phase: Proposed (20010829)
Reference: ISS:20010806 Multiple Buffer Overflow Vulnerabilities in Raytheon SilentRunner
Reference: URL:http://xforce.iss.net/alerts/advise91.php

Description:
Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in the Knowledge Browser component in SilentRunner 2.0 and 2.0.1. NOTE: It is highly likely that this candidate will be split into multiple candidates.

Votes:

   ACCEPT(3) Foat, Cole, Ziese
   MODIFY(1) Frech
   NOOP(3) Wall, Armstrong, Christey
   RECAST(2) Baker, Bishop
Voter Comments:
 Bishop> please split it into 2 candidates, one for the DoS and one 
   for the execute part
 Frech> XF:silentrunner-collector-popuser-bo(6795)
   XF:silentrunner-collector-poppass-bo(6796)
   XF:silentrunner-collector-httpurl-bo(6797)
 Baker> SPLIT
 Christey> Consider adding BID:3150
 Christey> Consider adding BID:3151


CAN-2001-0642

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010511 [eyeonsecurity.net] Incredimail allows automatic over writing offiles on your hard disk
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0078.html
Reference: XF:incredimail-dot-overwrite-files(6529)
Reference: URL:http://xforce.iss.net/static/6529.php

Description:
Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to filenames listed in the content.ini file.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Stracener, Ziese

CAN-2001-0643

Phase: Interim (20030326)
Reference: BUGTRAQ:20010416 Double clicking on innocent looking files may be dangerous
Reference: URL:http://www.securityfocus.com/archive/1/176909
Reference: MISC:http://vil.nai.com/vil/virusSummary.asp?virus_k=99048
Reference: MISC:http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html
Reference: XF:ie-clsid-execute-files(6426)
Reference: URL:http://xforce.iss.net/static/6426.php

Description:
A type-check flaw in Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Baker, Frech
   NOOP(2) Stracener, Ziese
Voter Comments:
 CHANGE> [Wall changed vote from REVIEWING to ACCEPT]


CAN-2001-0645

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x password restrictions
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0097.html
Reference: BUGTRAQ:20010510 Corsaire Limited Security Advisory - Symantec/Axent NetProwler 3. 5.x database configuration
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0098.html
Reference: XF:netprowler-default-odbc-password(6539)
Reference: URL:http://xforce.iss.net/static/6539.php
Reference: XF:netprowler-default-management-password(6537)
Reference: URL:http://xforce.iss.net/static/6537.php

Description:
Symantec/AXENT NetProwler 3.5.x contains several default passwords, which could allow remote attackers to (1) access to the management tier via the "admin" password, or (2) connect to a MySQL ODBC from the management tier using a blank password.

Votes:

   ACCEPT(5) Cole, Prosser, Baker, Frech, Ziese
   NOOP(2) Wall, Foat
Voter Comments:
 Prosser> Additional Reference
   http://www.sarc.com/avcenter/security/Content/2001_05_08.html
 Prosser> Add Symantec vendor advisory source
   http://securityresponse.symantec.com/avcenter/security/Content/2001_05_08.html


CAN-2001-0647

Phase: Proposed (20010912)
Reference: BUGTRAQ:20010227 Orange Web Server v2.1 DoS
Reference: URL:http://www.securityfocus.com/archive/1/165658
Reference: BID:20010227 Orange Web Server DoS Vulnerability
Reference: URL:http://www.securityfocus.com/bid/2432

Description:
Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version.

Votes:

   ACCEPT(2) Williams, Foat
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Stracener, Christey
Voter Comments:
 Frech> XF:orange-http-echo-dos(6164)
 Christey> Need to clean up BID, add other Bugtraq ref.


CAN-2001-0649

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010510 Personal Web Sharing remote stop
Reference: URL:http://www.securityfocus.com/archive/1/184548
Reference: XF:macos-web-sharing-dos(6536)
Reference: URL:http://xforce.iss.net/static/6536.php

Description:
Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.

Votes:

   ACCEPT(2) Frech, Ziese
   NOOP(4) Wall, Foat, Cole, Stracener

CAN-2001-0654

Phase: Assigned (20010815)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0655

Phase: Assigned (20010815)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0656

Phase: Assigned (20010815)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0657

Phase: Assigned (20010815)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0661

Phase: Assigned (20010815)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0669

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010905 %u encoding IDS bypass vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99972950200602&w=2
Reference: ISS:20010905 Multiple Vendor IDS Unicode Bypass Vulnerability
Reference: URL:http://xforce.iss.net/alerts/advise95.php
Reference: CISCO:20010905 Cisco Secure Intrusion Detection System Signature Obfuscation Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-intrusion-detection-obfuscation-vuln-pub.shtml

Description:
Various Intrusion Detection Systems (IDS) including (1) Cisco Secure Intrusion Detection System, (2) Cisco Catalyst 6000 Intrusion Detection System Module, (3) Dragon Sensor 4.x, (4) Snort before 1.8.1, (5) ISS RealSecure Network Sensor 5.x and 6.x before XPU 3.2, and (6) ISS RealSecure Server Sensor 5.5 and 6.0 for Windows, allow remote attackers to evade detection of HTTP attacks via non-standard "%u" Unicode encoding of ASCII characters in the requested URL.

Votes:

   ACCEPT(4) Balinsky, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:iis-unicode-encoding-detected(6994)
   XF:iis-unicode-wide-encoding(6995)


CAN-2001-0671

Phase: Proposed (20011122)
Reference: CERT:CA-2001-30
Reference: URL:http://www.cert.org/advisories/CA-2001-30.html
Reference: AIXAPAR:IY23037
Reference: AIXAPAR:IY23041
Reference: CERT-VN:VU#466239
Reference: URL:http://www.kb.cert.org/vuls/id/466239
Reference: CERT-VN:VU#388183
Reference: URL:http://www.kb.cert.org/vuls/id/388183
Reference: CERT-VN:VU#722143
Reference: URL:http://www.kb.cert.org/vuls/id/722143

Description:
Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.

Votes:

   ACCEPT(6) Foat, Cole, Armstrong, Baker, Bollinger, Bishop
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:aix-lpd-bo(7624)
   Suggest using following ref in addition to IBM AIXAPAR:
   http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-
   2001.391.1/$file/oar391.txt


CAN-2001-0672

Phase: Assigned (20010828)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0673

Phase: Assigned (20010828)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0674

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010417 Advisory for Viking
Reference: URL:http://www.securityfocus.com/archive/1/177231
Reference: CONFIRM:http://www.robtex.com/viking/bugs.htm
Reference: XF:viking-hex-directory-traversal(6394)
Reference: URL:http://xforce.iss.net/static/6394.php

Description:
Directory traversal vulnerability in RobTex Viking Web server before 1.07-381 allows remote attackers to read arbitrary files via a hexidecimal encoded dot-dot attack (eg. http://www.server.com/%2e%2e/%2e%2e) in an HTTP URL request.

Votes:

   ACCEPT(6) Foat, Cole, Stracener, Baker, Frech, Ziese
   NOOP(1) Wall

CAN-2001-0678

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010519 TrendMicro Interscan VirusWall RegGo.dll BOf
Reference: URL:http://www.securityfocus.com/archive/1/185383
Reference: XF:interscan-reggo-bo(6575)
Reference: URL:http://xforce.iss.net/static/6575.php

Description:
A buffer overflow in reggo.dll file used by Trend Micro InterScan VirusWall prior to 3.51 build 1349 for Windows NT 3.5 and InterScan WebManager 1.2 allows a local attacker to execute arbitrary code.

Votes:

   ACCEPT(5) Cole, Stracener, Baker, Frech, Ziese
   NOOP(2) Wall, Foat
   RECAST(1) Christey
Voter Comments:
 Christey> CD:SF-LOC may suggest merging with CAN-2001-0761
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> CONFIRM:http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionID=9590
   CONFIRM:http://solutionfile.trendmicro.com/SolutionFile/9590/en/PatchT3419.zip
   Also say it's the Serial Number field, as stated in
   ISVWNTBufferOverflowPatch.txt of the zip file.
   Since there is a separate patch for CAN-2001-0761 (though no
   build number), there is enough evidence to keep these
   2 candidates separate.
 CHANGE> [Christey changed vote from REVIEWING to RECAST]
 Christey> CONFIRM:http://download.antivirus.com/ftp/products/patches/isapi_security_patch_351b1360.zip
   
   This patch fixes a number of overflows in various DLL's,
   including RegGo.dll.  See Readme_ISNT_BufferOverflowPatchFiles.txt.
   By CD:SF-LOC, the same type of issue appears in the same
   versions, so CAN-2001-0678 must be RECAST to include the following
   *other* issues in 1512:
   (1) FtpSaveCSP.dll, (2) FtpSaveCVP.dll, (3)
   HttpSaveCSP.dll, (4) HttpSaveCVP.dll, (5) RegGo.dll, (6) ViewLog.dll,
   (7) ftpSaveCVP.dll, (8) patupd.dll, (9) smtpscan.dll, or (10)
   smtpscanCVP.dll.
   
   BUGTRAQ:20010612 [SNS Advisory No.31] Trend Micro InterScan VirusWall for Windows NT 3.51 FtpSaveC*P.dll Buffer Overflow Vulnerability
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0148.html
   XF:interscan-viruswall-ftpsave-bo(6698)
   URL:http://xforce.iss.net/static/6698.php


CAN-2001-0679

Phase: Proposed (20010912)
Reference: NTBUGTRAQ:19991108 Interscan VirusWall NT 3.23/3.3 buffer overflow.
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind9911&L=NTBUGTRAQ&P=R2331
Reference: NTBUGTRAQ:19991109 InterScan VirusWall 3.23/3.3 Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94216491202063&w=2
Reference: BUGTRAQ:19991108 Patch for VirusWall 3.23.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=94204166130782&w=2
Reference: NTBUGTRAQ:19991108 Patch for VirusWall 3.23.
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=94208143007829&w=2
Reference: XF:viruswall-helo-bo(3465)
Reference: URL:http://xforce.iss.net/static/3465.php

Description:
A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.

Votes:

   ACCEPT(3) Foat, Cole, Frech
   NOOP(1) Wall
   REJECT(1) Christey
Voter Comments:
 Christey> Whoops, DUPE CAN-1999-1529.


CAN-2001-0681

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010413 QPC FTPd Directory Traversal and BoF Vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/176712
Reference: XF:qpc-ftpd-bo(6376)
Reference: URL:http://xforce.iss.net/static/6376.php

Description:
Buffer overflow in ftpd in QPC QVT/Net 5.0 and QVT/Term 5.0 allows a remote attacker to cause a denial of service via a long (1) username or (2) password.

Votes:

   ACCEPT(2) Frech, Ziese
   MODIFY(1) Christey
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Christey> Consider adding 4.3 as an affected version for QVT/Net,
   as implied by the FTP banner in the Bugtraq post.


CAN-2001-0683

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010226 def-2001-08: Netscape Collabra DoS
Reference: URL:http://www.securityfocus.com/archive/1/165516
Reference: XF:netscape-collabra-kernel-dos(6158)
Reference: URL:http://xforce.iss.net/static/6158.php

Description:
Memory leak in Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service (memory exhaustion) by repeatedly sending approximately 5K of data to TCP port 5238.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-0684

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010226 def-2001-08: Netscape Collabra DoS
Reference: URL:http://www.securityfocus.com/archive/1/165516
Reference: XF:netscape-collabra-cpu-dos(6159)
Reference: URL:http://xforce.iss.net/static/6159.php

Description:
Netscape Collabra Server 3.5.4 and earlier allows a remote attacker to cause a denial of service by sending seven or more characters to TCP port 5239.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-0687

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal
Reference: URL:http://www.securityfocus.com/archive/1/190032
Reference: XF:broker-ftp-cd-directory-traversal(6674)
Reference: URL:http://xforce.iss.net/static/6674.php
Reference: BID:2853
Reference: URL:http://www.securityfocus.com/bid/2853

Description:
Broker FTP server 5.9.5 for Windows NT and 9x allows a remote attacker to retrieve privileged web server system information by (1) issuing a CD command (CD C:) followed by the LS command, (2) specifying arbitrary paths in the UNC format (\\computername\sharename).

Votes:

   ACCEPT(2) Frech, Ziese
   NOOP(4) Foat, Cole, Armstrong, Bishop
   REVIEWING(1) Wall

CAN-2001-0688

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010610 Broker FTP Server 5.9.5.0 Buffer Overflow / DoS / Directory Traversal
Reference: URL:http://www.securityfocus.com/archive/1/190032
Reference: BID:2851
Reference: URL:http://www.securityfocus.com/bid/2851

Description:
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or CWD ("CD . .") command.

Votes:

   ACCEPT(1) Ziese
   MODIFY(1) Frech
   NOOP(4) Foat, Cole, Armstrong, Bishop
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:broker-ftp-dot-bo(6673)


CAN-2001-0689

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010607 [SNS Advisory No.29] Trend Micro Virus Control System(VCS)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0065.html

Description:
Vulnerability in TrendMicro Virus Control System 1.8 allows a remote attacker to view configuration files and change the configuration via a certain CGI program.

Votes:

   ACCEPT(1) Ziese
   MODIFY(2) Christey, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
   REVIEWING(1) Bishop
Voter Comments:
 Frech> XF:vcs-cgi-auth-bypass(6677)
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]
 Christey> BID:2842
   URL:http://www.securityfocus.com/bid/2842


CAN-2001-0691

Phase: Modified (20020817-01)
Reference: MANDRAKE:MDKSA-2001:054
Reference: URL:http://www.securityfocus.com/advisories/3352
Reference: BID:2856
Reference: URL:http://www.securityfocus.com/bid/2856
Reference: REDHAT:RHSA-2001:094
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-094.html
Reference: XF:imap-ipop2d-ipop3d-bo(6269)
Reference: URL:http://www.iss.net/security_center/static/6269.php

Description:
Buffer overflows in Washington University imapd 2000a through 2000c could allow local users without shell access to execute code as themselves in certain configurations.

Votes:

   ACCEPT(6) Cole, Armstrong, Prosser, Baker, Bishop, Ziese
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Prosser> http://www.linux-mandrake.com/en/updates/2001/MDKSA-2001-054.php3?dis=7.1
 Frech> XF:imap-ipop2d-ipop3d-bo(6269)
 Christey> ADDREF RHSA-2001:094 (per Mark Cox of Red Hat)


CAN-2001-0693

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010603 Webtrends HTTP Server %20 bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99166905208903&w=2
Reference: BID:2812
Reference: URL:http://www.securityfocus.com/bid/2812
Reference: XF:webtrends-unicode-reveal-source(6639)
Reference: URL:http://xforce.iss.net/static/6639.php

Description:
WebTrends HTTP Server 3.1c and 3.5 allows a remote attacker to view script source code via a filename followed by an encoded space (%20).

Votes:

   ACCEPT(2) Frech, Ziese
   NOOP(4) Wall, Foat, Cole, Armstrong
   REVIEWING(1) Bishop

CAN-2001-0694

Phase: Proposed (20010829)
Reference: VULN-DEV:20010525 WFTPD 32-bit (X86) 3.00 R5 Directory Traversal / Buffer Overflow / DoS
Reference: URL:http://archives.neohapsis.com/archives/vuln-dev/2001-q2/0454.html

Description:
Directory traversal vulnerability in WFTPD 3.00 R5 allows a remote attacker to view arbitrary files via a dot dot attack in the CD command.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Ziese
Voter Comments:
 Frech> XF:wftpd-dir-traverse(5608)


CAN-2001-0695

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010503 Potential DOS Vulnerability in WFTPD
Reference: URL:http://www.securityfocus.com/archive/1/182054
Reference: XF:wftpd-cd-dos(6496)
Reference: URL:http://xforce.iss.net/static/6496.php

Description:
WFTPD 3.00 R5 allows a remote attacker to cause a denial of service by making repeated requests to cd to the floppy drive (A:\).

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Stracener, Ziese

CAN-2001-0702

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010621 Cerberus FTP Server 1.x Remote DoS attack Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/192655
Reference: BUGTRAQ:20010704 CesarFTPd, Cerberus FTPd
Reference: URL:http://www.securityfocus.com/archive/1/194914
Reference: BID:2901
Reference: URL:http://www.securityfocus.com/bid/2901
Reference: XF:cerberus-ftp-bo(6728)
Reference: URL:http://xforce.iss.net/static/6728.php

Description:
Cerberus FTP 1.5 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long (1) username, (2) password, or (3) PASV command.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(3) Wall, Foat, Armstrong
   REVIEWING(1) Bishop

CAN-2001-0703

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.
Reference: URL:http://www.securityfocus.com/archive/1/192651
Reference: XF:arcadia-tradecli-dos(6739)
Reference: URL:http://xforce.iss.net/static/6739.php
Reference: BID:2905
Reference: URL:http://www.securityfocus.com/bid/2905

Description:
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to cause a denial of service via a URL request with an MS-DOS device name in the template parameter.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(4) Wall, Foat, Armstrong, Bishop

CAN-2001-0704

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.
Reference: URL:http://www.securityfocus.com/archive/1/192651
Reference: XF:arcadia-tradecli-reveal-path(6738)
Reference: URL:http://xforce.iss.net/static/6738.php
Reference: BID:2904
Reference: URL:http://www.securityfocus.com/bid/2904

Description:
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory via a URL with a template argument for a file that does not exist.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(4) Wall, Foat, Armstrong, Bishop

CAN-2001-0705

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010621 NERF Advisory #2 - 1C:Arcadia multiple vulnerablilities.
Reference: URL:http://www.securityfocus.com/archive/1/192651
Reference: XF:arcadia-tradecli-directory-traversal(6737)
Reference: URL:http://xforce.iss.net/static/6737.php
Reference: BID:2902
Reference: URL:http://www.securityfocus.com/bid/2902

Description:
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitrary files on the web server via a URL with "dot dot" sequences in the template argument.

Votes:

   ACCEPT(3) Cole, Frech, Ziese
   NOOP(4) Wall, Foat, Armstrong, Bishop

CAN-2001-0707

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/183911
Reference: XF:denicomp-rshd-dos(6523)
Reference: URL:http://xforce.iss.net/static/6523.php

Description:
Denicomp RSHD 2.18 and earlier allows a remote attacker to cause a denial of service (crash) via a long string to port 514.

Votes:

   ACCEPT(5) Cole, Stracener, Baker, Frech, Ziese
   NOOP(2) Wall, Foat
Voter Comments:
 Stracener> 
   The vendor fixed the problem in RSHD/NT version 2.18.04. CONFIRM: http://www.denicomp.com/rshdnt.htm


CAN-2001-0708

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010503 Denicomp REXECD/RSHD Denial of Service Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/183911
Reference: XF:denicomp-rexecd-dos(6524)
Reference: URL:http://xforce.iss.net/static/6524.php

Description:
Denicomp REXECD 1.05 and earlier allows a remote attacker to cause a denial of service (crash) via a long string.

Votes:

   ACCEPT(5) Cole, Stracener, Baker, Frech, Ziese
   NOOP(2) Wall, Foat
Voter Comments:
 Stracener> CONFIRM: http://www.denicomp.com/rexecdnt.htm


CAN-2001-0709

Phase: Proposed (20010829)
Reference: BUGTRAQ:20010622 [VIGILANTE-2001001] ASP source code retrieved with Unicode extens ion
Reference: URL:http://www.securityfocus.com/archive/1/192802
Reference: BID:2909
Reference: URL:http://www.securityfocus.com/bid/2909
Reference: XF:iis-unicode-asp-disclosure(6742)
Reference: URL:http://xforce.iss.net/static/6742.php

Description:
Microsoft IIS 4.0 and before, when installed on a FAT partition, allows a remote attacker to obtain source code of ASP files via a URL encoded with Unicode.

Votes:

   ACCEPT(3) Foat, Frech, Ziese
   NOOP(3) Cole, Armstrong, Bishop
   REVIEWING(1) Wall
Voter Comments:
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-2001-0711

Phase: Modified (20020228-01)
Reference: CISCO:20010207 Cisco IOS Software SNMP Read-Write ILMI Community String Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/ios-snmp-ilmi-vuln-pub.shtml
Reference: XF:cisco-ios-modify-snmp(6169)
Reference: URL:http://xforce.iss.net/static/6169.php

Description:
Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Local Management Interface (ILMI) SNMP community string.

Votes:

   ACCEPT(5) Balinsky, Foat, Cole, Stracener, Baker
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:cisco-ios-modify-snmp(6169)


CAN-2001-0712

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010727 TXT or HTML? -- IE NEW BUG
Reference: URL:http://www.securityfocus.com/archive/1/200109
Reference: BUGTRAQ:20010729 Re: TXT or HTML? -- IE NEW BUG
Reference: URL:http://www.securityfocus.com/archive/1/200291
Reference: BID:3116
Reference: URL:http://www.securityfocus.com/bid/3116

Description:
The rendering engine in Internet Explorer determines the MIME type independently of the type that is specified by the server, which allows remote servers to automatically execute script which is placed in a file whose MIME type does not normally support scripting, such as text (.txt), JPEG (.jpg), etc.

Votes:

   ACCEPT(2) Cole, Baker
   NOOP(1) Armstrong
   REJECT(2) Foat, Frech
   REVIEWING(1) Wall
Voter Comments:
 Baker> I would argue that a browser executing a script when it shouldn't is still a vulnerability.  If it is supposed to be a non-scriptable file type, and that fails, resulting in a script being executed without the user's knowledge, then it is a problem, and thus should be included as a vulnerability.  I vote this should be accepted, and if Microsoft acknowledges this in their follow up, then you have vendor acknowledgement of the problem as well.
 Foat> The candidate does not meet the criteria for a vulnerability or 
   exposure, even though it describes an unexpected behavior.


CAN-2001-0713

Phase: Proposed (20011012)
Reference: BINDVIEW:20011001 Multiple Local Sendmail Vulnerabilities
Reference: URL:http://razor.bindview.com/publish/advisories/adv_sm812.html

Description:
Sendmail before 8.12.1 does not properly drop privileges when the -C option is used to load custom configuration files, which allows local users to gain privileges via malformed arguments in the configuration file whose names contain characters with the high bit set, such as (1) macro names that are one character long, (2) a variable setting which is processed by the setoption function, or (3) a Modifiers setting which is processed by the getmodifiers function.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:sendmail-setregid-gain-privileges(7192)
 Christey> Consider adding BID:3377
 Christey> BID:3377
   URL:http://www.securityfocus.com/bid/3377


CAN-2001-0714

Phase: Proposed (20011012)
Reference: BINDVIEW:20011001 Multiple Local Sendmail Vulnerabilities
Reference: URL:http://razor.bindview.com/publish/advisories/adv_sm812.html

Description:
Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to cause a denial of service (data loss) by (1) setting a high initial message hop count option (-h), which causes Sendmail to drop queue entries, (2) via the -qR option, or (3) via the -qS option.

Votes:

   ACCEPT(6) Wall, Foat, Cole, Armstrong, Prosser, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:sendmail-queue-dos(7190)
 Christey> ADDREF SGI:20011101-01-I
 Christey> CALDERA:CSSA-2001-034.0
   URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-034.0.txt
   BID:3378
   URL:http://www.securityfocus.com/bid/3378
   CIAC:M-020
   URL:http://ciac.llnl.gov/ciac/bulletins/m-020.shtml


CAN-2001-0715

Phase: Proposed (20011012)
Reference: BINDVIEW:20011001 Multiple Local Sendmail Vulnerabilities
Reference: URL:http://razor.bindview.com/publish/advisories/adv_sm812.html

Description:
Sendmail before 8.12.1, without the RestrictQueueRun option enabled, allows local users to obtain potentially sensitive information about the mail queue by setting debugging flags to enable debug mode.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:sendmail-debug-gain-information(7191)
 Christey> ADDREF SGI:20011101-01-I
 Christey> CIAC:M-020
   URL:http://ciac.llnl.gov/ciac/bulletins/m-020.shtml
   HP:HPSBUX0201-179
   URL:http://www.securityfocus.com/advisories/3794
   BID:3898
   URL:http://www.securityfocus.com/bid/3898
   It *might* be that HP:HPSBUX0201-179 addresses this, but the
   advisory is too vague to be certain.
   URL:http://www.securityfocus.com/advisories/3794


CAN-2001-0721

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011101 Three Windows XP UPNP DOS attacks
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100467787323377&w=2
Reference: BUGTRAQ:20011109 Important Information Regarding MS01-054 and WindowsME
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100528449024158&w=2
Reference: MS:MS01-054
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS01-054.asp

Description:
Universal Plug and Play (UPnP) in Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service (memory consumption or crash) via a malformed UPnP request.

Votes:

   ACCEPT(3) Wall, Foat, Cole
   MODIFY(1) Frech
   NOOP(1) Christey
   RECAST(3) Armstrong, Baker, Bishop
Voter Comments:
 Bishop> I agree that these should be split, as the abstraction says.
 Frech> XF:win-upnp-dos(7428)
 Baker> SPLIT
 Armstrong> SPLIT
 Christey> Consider adding BID:3499
 Christey> CIAC:M-015
   URL:http://www.ciac.org/ciac/bulletins/m-015.shtml
   XF:win-upnp-dos(7428)
   URL:http://www.iss.net/security_center/static/7428.php
   BID:3499
   URL:http://www.securityfocus.com/bid/3499


CAN-2001-0725

Phase: Assigned (20010927)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0729

Phase: Modified (20011016-01)
Reference: CONFIRM:http://www.apacheweek.com/issues/01-09-28#security

Description:
Apache 1.3.20 on Windows servers allows remote attackers to bypass the default index page and list directory contents via a URL with a large number of / (slash) characters.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> The initial description originally stated that this was a
   denial of service, but it's really a directory listing
   problem.  I changed the description accordingly.
 Frech> XF:apache-slash-directory-listing(6921)
 Christey> XF:apache-slash-directory-listing(6921) is identifying a
   different issue that has not had a CAN assigned yet.
 Christey> SGI:20020301-01-P
   URL:ftp://patches.sgi.com/support/free/security/advisories/20020301-01-P
 Christey> CAN-2001-0925 and CAN-2001-0729 are different issues.
   CAN-2001-0925 only applies to versions before 1.3.19, whereas
   CAN-2001-0729 applies to 1.3.20, and only Windows.
   
   The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3
   specifically mentions these CANs separately.


CAN-2001-0734

Phase: Proposed (20011012)
Reference: NETBSD:NetBSD-SA2001-008
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-008.txt.asc
Reference: BID:2810
Reference: URL:http://www.securityfocus.com/bid/2810
Reference: XF:bsd-sh3-sigreturn-privileges(6637)
Reference: URL:http://xforce.iss.net/static/6637.php

Description:
Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Baker, Frech
   NOOP(1) Wall

CAN-2001-0735

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010621 cfingerd local vulnerability (possibly root)
Reference: URL:http://www.securityfocus.com/archive/1/192844
Reference: BUGTRAQ:20010711 Another exploit for cfingerd <= 1.4.3-8
Reference: URL:http://www.securityfocus.com/archive/1/01071120191900.00788@localhost.localdomain
Reference: DEBIAN:DSA-066
Reference: URL:http://www.debian.org/security/2001/dsa-066
Reference: BID:2914
Reference: URL:http://www.securityfocus.com/bid/2914
Reference: XF:cfingerd-util-bo(6744)
Reference: URL:http://xforce.iss.net/static/6744.php

Description:
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.

Votes:

   ACCEPT(4) Foat, Armstrong, Baker, Frech
   NOOP(2) Wall, Cole

CAN-2001-0736

Phase: Proposed (20011012)
Reference: REDHAT:RHSA-2001:042-02
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-042.html
Reference: MANDRAKE:MDKSA-2001:047
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-047.php3?dis=8.0
Reference: BUGTRAQ:20010527 [ESA-20010509-01] pine temporary file handling vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99106787825229&w=2
Reference: BUGTRAQ:20010416 Immunix OS Security update for pine
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98749102621604&w=2
Reference: XF:pine-tmp-file-symlink(6367)
Reference: URL:http://xforce.iss.net/static/6367.php

Description:
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.

Votes:

   ACCEPT(6) Wall, Foat, Cole, Armstrong, Baker, Frech
   NOOP(1) Christey
Voter Comments:
 Christey> Remove version number from REDHAT reference.
 Christey> Fix typo: "local users local users"


CAN-2001-0737

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010516 logitech wireless devices: man-in-the-middle attack
Reference: URL:http://www.securityfocus.com/archive/1/185003
Reference: BUGTRAQ:20010522 Logitech vulnerability (DoS, man-in-the-middle-attack) - Resend
Reference: URL:http://www.securityfocus.com/archive/1/3B0A36C8.E9D8610@daten-treuhand.de
Reference: XF:logitech-wireless-unauthorized-access(6562)
Reference: URL:http://xforce.iss.net/static/6562.php
Reference: BID:2738
Reference: URL:http://www.securityfocus.com/bid/2738

Description:
A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle attack.

Votes:

   ACCEPT(3) Foat, Armstrong, Frech
   NOOP(2) Wall, Cole

CAN-2001-0741

Phase: Interim (20030326)
Reference: BUGTRAQ:20010503 Cisco HSRP Weakness/DoS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0035.html
Reference: MISC:http://www.cisco.com/networkers/nw00/pres/2402.pdf
Reference: XF:cisco-hsrp-dos(6497)
Reference: URL:http://xforce.iss.net/static/6497.php
Reference: BID:2684
Reference: URL:http://www.securityfocus.com/bid/2684

Description:
Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.

Votes:

   ACCEPT(3) Foat, Armstrong, Frech
   NOOP(2) Wall, Cole

CAN-2001-0742

Phase: Proposed (20011012)
Reference: MISC:http://www.securiteam.com/windowsntfocus/5UP0B204AY.html

Description:
Buffer overflow in Computalynx CMail POP3 mail server 2.4.9 allows remote attackers to run arbitrary code via a long HELO command.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:cmail-helo-bo(7406)


CAN-2001-0743

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010602 O'Reilly WebBoard 4.10.30 JavaScript code execution problem
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0326.html
Reference: BID:2814
Reference: URL:http://www.securityfocus.com/bid/2814

Description:
Paging function in O'Reilly WebBoard Pager 4.10 allows remote attackers to cause a denial of service via a message with an escaped ' character followed by JavaScript commands.

Votes:

   MODIFY(1) Frech
   NOOP(6) Oliver, Wall, Foat, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:webboard-pager-javascript-dos(6653)
 Christey> Need to re-examine this; sounds like XSS to me on a second
   glance at the Bugtraq post.


CAN-2001-0744

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010531 Imp-2.2.4 temporary files
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0303.html
Reference: CONFIRM:http://www.horde.org/imp/2.2/news.php
Reference: CALDERA:CSSA-2001-025.0
Reference: URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-025.0.txt

Description:
Horde IMP 2.2.4 and earlier allows local users to overwrite files via a symlink attack on a temporary file.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:horde-popen-remote-access(5244)
 Christey> Need to examine the codebase relationship between Horde and
   IMP.
 Christey> BID:3066
   URL:http://online.securityfocus.com/bid/3066


CAN-2001-0746

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010515 iPlanet - Netscape Enterprise Web Publisher Buffer Overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0132.html
Reference: CONFIRM:http://iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html
Reference: XF:netscape-enterprise-uri-bo(6554)
Reference: URL:http://xforce.iss.net/static/6554.php
Reference: BID:2732
Reference: URL:http://www.securityfocus.com/bid/2732

Description:
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods.

Votes:

   ACCEPT(6) Wall, Foat, Cole, Armstrong, Baker, Frech
   NOOP(1) Christey
Voter Comments:
 Christey> HP:HPSBUX0106-152 might address CAN-2001-0746 or
   CAN-2001-0747, or maybe neither, but only HP knows for sure.
   See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html
 Christey> I am about to create a separate candidate for the HP advisory.
   Obviously that advisory is affected by CD:VAGUE.


CAN-2001-0747

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010518 Netscape Enterprise Server 4 Method and URI overflow
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0203.html
Reference: CONFIRM:http://www.iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html

Description:
Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of sevice and possibly execute arbitrary code via a long method name in an HTTP request.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:netscape-enterprise-uri-bo(6554)
 Christey> HP:HPSBUX0106-152 might address CAN-2001-0746 or
   CAN-2001-0747, or maybe neither, but only HP knows for sure.
   See: http://archives.neohapsis.com/archives/hp/2001-q2/0059.html
 Christey> I am about to create a separate candidate for the HP advisory.
   Obviously that advisory is affected by CD:VAGUE.


CAN-2001-0749

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010524 IPC@Chip Security
Reference: URL:http://www.securityfocus.com/archive/1/186418
Reference: BID:2775
Reference: URL:http://www.securityfocus.com/bid/2775

Description:
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attacker to retrieve arbitrary files via webserver root directory set to system root.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Armstrong
Voter Comments:
 Frech> XF:ipcchip-web-root-system(8922)


CAN-2001-0753

Phase: Proposed (20011012)
Reference: CISCO:20010522 More Multiple Vulnerabilities in CBOS
Reference: URL:http://www.cisco.com/warp/public/707/CBOS-multiple2-pub.html

Description:
Cisco CBOS 2.3.8 and earlier stores the passwords for (1) exec and (2) enable in cleartext in the NVRAM and a configuration file, which could allow unauthorized users to obtain the passwords and gain privileges.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:cisco-cbos-gain-information(6453)


CAN-2001-0755

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010518 Tamersahin.net Security Announcement: Debian 2.2 is 2.2r3 Ftpd Daemon Buffer Owerflow Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0188.html

Description:
Buffer overflow in ftp daemon (ftpd) 6.2 in Debian Linux allows attackers to cause a denial of service and possibly execute arbitrary code via a long SITE command.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:linux-ftpd-site-bo(7414)


CAN-2001-0756

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010607 cgisecurity.com Advisory #5
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0067.html
Reference: BUGTRAQ:20010611 re: Advisory #5 Corrections.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99237435902211&w=2

Description:
CatalogMgr.pl in VirtualCatalog (incorrectly claimed to be in VirtualCart) allows remote attackers to execute arbitrary code via the template parameter.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:virtualcatalog-command-execution(6663)


CAN-2001-0758

Phase: Proposed (20011012)
Reference: MISC:http://www.securiteam.com/windowsntfocus/5SP011P4KC.html

Description:
Directory traversal vulnerability in Shambala 4.5 allows remote attackers to escape the FTP root directory via "CWD ..." command.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:shambala-ftp-cwd-directory-traversal(7418)
 Christey> Other .. problems were found in 4.5 as described in:
   BUGTRAQ:20020530 [[ TH 026 Inc. ]] SA #3 - Shambala Server 4.5, Directory Traversal and DoS
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0282.html
   CD:SF-LOC might suggest merging these two.  (I'm working
   on creating a CAN for the newer discovery).


CAN-2001-0759

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010614 Buffer overflow in BestCrypt for Linux
Reference: URL:http://www.securityfocus.com/archive/1/191111
Reference: BID:2875
Reference: URL:http://www.securityfocus.com/bid/2875

Description:
Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file or directory with a long pathname, which is processed during an unmount.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:bestcrypt-bctool-bo(6690)


CAN-2001-0761

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010702 [SNS Advisory No.36] TrendMicro InterScan WebManager Version 1.2 HttpSave.dll Buffer Overflow Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/194463
Reference: BID:2959
Reference: URL:http://www.securityfocus.com/bid/2959

Description:
Buffer overflow in HttpSave.dll in Trend Micro InterScan WebManager 1.2 allows remote attackers to execute arbitrary code via a long value to a certain parameter.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Christey> CD:SF-LOC may suggest merging with CAN-2001-0678
 Frech> XF:interscan-webmanager-httpsave-bo(6788)
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> There is evidence that this problem was confirmed by Trend,
   but there are some inconsistencies.
   MISC:http://solutionbank.antivirus.com/solutions/solutionDetail.asp?solutionID=9682
   Note, however, that the date of the patch description at
   MISC:http://solutionfile.trendmicro.com/SolutionFile/9682/en/ReadMe-BufferOverflowPatch.txt
   is June 19th, but the Bugtraq post was July 2, and the poster
   said that a patch had not been available yet.  However, the
   poster also said that they had notified Trend on June 11.
   Add that the Action parameter is the one with the overflow.
   
   This patch description only identifies HttpSave.dll, not
   RegGo.dll (as identified by CAN-2001-0678), but it implies
   that multiple DLL's may have been fixed.  Looking at the DLL's
   in the patch, there is RegGo.dll and a number of other DLL's.
   However, this RegGo.dll is different than the one from
   the patch for CAN-2001-0678, so maybe they fixed yet another
   problem here.
   
   That problem might be:
   BUGTRAQ:20010621 TrendMicro InterScan WebManager Version 1.2 RegGo.dll Buffer Overflow Vulnerability
   URL:http://www.securityfocus.com/archive/1/192645
   where the discloser said that the problem was discovered
   in June 6 and implied that Trend Micro would fix the problem,
   so Trend was notified sometime between June 6 and June 21.
   So, the dates might imply that Trend fixed both the
   HTTPSave.dll and this variant (if in fact it's a variant and
   not a rediscovery of CAN-2001-0678) in a single patch.
   If true, then that would argue that this candidate should be 
   merged with the RegGo.dll variant reported in the above
   Bugtraq reference, along with some of the other DLL's - just
   in case someone rediscovers THOSE, too.
   
   Other DLL's in this patch are covered in other posts
   in the same time frame by the same person.
   HttpSaveCVP.dll and HttpSaveCSP.dll are in:
   BUGTRAQ:20010628 [SNS Advisory No.35] TrendMicro InterScan VirusWall 3.51 HttpSaveC*P.dll Buffer Overflow
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0388.html
   smtpscan.dll is described in:
   BUGTRAQ:20010628 [SNS Advisory No.34] TrendMicro InterScan VirusWall 3.51 smtpscan.dll Buffer Overflow
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0387.html


CAN-2001-0762

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010602 su-wrapper 1.1.1 Local root exploit.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0057.html

Description:
Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument.

Votes:

   MODIFY(2) Christey, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:suid-wrapper-argument-bo(6675)
 Christey> Add "suid wrapper" to desc.
   ADDREF BID:2837
   URL:http://www.securityfocus.com/bid/2837


CAN-2001-0766

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010610 Mac OS X - Apache & Case Insensitive Filesystems
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0090.html
Reference: BID:2852
Reference: URL:http://www.securityfocus.com/bid/2852

Description:
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a URL that contains some characters whose case is not matched by Apache's filters.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:macos-apache-file-disclosure(6687)
 Christey> CERT-VN:VU#439395
   URL:http://www.kb.cert.org/vuls/id/439395


CAN-2001-0767

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010526 GuildFTPD v0.97 Directory Traversal / Weak password encryption
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0250.html
Reference: MISC:http://www.nitrolic.com/
Reference: BID:2789
Reference: URL:http://www.securityfocus.com/bid/2789

Description:
Directory traversal vulnerability in GuildFTPd 0.9.7 allows attackers to list or read arbitrary files and directories via a .. in (1) LS or (2) GET.

Votes:

   ACCEPT(3) Foat, Cole, Armstrong
   NOOP(2) Wall, Christey
   REJECT(1) Frech
Voter Comments:
 Frech> DUPE CVE-2000-0640
 Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002


CAN-2001-0768

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010526 GuildFTPD v0.97 Directory Traversal / Weak password encryption
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0250.html
Reference: BID:2792
Reference: URL:http://www.securityfocus.com/bid/2792
Reference: XF:guildftpd-usr-plaintext-passwords(6611)
Reference: URL:http://xforce.iss.net/static/6611.php

Description:
GuildFTPd 0.9.7 stores user names and passwords in plaintext in the default.usr file, which allows local users to gain privileges as other FTP users by reading the file.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Christey
Voter Comments:
 Baker> Vendor added password encryption in latest version, 0.996, and you can see the comments in the changes log, at the following URL:
   
   www.nitrolic.com/main.htm
 Christey> Email ack received from guildftpd@nitrolic.com on 3/8/2002


CAN-2001-0771

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010521 SpyAnywhere Authentication Bypassing Vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/186006
Reference: BID:2755
Reference: URL:http://www.securityfocus.com/bid/2755
Reference: XF:spyanywhere-weak-authentication(6578)
Reference: URL:http://xforce.iss.net/static/6578.php

Description:
Spytech SpyAnywhere 1.50 allows remote attackers to gain administrator access via a a single character in the "loginpass" field.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Christey
Voter Comments:
 Christey> fix typo: "a a"


CAN-2001-0772

Phase: Proposed (20011012)
Reference: HP:HPSBUX0105-151
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q2/0044.html
Reference: XF:hpux-cde-bo(6585)
Reference: URL:http://xforce.iss.net/static/6585.php

Description:
Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.

Votes:

   ACCEPT(4) Foat, Cole, Baker, Frech
   NOOP(2) Wall, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 Christey> There is some overlap between CAN-2001-0551 and CAN-2001-0772.
   CAN-2001-0551 describes a specific vulnerability in
   dtprintinfo.  HP acknowledges CAN-2001-0551 by stating
   that the problem is fixed in HP:HPSBUX0105-151, which
   is CAN-2001-0772.  But CAN-2001-0772 is a vague advisory
   that identifies other vulnerabilities (and vulnerability
   types) besides CAN-2001-0551.  Perhaps CAN-2001-0772 should
   be RECAST to "remove" the reference to dtprintinfo and
   leave the other vague descriptions.  CAN-2001-0772 and
   CAN-2001-0551 are very good examples of the problems that
   CVE faces in being consistent with respect to the level of
   abstraction, as documented in the CD:SF-CODEBASE, CD:SF-LOC,
   and CD:VAGUE content decisions.


CAN-2001-0775

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20010710 xloadimage remote exploit - tstot.c
Reference: URL:http://www.securityfocus.com/archive/1/195823
Reference: DEBIAN:DSA-069
Reference: URL:http://www.debian.org/security/2001/dsa-069
Reference: SUSE:SA:2001:024
Reference: URL:http://www.suse.de/de/support/security/2001_024_xli_txt.txt
Reference: REDHAT:RHSA-2001:088
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-088.html
Reference: BID:3006
Reference: URL:http://www.securityfocus.com/bid/3006
Reference: XF:xloadimage-faces-bo(6821)
Reference: URL:http://www.iss.net/security_center/static/6821.php

Description:
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attacker to execute arbitrary code via a FACES format image containing a long (1) Firstname or (2) Lastname field.

Votes:

   ACCEPT(3) Foat, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Christey
Voter Comments:
 Frech> XF:xloadimage-faces-bo(6821)
 Christey> ADDREF RHSA-2001:088 (per Mark Cox of Red Hat)


CAN-2001-0776

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010526 DynFX POPd Denial of Service Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0278.html
Reference: BID:2781
Reference: URL:http://www.securityfocus.com/bid/2781
Reference: XF:dynfx-mailserver-pop3-bo(6615)
Reference: URL:http://xforce.iss.net/static/6615.php

Description:
Buffer overflow in DynFX MailServer version 2.10 allows remote attackers to conduct a denial of service via a long username to the POP3 service.

Votes:

   ACCEPT(2) Armstrong, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-0777

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010526 Remote vulnerabilities in OmniHTTPd
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0248.html
Reference: XF:omnihttpd-php-request-dos(6620)
Reference: URL:http://xforce.iss.net/static/6620.php
Reference: BID:2783
Reference: URL:http://www.securityfocus.com/bid/2783

Description:
Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0778

Phase: Modified (20020225-01)
Reference: BUGTRAQ:20010525 Remote vulnerabilities in OmniHTTPd
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0248.html
Reference: CONFIRM:http://www.omnicron.ca/httpd/docs/release.html
Reference: XF:omnihttpd-reveal-source-code(6621)
Reference: URL:http://xforce.iss.net/static/6621.php

Description:
OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0780

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010527 directorypro.cgi , directory traversal
Reference: URL:http://www.securityfocus.com/archive/1/187182
Reference: BID:2793
Reference: URL:http://www.securityfocus.com/bid/2793

Description:
Directory traversal vulnerability in cosmicpro.cgi in Cosmicperl Directory Pro 2.0 allows remote attacker to gain sensitive information via a .. (dot dot) in the SHOW parameter.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:directory-pro-directory-traversal(6632)
   All references point to CGI with the name of
   directorypro.cgi, not cosmicpro.cgi as listed in description.
 Christey> Not sure how cosmicpro.cgi got in there.  It should be
   directorypro.cgi as indicated by Andre.


CAN-2001-0781

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010530 SpoonFTP Buffer Overflow Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0296.html
Reference: XF:spoonftp-cwd-list-bo(6630)
Reference: URL:http://xforce.iss.net/static/6630.php

Description:
Buffer overflow in SpoonFTP 1.0.0.12 allows remote attacker to execute arbitrary code via a long argument to the commands (1) CWD or (2) LIST.

Votes:

   ACCEPT(3) Foat, Armstrong, Frech
   NOOP(2) Wall, Cole

CAN-2001-0782

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010622 Symlinks symlinks...this time KTVision
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0302.html
Reference: XF:ktvision-symlink(6741)
Reference: URL:http://xforce.iss.net/static/6741.php

Description:
KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configuration file.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0783

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010618 Cisco TFTPD 1.1 Vulerablity
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0227.html
Reference: BID:2886
Reference: URL:http://www.securityfocus.com/bid/2886

Description:
Cisco TFTP server 1.1 allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command.

Votes:

   ACCEPT(1) Foat
   MODIFY(1) Frech
   NOOP(4) Oliver, Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:cisco-tftp-directory-traversal(6722)


CAN-2001-0785

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010618 Multiple Vulnerabilities In AMLServer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0228.html
Reference: BID:2883
Reference: URL:http://www.securityfocus.com/bid/2883

Description:
Directory traversal in Webpaging interface in Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows allows remote attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:amlserver-directory-traversal(6708)


CAN-2001-0786

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010618 Multiple Vulnerabilities In AMLServer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0228.html
Reference: BID:2882
Reference: URL:http://www.securityfocus.com/bid/2882

Description:
Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 stores user passwords in plaintext in the pUser.Dat file.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:amlserver-plaintext-password(6709)


CAN-2001-0788

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010618 Multiple Vulnerabilities In AMLServer
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0228.html
Reference: BID:2881
Reference: URL:http://www.securityfocus.com/bid/2881

Description:
Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute path for the server directory by viewing the Location header.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:amlserver-reveals-path(6710)


CAN-2001-0789

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010621 SECURITY.NNOV: KAV (AVP) for sendmail format string vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0274.html

Description:
Format string vulnerability in avpkeeper in Kaspersky KAV 3.5.135.2 for Sendmail allows remote attacker to cause a denial of service or possibly execute arbitrary code via a malformed mail message.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:kav-avpkeeper-format-string(6727)


CAN-2001-0790

Phase: Proposed (20011012)
Reference: WIN2KSEC:20010527
Reference: URL:http://archives.neohapsis.com/archives/win2ksecadvice/2001-q2/0071.html

Description:
Specter IDS version 4.5 and 5.0 allows a remote attacker to cause a denial of service (CPU exhaustion) via a port scan, which causes the server to consume CPU while preparing alerts.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:specter-ids-portscan-dos(7415)


CAN-2001-0791

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010531 [SNS Advisory No.28]InterScan VirusWall for NT remote configuration
Reference: URL:http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00006.html

Description:
Trend Micro InterScan VirusWall for Windows NT allows remote attackers to make configuration changes by directly calling certain CGI programs, which do not restrict access.

Votes:

   MODIFY(1) Frech
   NOOP(3) Foat, Cole, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:interscan-viruswall-change-configuration(6641)


CAN-2001-0792

Phase: Modified (20020226-01)
Reference: MISC:http://www.securiteam.com/exploits/5AP0Q2A4AQ.html
Reference: XF:xchat-nickname-format-string(7416)
Reference: URL:http://xforce.iss.net/static/7416.php

Description:
Format string vulnerability in XChat 1.2.x allows remote attackers to execute arbitrary code via a malformed nickname.

Votes:

   ACCEPT(2) Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Frech> XF:xchat-nickname-format-string(7416)
 Christey> Inquiry sent to xchat developer on 2/25/2002.
 Christey> Received a reply 2/26/2002: "I don't know...  It doesn't seem
   to effect [sic] any recent versions though."
   
   This vulnerability was reported for a *MUCH* older version.


CAN-2001-0794

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010621 A-FTP Anonymous FTP Server Remote DoS attack Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0280.html

Description:
Buffer overflow in A-FTP Anonymous FTP Server allows remote attackers to cause a denial of service via a long USER command.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:softhead-aftp-bo(6729)


CAN-2001-0795

Phase: Proposed (20011012)
Reference: BUGTRAQ:20010625 Perception LiteServe MS-DOS filename vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0328.html
Reference: BID:2926
Reference: URL:http://www.securityfocus.com/bid/2926

Description:
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs that contain MS-DOS conventions such as (1) upper case letters or (2) 8.3 file names.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:perception-liteserve-reveal-code(6747)


CAN-2001-0798

Phase: Assigned (20011025)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0799

Phase: Proposed (20011122)
Reference: MISC:http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2
Reference: SGI:20011003-02-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20011003-02-P

Description:
Buffer overflows in lpsched in IRIX 6.5.13f and earlier allow remote attackers to execute arbitrary commands via a long argument.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF;irix-lpsched-bo(7641)


CAN-2001-0800

Phase: Proposed (20011122)
Reference: MISC:http://www.lsd-pl.net/files/get?IRIX/irx_lpsched2
Reference: SGI:20011003-02-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20011003-02-P

Description:
lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF;irix-lpsched-execute-commands(7642)


CAN-2001-0802

Phase: Assigned (20011025)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0807

Phase: Modified (20020226-01)
Reference: BUGTRAQ:20010606 security bug Internet Explorer 5
Reference: URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=189341
Reference: XF:ie-local-file-disclosure(6688)
Reference: URL:http://xforce.iss.net/static/6688.php

Description:
Internet Explorer 5.0, and possibly other versions, may allow remote attackers (malicious web pages) to read known text files from a client's hard drive via a SCRIPT tag with a SRC value that points to the text file.

Votes:

   ACCEPT(3) Cole, Prosser, Baker
   MODIFY(1) Frech
   NOOP(4) Foat, Armstrong, Christey, Bishop
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:ie-local-file-disclosure(6688)
 Prosser> Legacy product, users should have updated.
   Courtesy of Microsoft Security Response Center <secure@microsoft.com>:
   
   IE 5 is no longer supported - so unless this repro's on 5.01 or 5.5, we wouldn't consider doing anything for this.
 Christey> ADDREF BID:2836
   URL:http://www.securityfocus.com/bid/2836


CAN-2001-0808

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010627 gnats update
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0365.html
Reference: CONFIRM:http://sources.redhat.com/gnats/gnatsweb/advisory-jun-26-2001.html
Reference: XF:gnatsweb-helpfile-execute-commands(6753)
Reference: URL:http://xforce.iss.net/static/6753.php

Description:
gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.

Votes:

   ACCEPT(4) Cole, Baker, Frech, Bishop
   NOOP(3) Wall, Foat, Armstrong
Voter Comments:
 Bishop> If the SPECIFIC nature of the problem is determined to be both, I would
   accept two separate candidates. But in the absence of this information,
   I favor accepting it now rather than waiting for details. We can always
   revisit it later.


CAN-2001-0809

Phase: Proposed (20011122)
Reference: HP:HPSBUX0106-155
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q2/0074.html

Description:
Vulnerability in CIFS/9000 Server (SAMBA) A.01.06 and earlier in HP-UX 11.0 and 11.11, when configured as a print server, allows local users to overwrite arbitrary files by modifying certain resources.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Bishop
   NOOP(1) Wall
   REJECT(1) Frech
Voter Comments:
 Frech> See XF:samba-tmpfile-symlink(6396). 
   Discovery and advisory are two months apart, and no other Samba
   issues seem to exist around that timespan.


CAN-2001-0810

Phase: Assigned (20011109)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0811

Phase: Assigned (20011109)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0812

Phase: Assigned (20011109)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0813

Phase: Assigned (20011109)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0814

Phase: Assigned (20011109)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0817

Phase: Modified (20020226-01)
Reference: ISS:20011120 Remote Logic Flaw Vulnerability in HP-UX Line Printer Daemon
Reference: URL:http://xforce.iss.net/alerts/advise102.php
Reference: HP:HPSBUX0111-176
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q4/0047.html
Reference: CERT:CA-2001-32
Reference: URL:http://www.cert.org/advisories/CA-2001-32.html
Reference: CERT-VN:VU#638011
Reference: URL:http://www.kb.cert.org/vuls/id/638011
Reference: CIAC:M-021
Reference: URL:http://www.ciac.org/ciac/bulletins/m-021.shtml
Reference: BID:3561
Reference: URL:http://www.securityfocus.com/bid/3561
Reference: XF:hpux-rlpdaemon-logic-flaw(7234)
Reference: URL:http://xforce.iss.net/static/7234.php

Description:
Vulnerability in HP-UX line printer daemon (rlpdaemon) in HP-UX 10.01 through 11.11 allows remote attackers to modify arbitrary files and gain root privileges via a certain print request.

Votes:

   ACCEPT(6) Foat, Cole, Armstrong, Baker, Frech, Bishop
   NOOP(2) Wall, Christey
Voter Comments:
 Christey> CERT:CA-2001-32
   URL:http://www.cert.org/advisories/CA-2001-32.html
   CERT-VN:VU#638011
   URL:http://www.kb.cert.org/vuls/id/638011
 Christey> BID:3561
   URL:http://www.securityfocus.com/bid/3561
   CIAC:M-021
   http://www.ciac.org/ciac/bulletins/m-021.shtml


CAN-2001-0818

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010612 Remote buffer overflow in MDBMS.
Reference: URL:http://www.securityfocus.com/archive/1/190933
Reference: BID:2867
Reference: URL:http://www.securityfocus.com/bid/2867
Reference: XF:mdbms-query-display-bo(6700)
Reference: URL:http://xforce.iss.net/static/6700.php

Description:
A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary commands by sending the command a large amount of data.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop

CAN-2001-0820

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010617 Buffer Overflow in GazTek HTTP Daemon v1.4 (ghttpd)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99279182704674&w=2
Reference: BUGTRAQ:20010630 Advisory Ghttp 1.4
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99406263214417&w=2
Reference: XF:gaztek-ghttpd-bo(6702)
Reference: URL:http://xforce.iss.net/static/6702.php
Reference: BID:2879
Reference: URL:http://www.securityfocus.com/bid/2879
Reference: BID:2965
Reference: URL:http://www.securityfocus.com/bid/2965

Description:
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop

CAN-2001-0821

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010618 DCShop vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0233.html
Reference: CONFIRM:http://www.dcscripts.com/dcforum/dcshop/44.html
Reference: BID:2889
Reference: URL:http://www.securityfocus.com/bid/2889
Reference: XF:dcshop-cgi-retrieve-information(6707)
Reference: URL:http://xforce.iss.net/static/6707.php

Description:
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote attackers to read sensitive data via an HTTP GET request for (1) orders.txt or (2) auth_user_file.txt.

Votes:

   ACCEPT(5) Cole, Armstrong, Baker, Frech, Bishop
   NOOP(2) Wall, Foat

CAN-2001-0824

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/20010702202828.128B.TAKAGI@etl.go.jp
Reference: BID:2969
Reference: URL:http://www.securityfocus.com/bid/2969

Description:
Cross-site scripting vulnerability in IBM WebSphere 3.02 and 3.5 FP2 allows remote attackers to execute Javascript by inserting the Javascript into (1) a request for a .JSP file, or (2) a request to the webapp/examples/ directory, which inserts the Javascript into an error page.

Votes:

   MODIFY(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Christey, Bishop
Voter Comments:
 Frech> XF:java-servlet-crosssite-scripting(6793)
   This issue is associated with multiple operating
   environments.
 Christey> CERT-VN:VU#560659
   URL:http://www.kb.cert.org/vuls/id/560659
   MISC:http://www.kb.cert.org/vuls/id/JARL-4YZKLU


CAN-2001-0825

Phase: Modified (20020821-02)
Reference: SUSE:SuSE-SA:2001:022
Reference: URL:http://lists.suse.com/archives/suse-security-announce/2001-Jun/0002.html
Reference: CONECTIVA:CLA-2001:406
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000406
Reference: REDHAT:RHSA-2001:092
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-092.html
Reference: IMMUNIX:IMNX-2001-70-029-01
Reference: URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-029-01
Reference: BID:2971
Reference: URL:http://www.securityfocus.com/bid/2971
Reference: XF:xinetd-zero-length-bo(6804)
Reference: URL:http://xforce.iss.net/static/6804.php

Description:
Buffer overflow in internal string handling routines of xinetd before 2.1.8.8 allows remote attackers to execute arbitrary commands via a length argument of zero or less, which disables the length check.

Votes:

   ACCEPT(6) Wall, Foat, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Frech> XF:xinetd-zero-length-bo(6804)
 Christey> Need to sift through the references to make sure they're
   correct and appropriately distinguish from CAN-2001-0763.
 Christey> DELREF IMMUNIX:IMNX-2001-70-024-01 - it does not explicitly
   mention this issue.
   DELREF BUGTRAQ:20010608 potential buffer overflow in xinetd-2.1.8.9pre11-1
   That's for CAN-2001-0763.
   
   Change affected version to 2.1.8, I have no idea where 2.3.1
   came from.


CAN-2001-0826

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010630 cesarFTP v0.98b 'HELP' buffer overflow
Reference: URL:http://www.securityfocus.com/archive/1/20010630093621.66913.qmail@web13002.mail.yahoo.com
Reference: BUGTRAQ:20010704 CesarFTPd, Cerberus FTPd
Reference: URL:http://www.securityfocus.com/archive/1/005701c10466$2332ed80$2c001fac@qualica.com
Reference: BID:2972
Reference: URL:http://www.securityfocus.com/bid/2972

Description:
Buffer overflows in CesarFTPD 0.98b allows remote attackers to execute arbitrary commands via long arguments to (1) HELP, (2) USER, (3) PASS, (4) PORT, (5) DELE, (6) REST, (7) RMD, or (8) MKD.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:cesarftp-long-command-bo(6768)


CAN-2001-0827

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010704 CesarFTPd, Cerberus FTPd
Reference: URL:http://www.securityfocus.com/archive/1/005701c10466$2332ed80$2c001fac@qualica.com
Reference: BID:2976
Reference: URL:http://www.securityfocus.com/bid/2976

Description:
Cerberus FTP server 1.0 - 1.5 allows remote attackers to cause a denial of service (crash) via a large number of "PASV" requests.

Votes:

   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
   REJECT(1) Frech
Voter Comments:
 Frech> See XF:cerberus-ftp-bo(6728). May also be a dupe with
   BID:2901.


CAN-2001-0829

Phase: Proposed (20011122)
Reference: BUGTRAQ:20010702 Multiple Vendor Java Servlet Container Cross-Site Scripting Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/20010702202828.128B.TAKAGI@etl.go.jp
Reference: MISC:http://jakarta.apache.org/tomcat/tomcat-3.2-doc/readme
Reference: BID:2982
Reference: URL:http://www.securityfocus.com/bid/2982

Description:
A cross-site scripting vulnerability in Apache Tomcat 3.2.1 allows a malicious webmaster to embed Javascript in a request for a .JSP file, which causes the Javascript to be inserted into an error message.

Votes:

   MODIFY(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Christey, Bishop
Voter Comments:
 Frech> XF:java-servlet-crosssite-scripting(6793)
 Christey> CERT-VN:VU#672683
   URL:http://www.kb.cert.org/vuls/id/672683


CAN-2001-0831

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011023 FW: ASI Oracle Security Alert: 3 new security alerts
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100386756715645&w=2
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/OLS817alert.pdf

Description:
Vulnerability in Oracle Label Security in Oracle 8.1.7 and 9.0.1, when audit functionality, SET_LABEL, or SQL*Predicate is being used, allows local users to gain additional access.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:oracle-label-security-access(7344)


CAN-2001-0832

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011023 FW: ASI Oracle Security Alert: 3 new security alerts
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100386756715645&w=2
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf

Description:
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(2) Wall, Christey
Voter Comments:
 Frech> XF:oracle-binary-symlink(6940)
 Christey> Possible dupe with CAN-2001-1041; need to review more closely.


CAN-2001-0835

Phase: Modified (20020226-01)
Reference: BUGTRAQ:20011024 Cross-site Scripting Flaw in webalizer
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100394630702875&w=2
Reference: CONFIRM:http://www.mrunix.net/webalizer/news.html
Reference: SUSE:SuSE-SA:2001:040
Reference: URL:http://lists.suse.com/archives/suse-security-announce/2001-Nov/0001.html
Reference: REDHAT:RHSA-2001:140
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-140.html
Reference: REDHAT:RHSA-2001:141
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-141.html
Reference: ENGARDE:ESA-20011101-01
Reference: URL:http://www.linuxsecurity.com/advisories/other_advisory-1677.html
Reference: BID:3473
Reference: URL:http://www.securityfocus.com/bid/3473
Reference: XF:webalizer-html-tag-host(7350)
Reference: URL:http://xforce.iss.net/static/7350.php
Reference: XF:webalizer-html-tags-keywords(7351)
Reference: URL:http://xforce.iss.net/static/7351.php

Description:
Cross-site scripting vulnerability in Webalizer 2.01-06, and possibly other versions, allows remote attackers to inject arbitrary HTML tags by specifying them in (1) search keywords embedded in HTTP referrer information, or (2) host names that are retrieved via a reverse DNS lookup.

Votes:

   ACCEPT(5) Wall, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
Voter Comments:
 Frech> XF:webalizer-html-tag-host(7350)
   XF:webalizer-html-tags-keywords(7351)
 Christey> ADDREF RHSA-2001:140 (per Mark Cox of Red Hat)
 Christey> CONECTIVA:CLA-2001:435
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000435


CAN-2001-0837

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011025 Pc-to-Phone vulnerability - broken by design
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100403691432052&w=2

Description:
DeltaThree Pc-To-Phone 3.0.3 places sensitive data in world-readable locations in the installation directory, which allows local users to read the information in (1) temp.html, (2) the log folder, and (3) the PhoneBook folder.

Votes:

   ACCEPT(1) Armstrong
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Bishop
Voter Comments:
 Frech> XF:pc2phone-temp-account-readable(7393)
 Armstrong> http://www.securiteam.com/windowsntfocus/6V00P202UC.html


CAN-2001-0838

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011025 RWhoisd remote format string vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100402652724815&w=2

Description:
Format string vulnerability in Network Solutions Rwhoisd 1.5.x allows remote attackers execute arbitrary code via format string specifiers in the -soa command.

Votes:

   ACCEPT(2) Armstrong, Baker
   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Christey, Bishop
Voter Comments:
 Frech> XF:rwhoisd-remote-format-string(7353)
   CONFIRM:http://www.securityfocus.com/archive/1/223080
 Christey> The CONFIRM reference by Andre is really this one:
   BUGTRAQ:20011026 RWhoisd patched
   URL:http://www.securityfocus.com/archive/1/223080
 Christey> CONFIRM:http://lists.research.netsol.com/pipermail/rwhois-announce/2001-October/000022.html


CAN-2001-0839

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011025 Weak authentication in iBill's Password Management CGI
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100404371423927&w=2

Description:
ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows remote attackers to modify account information in the .htpasswd file via brute force password guessing.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:ibillpm-cgi-insecure-password(7352)


CAN-2001-0840

Phase: Proposed (20011122)
Reference: COMPAQ:SSRT0766
Reference: URL:http://www.compaq.com/products/servers/management/mgtsw-advisory.html

Description:
Buffer overflow in Compaq Insight Manager XE 2.1b and earlier allows remote attackers to execute arbitrary code via (1) SNMP and (2) DMI.

Votes:

   ACCEPT(4) Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:compaq-insightmanager-xe-bo(7411)


CAN-2001-0841

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011030 Ikonboard Cookie filter vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100446445208739&w=2

Description:
Directory traversal vulnerability in Search.cgi in Ikonboard ib219 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

Votes:

   MODIFY(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Christey, Bishop
Voter Comments:
 Frech> XF:ikonboard-cookie-auth-privileges(7433)
 Christey> BID:3486
   URL:http://www.securityfocus.com/bid/3486


CAN-2001-0842

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011030 LB5000 Cookie filter vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100446455809273&w=2

Description:
Directory traversal vulnerability in Search.cgi in LB5000 LB5000II 1029 and earlier allows remote attackers to overwrite files and gain privileges via .. (dot dot) sequences in the amembernamecookie cookie.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:leoboard-cookie-auth-privileges(7436)


CAN-2001-0844

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011030 cgi vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100446263601021&w=2

Description:
Vulnerability in (1) Book of guests and (2) Post it! allows remote attackers to execute arbitrary code via shell metacharacters in the email parameter.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:bookofguests-cgi-command-execution(7434)
   XF:postit-cgi-command-execution(7435)


CAN-2001-0845

Phase: Modified (20020226-01)
Reference: COMPAQ:SSRT0738
Reference: URL:http://ftp.support.compaq.com/patches/.new/html/SSRT0738.shtml
Reference: XF:openvms-dms-unauthorized-access(7425)
Reference: URL:http://xforce.iss.net/static/7425.php
Reference: BID:3492
Reference: URL:http://online.securityfocus.com/bid/3492

Description:
Vulnerability in DECwindows Motif Server on OpenVMS VAX or Alpha 6.2 through 7.3, and SEVMS VAX or Alpha 6.2, allows local users to gain access to unauthorized resources.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:openvms-dms-unauthorized-access(7425)


CAN-2001-0847

Phase: Modified (20020226-01)
Reference: BUGTRAQ:20011031 Lotus Domino Default Navigator Protection By-pass (#NISR29102001B)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100448726831108&w=2
Reference: XF:lotus-domino-navigator-access(7423)
Reference: URL:http://xforce.iss.net/static/7423.php
Reference: BID:3488
Reference: URL:http://online.securityfocus.com/bid/3488

Description:
Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.

Votes:

   ACCEPT(2) Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Bishop
Voter Comments:
 Frech> XF:lotus-domino-navigator-access(7423)


CAN-2001-0848

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011101 Fuse Talk vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100463832209281&w=2

Description:
join.cfm in e-Zone Media Fuse Talk allows a local user to execute arbitrary SQL code via a semi-colon (;) in a form variable.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Armstrong, Bishop
Voter Comments:
 Frech> XF:fusetalk-joincfm-sql-execution(7445)


CAN-2001-0849

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011101 Vulnerability in Viralator proxy extension
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100463639800515&w=2
Reference: MISC:http://viralator.loddington.com/changes.html

Description:
viralator CGI script in Viralator 0.9pre1 and earlier allows remote attackers to execute arbitrary code via a URL for a file being downloaded, which is insecurely passed to a call to wget.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:viralator-cgi-command-execution(7440)


CAN-2001-0853

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011105 New getAccess[tm] Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100498111712723&w=2
Reference: BUGTRAQ:20011105 Entrust Bulletin E01-005: GetAccess Access Service vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-11/0022.html

Description:
Directory traversal vulnerability in Entrust GetAccess allows remote attackers to read arbitrary files via a .. (dot dot) in the locale parameter to (1) helpwin.gas.bat or (2) AboutBox.gas.bat.

Votes:

   ACCEPT(4) Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:getaccess-shellscripts-retrieve-files(7474)


CAN-2001-0854

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011105 Copying and Deleting Files Using PHP-Nuke
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100525739116093&w=2

Description:
PHP-Nuke 5.2 allows remote attackers to copy and delete arbitrary files by calling case.filemanager.php with admin.php as an argument, which sets the $PHP_SELF variable and makes it appear that case.filemanager.php is being called by admin.php instead of the user.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:phpnuke-filemanager-gain-privileges(7478)


CAN-2001-0855

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011109 ClearCase db_loader TERM environment variable buffer overflow vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100528623328037&w=2

Description:
Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM environment variable.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:clearcase-dbloader-term-bo(7488)


CAN-2001-0856

Phase: Proposed (20011122)
Reference: BUGTRAQ:20011109 Extracting a 3DES key from an IBM 4758
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100533053219673&w=2
Reference: MISC:http://www.cl.cam.ac.uk/~rnc1/descrack/
Reference: MISC:http://www.cl.cam.ac.uk/~rnc1/descrack/attack.html

Description:
Common Cryptographic Architecture (CCA) in IBM 4758 allows an attacker with physical access to the system and Combine_Key_Parts permissions, to steal DES and 3DES keys by using a brute force attack to create a 3DES exporter key.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Bishop
Voter Comments:
 Frech> XF:cca-3des-weak-key(7491)


CAN-2001-0858

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20011113 Security Update: [CSSA-2001-SCO.32] Open UNIX, UnixWare 7: buffer overflow in ppp utilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100562386012917&w=2
Reference: CALDERA:CSSA-2001-SCO.32
Reference: URL:ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.32/
Reference: XF:unixware-openunix-ppp-bo(7570)
Reference: URL:http://www.iss.net/security_center/static/7570.php

Description:
Buffer overflow in pppattach and other linked PPP utilities in Caldera Open Unix 8.0 and UnixWare 7.1.0 and 7.1.1 allows local users to gain privileges.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Baker, Bishop
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:unixware-openunix-ppp-bo(7570)


CAN-2001-0868

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011123 Redhat Stronghold Secure Server File System Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100654958131854&w=2
Reference: XF:stronghold-webserver-obtain-information(7582)
Reference: URL:http://xforce.iss.net/static/7582.php

Description:
Red Hat Stronghold 2.3 to 3.0 allows remote attackers to retrieve system information via an HTTP GET request to (1) stronghold-info or (2) stronghold-status.

Votes:

   NOOP(3) Foat, Cole, Armstrong
   REVIEWING(1) Wall

CAN-2001-0870

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011130 Rapid 7 Advisory R7-0002: Alchemy Eye Remote Unauthenticated Log Viewing
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100715758109838&w=2
Reference: BID:3598
Reference: URL:http://www.securityfocus.com/bid/3598
Reference: XF:alchemy-http-view-log(7630)
Reference: URL:http://xforce.iss.net/static/7630.php

Description:
HTTP server in Alchemy Eye and Alchemy Network Monitor 1.9x through 2.6.18 is enabled without authentication by default, which allows remote attackers to obtain network monitoring logs with potentially sensitive information by directly requesting the eye.ini file.

Votes:

   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0871

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011129 Rapid 7 Advisory R7-0001: Alchemy Eye HTTP Remote Command Execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100714173510535&w=2
Reference: BID:3599
Reference: URL:http://www.securityfocus.com/bid/3599
Reference: XF:alchemy-http-dot-variant(7626)
Reference: URL:http://xforce.iss.net/static/7626.php

Description:
Directory traversal vulnerability in HTTP server for Alchemy Eye and Alchemy Network Monitor allows remote attackers to execute arbitrary commands via an HTTP request containing (1) a .. in versions 2.0 through 2.6.18, or (2) a DOS device name followed by a .. in versions 2.6.19 through 3.0.10.

Votes:

   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0878

Phase: Assigned (20011211)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0880

Phase: Assigned (20011211)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0881

Phase: Assigned (20011211)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0882

Phase: Assigned (20011211)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0883

Phase: Assigned (20011211)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0885

Phase: Assigned (20011214)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2001-0890

Phase: Proposed (20020726)
Reference: REDHAT:RHSA-2001:171
Reference: URL:http://rhn.redhat.com/errata/RHSA-2001-171.html
Reference: BID:3987
Reference: URL:http://online.securityfocus.com/bid/3987
Reference: XF:xsane-temp-symlink(7714)
Reference: URL:http://www.iss.net/security_center/static/7714.php

Description:
Certain backend drivers in the SANE library 1.0.3 and earlier, as used in frontend software such as XSane, allows local users to modify files via a symlink attack on temporary files.

Votes:

   ACCEPT(5) Wall, Cole, Armstrong, Baker, Cox
   NOOP(1) Foat

CAN-2001-0892

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011113 Cgisecurity.com Advisory #6: thttpd and mini_http Permission bypass vuln
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100568999726036&w=2
Reference: CONFIRM:http://www.acme.com/software/thttpd/

Description:
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.

Votes:

   ACCEPT(3) Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:httpd-bypass-permissions(7541)


CAN-2001-0893

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011113 Cgisecurity.com Advisory #6: thttpd and mini_http Permission bypass vuln
Reference: URL:http://marc.theaimsgroup.com/?t=100568954600004&w=2&r=1
Reference: CONFIRM:http://www.acme.com/software/mini_httpd/

Description:
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.

Votes:

   ACCEPT(3) Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:httpd-bypass-permissions(7541)


CAN-2001-0897

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011115 UBB vulnerablietis + about: using example
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100586033530341&w=2
Reference: BUGTRAQ:20011115 Re: UBB vulnerablietis + about: using example
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100586541317940&w=2

Description:
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) before 5.47e allows remote attackers to steal user cookies via an [IMG] tag that references an about: URL with an onerror field.

Votes:

   ACCEPT(2) Cole, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Armstrong
Voter Comments:
 Frech> XF:ultimatebb-cookie-gain-privileges(6142)
   Is this a variant of the following references:
   BugTraq Mailing List, Wed Feb 21 2001 13:19:16	Ultimate Bulletin
   Board, http://online.securityfocus.com/archive/1/164583
   BugTraq Mailing List, Wed Feb 21 2001 17:59:13	Re: Ultimate Bulletin
   Board, http://online.securityfocus.com/archive/1/164716


CAN-2001-0898

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011115 Several javascript vulnerabilities in Opera
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100586079932284&w=2
Reference: BUGTRAQ:20011116 Re: Several javascript vulnerabilities in Opera
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100588139312696&w=2

Description:
Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domains via Javascript.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:opera-java-cross-site(7567)
 Christey> XF:opera-java-cross-site(7567)
   URL:http://www.iss.net/security_center/static/7567.php
   BID:3553
   URL:http://www.securityfocus.com/bid/3553
   
   Some people are calling this XSS, but is it?


CAN-2001-0902

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011120 IIS logging issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100626531103946&w=2
Reference: NTBUGTRAQ:20011120 IIS logging issue
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=100627497122247&w=2

Description:
Microsoft IIS 5.0 allows remote attackers to spoof web log entries via an HTTP request that includes hex-encoded newline or form-feed characters.

Votes:

   ACCEPT(2) Foat, Cole
   MODIFY(1) Frech
   NOOP(1) Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:iis-fake-log-entry(7613)


CAN-2001-0903

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011120 A Cryptanalysis of the High-bandwidth Digital Content Protection System
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100626641009560&w=2
Reference: MISC:http://nunce.org/hdcp/hdcp111901.htm

Description:
Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:hdcp-authentication-keys(7612)


CAN-2001-0904

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011120 MSIE 5.5/6 Q312461 patch disclose patch information
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100619268115798&w=2

Description:
Internet Explorer 5.5 and 6 with the Q312461 (MS01-055) patch modifies the HTTP_USER_AGENT (UserAgent) information that indicates that the patch has been installed, which could allow remote malicious web sites to more easily identify and exploit vulnerable clients.

Votes:

   ACCEPT(3) Foat, Cole, Armstrong
   MODIFY(1) Frech
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:ie-q312461-patch-existence(7581)


CAN-2001-0907

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20011018 Flaws in recent Linux kernels
Reference: URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=221337
Reference: MANDRAKE:MDKSA-2001:082
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082-1.php3
Reference: SUSE:SuSE-SA:2001:036
Reference: URL:http://www.suse.de/de/support/security/2001_036_kernel_txt.html
Reference: IMMUNIX:IMNX-2001-70-035-01
Reference: URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01
Reference: CALDERA:CSSA-2001-036.0
Reference: URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt
Reference: MANDRAKE:MDKSA-2001:079
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-079.php
Reference: ENGARDE:ESA-20011019-02
Reference: URL:http://www.linuxsecurity.com/advisories/other_advisory-1650.html
Reference: BUGTRAQ:20011019 TSLSA-2001-0028
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100350685431610&w=2
Reference: XF:linux-multiple-symlink-dos(7312)
Reference: URL:http://www.iss.net/security_center/static/7312.php
Reference: BID:3444
Reference: URL:http://www.securityfocus.com/bid/3444

Description:
Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a series of deeply nested symlinks, which causes the kernel to spend extra time when trying to access the link.

Votes:

   ACCEPT(4) Foat, Cole, Green, Baker
   MODIFY(1) Frech
   NOOP(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:linux-multiple-symlink-dos(7312)
 Christey> SUSE:SuSE-SA:2001:036
   URL:http://www.suse.de/de/support/security/2001_036_kernel_txt.html
   IMMUNIX:IMNX-2001-70-035-01
   URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01
   CALDERA:CSSA-2001-036.0
   URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt
   MANDRAKE:MDKSA-2001:079
   ENGARDE:ESA-20011019-02
   URL:http://www.linuxsecurity.com/advisories/other_advisory-1650.html
   BUGTRAQ:20011019 TSLSA-2001-0028
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100350685431610&w=2


CAN-2001-0908

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011121 CITRIX & Microsoft Windows Terminal Services False IP Address Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638693315933&w=2
Reference: BID:3566
Reference: URL:http://www.securityfocus.com/bid/3566
Reference: XF:win-terminal-spoof-address(7538)
Reference: URL:http://xforce.iss.net/static/7538.php

Description:
CITRIX Metaframe 1.8 logs the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through Network Address Translation (NAT).

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0909

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011121 Buffer overflow in Windows XP "helpctr.exe"
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638955422011&w=2
Reference: XF:winxp-helpctr-bo(7605)
Reference: URL:http://xforce.iss.net/static/7605.php

Description:
Buffer overflow in helpctr.exe program in Microsoft Help Center for Windows XP allows remote attackers to execute arbitrary code via a long hcp: URL.

Votes:

   ACCEPT(3) Foat, Cole, Frech
   NOOP(1) Armstrong
   REVIEWING(1) Wall

CAN-2001-0910

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011121 Legato Networker vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638782917917&w=2
Reference: XF:networker-reverse-dns-bypass-auth(7601)
Reference: URL:http://xforce.iss.net/static/7601.php
Reference: BID:3564
Reference: URL:http://www.securityfocus.com/bid/3564

Description:
Legato Networker before 6.1 allows remote attackers to bypass access restrictions and gain privileges on the Networker interface by spoofing the admin server name and IP address and connecting to Networker from an IP address whose hostname can not be determined by a DNS reverse lookup.

Votes:

   ACCEPT(2) Armstrong, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-0911

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011121 PhpNuke Admin password can be stolen !
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638850219503&w=2
Reference: BID:3567
Reference: URL:http://www.securityfocus.com/bid/3567
Reference: XF:phpnuke-postnuke-insecure-passwords(7596)
Reference: URL:http://xforce.iss.net/static/7596.php

Description:
PHP-Nuke 5.1 stores user and administrator passwords in a base-64 encoded cookie, which could allow remote attackers to gain privileges by stealing or sniffing the cookie and decoding it.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0913

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011122 [NetGuard Security] NSI Rwhoisd another Remote Format String Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100655265508104&w=2
Reference: CONFIRM:http://lists.research.netsol.com/pipermail/rwhois-announce/2001-November/000023.html

Description:
Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers.

Votes:

   ACCEPT(3) Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:rwhoisd-syslog-format-string(7597)


CAN-2001-0914

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011121 SuSE 7.3 : Kernel 2.4.10-4GB Bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638584813349&w=2
Reference: BUGTRAQ:20011122 Re: SuSE 7.3 : Kernel 2.4.10-4GB Bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100654787226869&w=2L:2

Description:
Linux kernel before 2.4.11pre3 in multiple Linux distributions allows local users to cause a denial of service (crash) by starting the core vmlinux kernel, possibly related to poor error checking during ELF loading.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:linux-vmlinux-dos(7591)


CAN-2001-0915

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011121 Advisory: Berkeley pmake
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638919720975&w=2

Description:
Format string vulnerability in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via format specifiers in the check argument of a shell definition.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:pmake-shell-format-string(7602)
 Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected.
   ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z
   
   This should be sufficient for vendor acknowledgement.


CAN-2001-0916

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011121 Advisory: Berkeley pmake
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100638919720975&w=2

Description:
Buffer overflow in Berkeley parallel make (pmake) 2.1.33 and earlier allows a local user to gain root privileges via a long check argument of a shell definition.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:pmake-shell-bo(7603)
 Baker> A check of the latest version of pmake, version 2.1.36 reveals that the author lists the format string error as having been corrected.
   ftp://ftp.icsi.berkeley.edu/pub/speech/stolcke/software/pmake-2.1.36.tar.Z
   
   This should be sufficient for vendor acknowledgement.


CAN-2001-0919

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011126 Javascript can bypass user preference for cookie prompt in IE5.50.4134.0100
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100679857614967&w=2

Description:
Internet Explorer 5.50.4134.0100 on Windows ME with "Prompt to allow cookies to be stored on your machine" enabled does not warn a user when a cookie is set using Javascript,

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Armstrong, Christey
Voter Comments:
 Frech> (ACCEPT: Task 2352)
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:ie-cookie-prompt-bypass(8621)
 Christey> Add period to the end of the description.


CAN-2001-0922

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011126 NMRC Advisory - NetDynamics Session ID is Reusable
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100681274915525&w=2

Description:
ndcgi.exe in Netdynamics 4.x through 5.x, and possibly earlier versions, allows remote attackers to steal session IDs and hijack user sessions by reading the SPIDERSESSION and uniqueValue variables from the login field, then using those variables after the next user logs in.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:netdynamics-session-hijacking(7620)


CAN-2001-0923

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011025 Advisory: Corrupt RPM Query Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/222542
Reference: CONECTIVA:CLA-2001:440
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000440
Reference: BID:3472
Reference: URL:http://www.securityfocus.com/bid/3472
Reference: XF:Linux-rpm-execute-code(7349)
Reference: URL:http://xforce.iss.net/static/7349.php

Description:
RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0924

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011122 double dot vulnerability on a site running Informix database.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100654890029878&w=2
Reference: BUGTRAQ:20011127 Re: double dot vulnerability on a site running Informix database.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100688672019635&w=2
Reference: BID:3575
Reference: URL:http://www.securityfocus.com/bid/3575
Reference: XF:informix-web-datablade-directory-traversal(7585)
Reference: URL:http://xforce.iss.net/static/7585.php

Description:
Directory traversal vulnerability in ifx CGI program in Informix Web DataBlade allows remote attackers to read arbitrary files via a .. (dot dot) in the LO parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0925

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010312 FORW: [ANNOUNCE] Apache 1.3.19 Released
Reference: URL:http://www.securityfocus.com/archive/1/168497
Reference: BUGTRAQ:20010624 Fw: Bugtraq ID 2503 : Apache Artificially Long Slash Path Directory Listing Exploit
Reference: URL:http://www.securityfocus.com/archive/1/193081
Reference: BUGTRAQ:20010419 OpenBSD 2.8patched Apache vuln!
Reference: URL:http://www.securityfocus.com/archive/1/178066
Reference: BUGTRAQ:20010726 Apache Artificially Long Slash Path Directory Listing Vulnerabili ty -- FILE READ ACCESS
Reference: URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&start=2002-01-27&end=2002-02-02&mid=199857&threads=1
Reference: CONFIRM:http://www.apacheweek.com/features/security-13
Reference: MANDRAKE:MDKSA-2001:077
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-077.php3
Reference: DEBIAN:DSA-067
Reference: URL:http://www.debian.org/security/2001/dsa-067
Reference: ENGARDE:ESA-20010620-02
Reference: URL:http://www.linuxsecurity.com/advisories/other_advisory-1452.html
Reference: BID:2503
Reference: URL:http://www.securityfocus.com/bid/2503
Reference: XF:apache-slash-directory-listing(6921)
Reference: URL:http://xforce.iss.net/static/6921.php

Description:
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview index.html file via an HTTP request for a path that contains many / (slash) characters, which causes the path to be mishandled by (1) mod_negotiation, (2) mod_dir, or (3) mod_autoindex.

Votes:

   ACCEPT(5) Foat, Cole, Armstrong, Green, Baker
   NOOP(2) Wall, Christey
   REJECT(1) Frech
Voter Comments:
 Frech> I'm using both candidates until we decide if it is a dupe,
   and then which 
   candidate to deprecate.
 Christey> BUGTRAQ:20010615 TSLSA-2001-0010 - Apache
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0180.html
 Christey> CAN-2001-0925 and CAN-2001-0729 are different issues.
   CAN-2001-0925 only applies to versions before 1.3.19, whereas
   CAN-2001-0729 applies to 1.3.20, and only Windows.
   
   The Change Log at http://www.apache.org/dist/httpd/CHANGES_1.3
   specifically mentions these CANs separately.


CAN-2001-0926

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011128 JRun SSI Request Body Parsing
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100697797325013&w=2
Reference: CONFIRM:http://www.macromedia.com/v1/handlers/index.cfm?ID=22261&Method=Full
Reference: BID:3589
Reference: URL:http://www.securityfocus.com/bid/3589
Reference: XF:allaire-jrun-view-source(7622)
Reference: URL:http://xforce.iss.net/static/7622.php

Description:
SSIFilter in Allaire JRun 3.1, 3.0 and 2.3.3 allows remote attackers to obtain source code for Java server pages (.jsp) and other files in the web root via an HTTP request for a non-existent SSI page, in which the request's body has an #include statement.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-0927

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011127 [CERT-intexxia] libgtop_daemon Remote Format String Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100689302316077&w=2
Reference: MISC:ftp://ftp.gnome.org/pub/GNOME/stable/sources/libgtop/libgtop-1.0.13.tar.gz

Description:
Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.

Votes:

   ACCEPT(3) Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Frech> XF:libgtop-format-string(7608)
 Christey> BID:3586
   URL:http://www.securityfocus.com/bid/3586
   CONECTIVA:CLA-2002:448
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000448
   MANDRAKE:MDKSA-2001:094
   URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-094.php3
   DEBIAN:DSA-098
   URL:http://www.debian.org/security/2002/dsa-098


CAN-2001-0928

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011128 Re: [CERT-intexxia] libgtop_daemon Remote Format String Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100699007010203&w=2

Description:
Buffer overflow in the permitted function of GNOME libgtop_daemon in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data.

Votes:

   ACCEPT(2) Foat, Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Armstrong, Christey
Voter Comments:
 Frech> XF:XF:libgtop-permitted-bo(7635)
   CONFIRM:MandrakeSoft Security Advisory MDKSA-2001:094,
   "libgtop",
   http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-094.php3
   CONFIRM:Debian Security Advisory DSA-098-1, "libgtop: format string
   vulnerability and buffer overflow",
   http://www.debian.org/security/2002/dsa-098
 Christey> BID:3594
   URL:http://www.securityfocus.com/bid/3594
   CONECTIVA:CLA-2002:448
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000448
   MANDRAKE:MDKSA-2001:094
   URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-094.php3
   DEBIAN:DSA-098
   URL:http://www.debian.org/security/2002/dsa-098
 Christey> DEBIAN:DSA-301
   URL:http://www.debian.org/security/2003/dsa-301


CAN-2001-0930

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011128 Sendpage (Perl CGI) Remote Execution Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100689313216624&w=2

Description:
Sendpage.pl allows remote attackers to execute arbitrary commands via a message containing shell metacharacters.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:sendpage-message-command-execution(7609)


CAN-2001-0931

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011128 PowerFTP-server-Bugs&Exploits-Remotes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100698397818175&w=2
Reference: XF:powerftp-dot-directory-traversal(7615)
Reference: URL:http://xforce.iss.net/static/7615.php
Reference: BID:3593
Reference: URL:http://www.securityfocus.com/bid/3593

Description:
Directory traversal vulnerability in Cooolsoft PowerFTP Server 2.03 allows attackers to list or read arbitrary files and directories via a .. (dot dot) in (1) LS or (2) GET.

Votes:

   ACCEPT(3) Foat, Baker, Frech
   NOOP(3) Wall, Cole, Armstrong

CAN-2001-0932

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011128 PowerFTP-server-Bugs&Exploits-Remotes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100698397818175&w=2
Reference: XF:powerftp-long-command-dos(7616)
Reference: URL:http://xforce.iss.net/static/7616.php
Reference: BID:3595
Reference: URL:http://www.securityfocus.com/bid/3595

Description:
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long command.

Votes:

   ACCEPT(2) Foat, Frech
   NOOP(3) Wall, Cole, Armstrong

CAN-2001-0933

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011128 PowerFTP-server-Bugs&Exploits-Remotes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100698397818175&w=2

Description:
Cooolsoft PowerFTP Server 2.03 allows remote attackers to list the contents of arbitrary drives via a ls (LIST) command that includes the drive letter as an argument, e.g. "ls C:".

Votes:

   ACCEPT(1) Foat
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:powerftp-dot-directory-traversal(7615)


CAN-2001-0934

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011128 PowerFTP-server-Bugs&Exploits-Remotes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100698397818175&w=2

Description:
Cooolsoft PowerFTP Server 2.03 allows remote attackers to obtain the physical path of the server root via the pwd command, which lists the full pathname.

Votes:

   ACCEPT(1) Foat
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Armstrong, Christey
Voter Comments:
 Frech> (ACCEPT; Task 2353)
 Christey> Rediscovered in:
   BUGTRAQ:20020211 PowerFTP Personal FTP Server Multiple Vulnerabilities
   http://marc.theaimsgroup.com/?l=bugtraq&m=101361745222207&w=2
   This rediscovery says the problem is in 2.10.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:powerftp-pwd-path-disclosure(8182)
 Christey> BID:4072
   URL:http://online.securityfocus.com/bid/4072


CAN-2001-0935

Phase: Proposed (20020131)
Reference: SUSE:SuSE-SA:2001:043
Reference: URL:http://www.suse.de/de/support/security/2001_043_wuftpd_txt.html

Description:
Vulnerability in wu-ftpd 2.6.0, and possibly earlier versions, which is unrelated to the ftpglob bug described in CAN-2001-0550.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:wuftp-glob-heap-corruption(7611)


CAN-2001-0937

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011130 Vulnerabilities in PGPMail.pl
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100714269114686&w=2
Reference: VULN-DEV:20011129 PGPMail.pl possible remote command execution
Reference: URL:http://www.securityfocus.com/archive/82/243262

Description:
PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Armstrong
Voter Comments:
 Frech> XF:pgpmail-config-execute-commands(7627)


CAN-2001-0938

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011130 Aspupload installs exploitable scripts
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100715294425985&w=2

Description:
Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp.

Votes:

   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:aspupload-upload-directory-traversal(7628)
   XF:aspupload-directory-browsing-download(7629)


CAN-2001-0941

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011130 ASI Oracle Security Alert: Oracle Home Environment Variable Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100716693806967&w=2
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf

Description:
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_HOME environment variable.

Votes:

   ACCEPT(4) Foat, Cole, Armstrong, Baker
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:oracle-dbsnmp-home-bo(7643)


CAN-2001-0942

Phase: Proposed (20020131)
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf

Description:
dbsnmp in Oracle 8.1.6 and 8.1.7 uses the ORACLE_HOME environment variable to find and execute the dbsnmp program, which allows local users to execute arbitrary programs by pointing the ORACLE_HOME to an alternate directory that contains a Trojan Horse version of dbsnmp.

Votes:

   ACCEPT(2) Foat, Armstrong
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:oracle-dbsnmp-home-validation(7645)


CAN-2001-0943

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010801 Oracle 8.1.5 dbnsmp vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/201020
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/dbsmp_alert.pdf
Reference: BID:3129
Reference: URL:http://www.securityfocus.com/bid/3129

Description:
dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.

Votes:

   ACCEPT(6) Wall, Foat, Cole, Armstrong, Green, Baker
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:oracle-dbsnmp-path-gain-privileges(7644)


CAN-2001-0944

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011202 mIRC bug?
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100734173831990&w=2

Description:
DDE in mIRC allows local users to launch applications under another user's account via a DDE message that executes a command, which may be executed by the other user's process.

Votes:

   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Green
Voter Comments:
 Frech> XF:mirc-dde-gain-privileges(8292)


CAN-2001-0945

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011203 Buffer over flow on Outlook express for Macintosh
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100741295502017&w=2

Description:
Buffer overflow in Outlook Express 5.0 through 5.02 for Macintosh allows remote attackers to cause a denial of service via an e-mail message that contains a long line.

Votes:

   ACCEPT(1) Green
   MODIFY(2) Foat, Frech
   NOOP(2) Wall, Cole
Voter Comments:
 CHANGE> [Foat changed vote from REVIEWING to MODIFY]
 Foat> Change the phrase "that contains a long line" to "that
   contains a particular string".  The buffer overflow does
   not appear to be length dependeng, but string dependent.
 Frech> XF:macos-outlook-long-message-bo(7648)


CAN-2001-0947

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011204 NMRC Advisory - Multiple Valicert Problems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100749428517090&w=2
Reference: CONFIRM:http://www.valicert.com/support/security_advisory_eva.html
Reference: XF:eva-forms-reveal-path(7649)
Reference: URL:http://xforce.iss.net/static/7649.php
Reference: BID:3615
Reference: URL:http://www.securityfocus.com/bid/3615

Description:
Forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to determine the real pathname of the server by requesting an invalid extension, which produces an error page that includes the path.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-0948

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011204 NMRC Advisory - Multiple Valicert Problems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100749428517090&w=2
Reference: CONFIRM:http://www.valicert.com/support/security_advisory_eva.html
Reference: XF:eva-admin-script-injection(7650)
Reference: URL:http://xforce.iss.net/static/7650.php
Reference: BID:3619
Reference: URL:http://www.securityfocus.com/bid/3619

Description:
Cross-site scripting (CSS) vulnerability in ValiCert Enterprise Validation Authority (EVA) 3.3 through 4.2.1 allows remote attackers to execute arbitrary code or display false information by including HTML or script in the certificate's description, which is executed when the certificate is viewed.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-0949

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011204 NMRC Advisory - Multiple Valicert Problems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100749428517090&w=2
Reference: CONFIRM:http://www.valicert.com/support/security_advisory_eva.html
Reference: XF:eva-forms-bo(7652)
Reference: URL:http://xforce.iss.net/static/7652.php
Reference: BID:3621
Reference: URL:http://www.securityfocus.com/bid/3621
Reference: BID:3622
Reference: URL:http://www.securityfocus.com/bid/3622
Reference: BID:3624
Reference: URL:http://www.securityfocus.com/bid/3624
Reference: BID:3625
Reference: URL:http://www.securityfocus.com/bid/3625
Reference: BID:3627
Reference: URL:http://www.securityfocus.com/bid/3627
Reference: BID:3628
Reference: URL:http://www.securityfocus.com/bid/3628
Reference: BID:3629
Reference: URL:http://www.securityfocus.com/bid/3629
Reference: BID:3630
Reference: URL:http://www.securityfocus.com/bid/3630
Reference: BID:3631
Reference: URL:http://www.securityfocus.com/bid/3631
Reference: BID:3632
Reference: URL:http://www.securityfocus.com/bid/3632
Reference: BID:3633
Reference: URL:http://www.securityfocus.com/bid/3633
Reference: BID:3634
Reference: URL:http://www.securityfocus.com/bid/3634
Reference: BID:3635
Reference: URL:http://www.securityfocus.com/bid/3635
Reference: BID:3636
Reference: URL:http://www.securityfocus.com/bid/3636

Description:
Buffer overflows in forms.exe CGI program in ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 allows remote attackers to execute arbitrary code via long arguments to the parameters (1) Mode, (2) Certificate_File, (3) useExpiredCRLs, (4) listenLength, (5) maxThread, (6) maxConnPerSite, (7) maxMsgLen, (8) exitTime, (9) blockTime, (10) nextUpdatePeriod, (11) buildLocal, (12) maxOCSPValidityPeriod, (13) extension, and (14) a particular combination of parameters associated with private key generation that form a string of a certain length.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-0950

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011204 NMRC Advisory - Multiple Valicert Problems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100749428517090&w=2
Reference: CONFIRM:http://www.valicert.com/support/security_advisory_eva.html
Reference: XF:eva-insecure-key-generation(7653)
Reference: URL:http://xforce.iss.net/static/7653.php
Reference: XF:eva-insecure-key-storage(7651)
Reference: URL:http://xforce.iss.net/static/7651.php
Reference: BID:3618
Reference: URL:http://www.securityfocus.com/bid/3618
Reference: BID:3620
Reference: URL:http://www.securityfocus.com/bid/3620

Description:
ValiCert Enterprise Validation Authority (EVA) Administration Server 3.3 through 4.2.1 uses insufficiently random data to (1) generate session tokens for HSMs using the C rand function, or (2) generate certificates or keys using /dev/urandom instead of another source which blocks when the entropy pool is low, which could make it easier for local or remote attackers to steal tokens or certificates via brute force guessing.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-0951

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011207 UDP DoS attack in Win2k via IKE
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100774842520403&w=2
Reference: BUGTRAQ:20011211 UDP DoS attack in Win2k via IKE
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100813081913496&w=2
Reference: XF:win2k-ike-dos(7667)
Reference: URL:http://xforce.iss.net/static/7667.php
Reference: BID:3652
Reference: URL:http://www.securityfocus.com/bid/3652

Description:
Windows 2000 allows remote attackers to cause a denial of service (high CPU usage) by flooding Internet Key Exchange (IKE) UDP port 500 with packets that contain a large number of dots.

Votes:

   ACCEPT(3) Foat, Green, Frech
   NOOP(1) Cole
   REVIEWING(1) Wall

CAN-2001-0952

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011207 Red Faction Server/Client DOS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100774266027774&w=2
Reference: XF:red-faction-udp-dos(7672)
Reference: URL:http://xforce.iss.net/static/7672.php
Reference: BID:3651
Reference: URL:http://www.securityfocus.com/bid/3651

Description:
THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via packets to UDP port 7755.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-0953

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011208 kebi-Webmail Solution vulnerability (Tested)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100780264902037&w=2:1
Reference: XF:kebi-webmail-admin-dir-access(7674)
Reference: URL:http://xforce.iss.net/static/7674.php
Reference: BID:3655
Reference: URL:http://www.securityfocus.com/bid/3655

Description:
Kebi WebMail allows remote attackers to access the administrator menu and gain privileges via the /a/ hidden directory, which is installed under the web document root.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2001-0955

Phase: Proposed (20020131)
Reference: VULN-DEV:20010922 XFree86 DOS / Buffer overflow local and remote.
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=100118958310463&w=2
Reference: BUGTRAQ:20011207 Crashing X
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100776624224549&w=2
Reference: BUGTRAQ:20011208 Re: Crashing X
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100784290015880&w=2
Reference: CONFIRM:http://www.xfree86.org/4.2.0/RELNOTES2.html#2
Reference: CONFIRM:http://www.xfree86.org/security/
Reference: MISC:http://cvsweb.xfree86.org/cvsweb/xc/programs/Xserver/fb/fbglyph.c
Reference: BID:3663
Reference: URL:http://www.securityfocus.com/bid/3663
Reference: BID:3657
Reference: URL:http://www.securityfocus.com/bid/3657
Reference: XF:xfree86-konqueror-bo(7673)
Reference: URL:http://xforce.iss.net/static/7673.php
Reference: XF:xfree86-xterm-title-bo(7683)
Reference: URL:http://xforce.iss.net/static/7683.php

Description:
Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-0956

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010911 security alert: speechd from speechio.org
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0089.html
Reference: CONFIRM:http://www.speechio.org/speechd.html
Reference: XF:speechd-execute-commands(7121)
Reference: URL:http://xforce.iss.net/static/7121.php
Reference: BID:3326
Reference: URL:http://www.securityfocus.com/bid/3326

Description:
speechd 0.54 and earlier, with the Festival or rsynth speech synthesis package, allows attackers to execute arbitrary commands via shell metacharacters.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-0958

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010912 [SNS Advisory No.42] Trend Micro InterScan eManager for NT Multiple Program Buffer Overflow Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0099.html
Reference: MISC:http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=3142
Reference: XF:interscan-emanager-bo(7104)
Reference: URL:http://xforce.iss.net/static/7104.php
Reference: BID:3327
Reference: URL:http://www.securityfocus.com/bid/3327

Description:
Buffer overflows in eManager plugin for Trend Micro InterScan VirusWall for NT 3.51 and 3.51J allow remote attackers to execute arbitrary code via long arguments to the CGI programs (1) register.dll, (2) ContentFilter.dll, (3) SFNofitication.dll, (4) register.dll, (5) TOP10.dll, (6) SpamExcp.dll, and (7) spamrule.dll.

Votes:

   ACCEPT(2) Cole, Frech
   MODIFY(1) Green
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Green> VENDOR ACKNOWLEDGEMENT MISSING
 Christey> register.dll is listed twice.


CAN-2001-0964

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010920 Advisory: Half-Life remote buffer overflow vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0178.html
Reference: XF:halflife-connect-bo(7148)
Reference: URL:http://xforce.iss.net/static/7148.php

Description:
Buffer overflow in client for Half-Life 1.1.0.8 and earlier allows malicious remote servers to execute arbitrary code via a long console command.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-0966

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010818 [Real Security] Advisory for Nudester 1.10
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0232.html
Reference: BID:3202
Reference: URL:http://www.securityfocus.com/bid/3202

Description:
Directory traversal vulnerability in Nudester 1.10 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the CD (CWD) command.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:nudester-sniffer-full-access(7032)


CAN-2001-0967

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010817 Arkeia Possible remote root & information leakage
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0228.html
Reference: BID:3204
Reference: URL:http://www.securityfocus.com/bid/3204

Description:
Knox Arkeia server 4.2, and possibly other versions, uses a constant salt when encrypting passwords using the crypt() function, which makes it easier for an attacker to conduct brute force password guessing.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:arkeia-weak-password-encryption(7000)


CAN-2001-0968

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010817 Arkeia Possible remote root & information leakage
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0228.html
Reference: BID:3203
Reference: URL:http://www.securityfocus.com/bid/3203

Description:
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:arkeia-blank-default-password(6999)


CAN-2001-0970

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010820 tdforum 1.2 Messageboard
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99832137410609&w=2
Reference: BID:3207
Reference: URL:http://www.securityfocus.com/bid/3207

Description:
Cross-site scripting vulnerability in TDForum 1.2 CGI script (tdforum12.cgi) allows remote attackers to execute arbitrary script on other clients via a forum message that contains the script.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Green> HAS-INDEPENDENT-CONFIRMATION
 Frech> XF:tdforum-cross-site-scripting(7009)


CAN-2001-0971

Phase: Modified (20020313-01)
Reference: BUGTRAQ:20010820 ACI 4D WebServer Directory traversal.
Reference: URL:http://www.securityfocus.com/archive/1/206102
Reference: BID:3209
Reference: URL:http://www.securityfocus.com/bid/3209
Reference: XF:4d-webserver-directory-traversal(7010)
Reference: URL:http://www.iss.net/security_center/static/7010.php

Description:
Directory traversal vulnerability in ACI 4d webserver allows remote attackers to read arbitrary files via a .. (dot dot) or drive letter (e.g., C:) in an HTTP request.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
   REJECT(1) Christey
Voter Comments:
 Christey> According to an email message from the vendor
   (bcoveney@4d.com) on March 13, 2002, this problem is only
   possible if the server admin has already configured the
   server's web root to be at the top-level folder.  This is not
   the default.  As such, any "directory traversal" attack would
   not escape above the folder that has already been specified by
   the admin.  Since this is a generic misconfiguration problem
   for all web servers, and not a default configuration of ACI
   4D, then this candidate should not be included in CVE.
   
   The quote from the vendor is: "By default the 4D WebServer
   doesn't have this behavior. A property has to be turned on to allow
   this (despite our warnings of the consequences). We don't allow pages
   outside of our web folder to be served but if the developer of the
   site wishes they can set the webroot folder to be whatever they
   want. In the system that 'krfinisterre@checkfree.com' evaluated the
   developer had chosen to set their root folder to be the root of the
   computer system (C:\) and therefore all the files on the system were
   available. By default we set the root folder at the same level as the
   database folder so this doesn't happen. You cannot look at any files
   outside the designated WebFolder root tree."
 Frech> XF:4d-webserver-directory-traversal(7010)


CAN-2001-0972

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010820 security problem in surf-net ASP Discussion Forum < 2.30
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99834088223352&w=2
Reference: BID:3210
Reference: URL:http://www.securityfocus.com/bid/3210

Description:
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:surfnet-asp-cookie-seq-predictable(7011)


CAN-2001-0974

Phase: Modified (20020416-01)
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CIAC:L-116
Reference: URL:http://www.ciac.org/ciac/bulletins/l-116.shtml
Reference: CERT-VN:VU#869184
Reference: URL:http://www.kb.cert.org/vuls/id/869184
Reference: BID:3048
Reference: URL:http://www.securityfocus.com/bid/3048
Reference: XF:oracle-ldap-protos-format-string(6903)
Reference: URL:http://xforce.iss.net/static/6903.php

Description:
Format string vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Frech
   NOOP(1) Foat

CAN-2001-0975

Phase: Modified (20020416-01)
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CIAC:L-116
Reference: URL:http://www.ciac.org/ciac/bulletins/l-116.shtml
Reference: CERT-VN:VU#869184
Reference: URL:http://www.kb.cert.org/vuls/id/869184
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/oid_cert_bof.pdf
Reference: XF:oracle-ldap-protos-bo(6902)
Reference: URL:http://xforce.iss.net/static/6902.php
Reference: BID:3047
Reference: URL:http://www.securityfocus.com/bid/3047

Description:
Buffer overflow vulnerabilities in Oracle Internet Directory Server (LDAP) 2.1.1.x and 3.0.1 allow remote attackers to execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Frech
   NOOP(1) Foat

CAN-2001-0976

Phase: Proposed (20020131)
Reference: HP:HPSBUX0108-165
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q3/0048.html

Description:
Vulnerability in HP Process Resource Manager (PRM) C.01.08.2 and earlier, as used by HP-UX Workload Manager (WLM), allows local users to gain root privileges via modified libraries or environment variables.

Votes:

   ACCEPT(4) Cole, Armstrong, Green, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Frech> XF:hp-prm-privilege-elevation(7050)
   ACKNOWLEDGED-BY-VENDOR
 Christey> NOTE: CAN-2001-1167 was discovered to be a duplicate of this
   issue.  Use this candidate (CAN-2001-0976) instead of the
   other one.


CAN-2001-0979

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010903 hpux warez
Reference: URL:http://www.securityfocus.com/archive/1/211687
Reference: BID:3279
Reference: URL:http://www.securityfocus.com/bid/3279
Reference: XF:hpux-swverify-bo(7078)
Reference: URL:http://xforce.iss.net/static/7078.php

Description:
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long command line argument.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> CONFIRM:http://archives.neohapsis.com/archives/hp/2001-q1/006
   9.html


CAN-2001-0983

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010823 Re: Respondus v1.1.2 stores passwords using weak encryption
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99861651923668&w=2
Reference: MISC:http://www.eve-software.com/security/ueditpw.html

Description:
UltraEdit uses weak encryption to record FTP passwords in the uedit32.ini file, which allows local users who can read the file to decrypt the passwords and gain privileges.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:ultraedit-weak-encryption(8696)


CAN-2001-0984

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010913 leak of information in counterpane/Bruce Schneier's Password Safe program
Reference: URL:http://www.securityfocus.com/archive/1/213931
Reference: XF:counterpane-password-access(7123)
Reference: URL:http://xforce.iss.net/static/7123.php
Reference: BID:3337
Reference: URL:http://www.securityfocus.com/bid/3337

Description:
Password Safe 1.7(1) leaves cleartext passwords in memory when a user copies the password to the clipboard and minimizes Password Safe with the "Clear the password when minimized" and "Lock password database on minimize and promp on restore" options enabled, which could allow an attacker with access to the memory (e.g. an administrator) to read the passwords.

Votes:

   ACCEPT(2) Foat, Frech
   MODIFY(1) Green
   NOOP(2) Wall, Cole
Voter Comments:
 Green> THE ISSUE OF WHETHER THIS IS PROGRAMMATIC OR OS RELATED SEEMS
   UNSETTLED, AS DOES THE LEVEL OF PRIVILEGE THAT CAN BE OBTAINED


CAN-2001-0985

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010908 Shopping Cart Version 1.23
Reference: URL:http://www.securityfocus.com/archive/1/212827
Reference: MISC:http://www.irata.com/shopver.html
Reference: BID:3308
Reference: URL:http://www.securityfocus.com/bid/3308
Reference: XF:hassan-cart-command-execution(7106)
Reference: URL:http://xforce.iss.net/static/7106.php

Description:
shop.pl in Hassan Consulting Shopping Cart 1.23 allows remote attackers to execute arbitrary commands via shell metacharacters in the "page" parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Green> THIS VULNERABILITY IS SUFFICIENTLY DISTINCT FROM A DIRECTORY
   TRANSVERSAL TO WARRANT INCLUSION


CAN-2001-0986

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010914 Security Vulnerability with Microsoft Index Server 2.0(Sample file reveals file info, physical path etc)
Reference: URL:http://www.securityfocus.com/archive/1/214217
Reference: XF:winnt-indexserver-sqlqhit-asp(7125)
Reference: URL:http://xforce.iss.net/static/7125.php
Reference: BID:3339
Reference: URL:http://www.securityfocus.com/bid/3339

Description:
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as the physical path, file attributes, or portions of source code by directly calling sqlqhit.asp with a CiScope parameter set to (1) webinfo, (2) extended_fileinfo, (3) extended_webinfo, or (4) fileinfo.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(2) Foat, Cole
   REVIEWING(1) Wall
Voter Comments:
 Frech> http://www.kb.cert.org/vuls/id/914859


CAN-2001-0988

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010723 permission probs with Arkeia
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0521.html
Reference: BID:3085
Reference: URL:http://www.securityfocus.com/bid/3085
Reference: XF:arkeia-insecure-file-permissions(6885)
Reference: URL:http://xforce.iss.net/static/6885.php

Description:
Arkeia backup server 4.2.8-2 and earlier creates its database files with world-writable permissions, which could allow local users to overwrite the files or obtain sensitive information.

Votes:

   ACCEPT(2) Cole, Frech
   MODIFY(1) Green
   NOOP(3) Wall, Foat, Armstrong
Voter Comments:
 Green> SEEMS TO BE CONTRADICTING INFORMATION IN THE MESSAGES AT BUGTRAQ


CAN-2001-0989

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010723 pileup 1.2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0512.html
Reference: CONFIRM:http://www.babbage.demon.co.uk/linux/pileup-1.2/pileup-1.2.tar.gz
Reference: BID:3086
Reference: URL:http://www.securityfocus.com/bid/3086

Description:
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or (2) a long callsign.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:pileup-scanf-bo(8924)


CAN-2001-0990

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010904 BUZ.CH Security Advisory 200109041: Inter7 vpopmail DB pw problem
Reference: URL:http://www.securityfocus.com/archive/1/212036
Reference: MISC:http://www.inter7.com/vpopmail/ChangeLog
Reference: BID:3284
Reference: URL:http://www.securityfocus.com/bid/3284
Reference: XF:vpopmail-insecure-auth-data(7076)
Reference: URL:http://xforce.iss.net/static/7076.php

Description:
Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a library, which allows local users to obtain the MySQL username and password by inspecting the vpopmail programs that use the library.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-0991

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010724 Proxomitron Cross-site Scripting Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/198954
Reference: XF:proxomitron-cross-site-scripting(6887)
Reference: URL:http://xforce.iss.net/static/6887.php
Reference: BID:3087
Reference: URL:http://www.securityfocus.com/bid/3087

Description:
Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitrary script on other clients via an incorrect URL containing the malicious script, which is printed back in an error message.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Green changed vote from REVIEWING to ACCEPT]


CAN-2001-0992

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010905 ShopPlus Cart
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0012.html
Reference: XF:shopplus-command-execution(7077)
Reference: URL:http://xforce.iss.net/static/7077.php

Description:
shopplus.cgi in ShopPlus shopping cart allows remote attackers to execute arbitrary commands via shell metacharacters in the "file" parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-0994

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010904 Telnet DoS Vulnerability in Marconi ATM Switch Software
Reference: URL:http://www.securityfocus.com/archive/1/211956
Reference: XF:forethought-telnet-dos(7082)
Reference: URL:http://xforce.iss.net/static/7082.php
Reference: BID:3286
Reference: URL:http://www.securityfocus.com/bid/3286

Description:
Marconi ForeThought 7.1 allows remote attackers to cause a denial of service by causing both telnet sessions to be locked via unusual input (e.g., from a port scanner), which prevents others from logging into the device.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2001-0996

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010902 POP3Lite 0.2.3b minor client side DoS and message injection
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0436.html
Reference: XF:pop3lite-dot-message-injection(7075)
Reference: URL:http://xforce.iss.net/static/7075.php
Reference: BID:3278
Reference: URL:http://www.securityfocus.com/bid/3278

Description:
POP3Lite before 0.2.4 does not properly quote a . (dot) in an email message, which could allow a remote attacker to append arbitrary text to the end of an email message, which could then be interpreted by various mail clients as valid POP server responses or other input that could cause clients to crash or otherwise behave unexpectedly.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-0997

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010911 Textor Webmasters Ltd (listrec.pl)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0096.html
Reference: XF:listrecpl-remote-command-execution(7117)
Reference: URL:http://xforce.iss.net/static/7117.php

Description:
Textor Webmasters Ltd listrec.pl CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in the TEMPLATE parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2001-0999

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010912 FREAK SHOW: Outlook Express 6.00
Reference: URL:http://www.securityfocus.com/archive/1/213754
Reference: BUGTRAQ:20010915 Proof-Of-Concept Perl Script for Bugtraq-ID: #3334
Reference: URL:http://www.securityfocus.com/archive/1/214453
Reference: XF:outlook-express-text-script-execution(7118)
Reference: URL:http://xforce.iss.net/static/7118.php
Reference: BID:3334
Reference: URL:http://www.securityfocus.com/bid/3334

Description:
Outlook Express 6.00 allows remote attackers to execute arbitrary script by embedding SCRIPT tags in a message whose MIME content type is text/plain, contrary to the expected behavior that text/plain messages will not run script.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(2) Foat, Cole
   REVIEWING(1) Wall

CAN-2001-1000

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010907 rlmadmin v3.8M view file symlink vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0036.html
Reference: XF:radius-rlmadmin-help-symlink(7096)
Reference: URL:http://xforce.iss.net/static/7096.php
Reference: BID:3302
Reference: URL:http://www.securityfocus.com/bid/3302

Description:
rlmadmin RADIUS management utility in Merit AAA Server 3.8M, 5.01, and possibly other versions, allows local users to read arbitrary files via a symlink attack on the rlmadmin.help file.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Green
Voter Comments:
 Frech> If the software is available to the general public, then it
   should
   be included in CVE. Marking the software 'MichNet Only' does not
   prevent
   someone from running it outside of MichNet, but it allegedly may
   protect
   MichNet against actual or perceived liabilities.


CAN-2001-1003

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010823 Respondus v1.1.2 stores passwords using weak encryption
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99859557930285&w=2

Description:
Respondus 1.1.2 for WebCT uses weak encryption to remember usernames and passwords, which allows local users who can read the WEBCT.SVR file to decrypt the passwords and gain additional privileges.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:webct-respondus-weak-encryption(7033)


CAN-2001-1004

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010830 gnut gnutella client html injection
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0415.html
Reference: MISC:http://www.gnutelliums.com/linux_unix/gnut/ChangeLog.txt

Description:
Cross-site scripting (CSS) vulnerability in gnut Gnutella client before 0.4.27 allows remote attackers to execute arbitrary script on other clients by sharing a file whose name contains the script tags.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:gnut-embedded-code-execution(7071)


CAN-2001-1005

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/210067
Reference: BID:3231
Reference: URL:http://www.securityfocus.com/bid/3231

Description:
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:truesync-desktop-insecure-passwords(7031)


CAN-2001-1006

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/210067
Reference: BID:3232
Reference: URL:http://www.securityfocus.com/bid/3232

Description:
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:truesync-desktop-insecure-passwords(7031)


CAN-2001-1007

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010824 Starfish Truesync Desktop + REX 5000 Pro multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/210067

Description:
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:truesync-desktop-devicekeys-bruteforce(8712)


CAN-2001-1009

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20010809 Fetchmail security advisory
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0118.html
Reference: ENGARDE:ESA-20010816-01
Reference: URL:http://www.linuxsecurity.com/advisories/other_advisory-1555.html
Reference: REDHAT:RHSA-2001:103
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-103.html
Reference: MANDRAKE:MDKSA-2001:072
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-072.php3
Reference: DEBIAN:DSA-071
Reference: URL:http://www.debian.org/security/2001/dsa-071
Reference: CONECTIVA:CLA-2001:419
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000419
Reference: SUSE:SuSE-SA:2001:026
Reference: URL:http://www.suse.de/de/security/2001_026_fetchmail_txt.html
Reference: BID:3164
Reference: URL:http://www.securityfocus.com/bid/3164
Reference: BID:3166
Reference: URL:http://www.securityfocus.com/bid/3166
Reference: XF:fetchmail-signed-integer-index(6965)
Reference: URL:http://www.iss.net/security_center/static/6965.php

Description:
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.

Votes:

   ACCEPT(4) Cole, Armstrong, Green, Baker
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:fetchmail-signed-integer-index(6965)


CAN-2001-1012

Phase: Modified (20020817-01)
Reference: SUSE:SuSE-SA:2001:030
Reference: URL:http://www.suse.com/de/support/security/2001_030_screen_txt.txt
Reference: XF:screen-local-privilege-elevation(7134)
Reference: URL:http://xforce.iss.net/static/7134.php

Description:
Vulnerability in screen before 3.9.10, related to a multi-attach error, allows local users to gain root privileges when there is a subdirectory under /tmp/screens/.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Christey
Voter Comments:
 Christey> Typo: "toa"


CAN-2001-1013

Phase: Proposed (20020131)
Reference: VULN-DEV:20000707 (no subject)
Reference: URL:http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0083.html
Reference: VULN-DEV:20000707 Re: your mail
Reference: URL:http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0094.html
Reference: VULN-DEV:20000707 Re: apache and 404/404 status codes
Reference: URL:http://archives.neohapsis.com/archives/vuln-dev/2000-q3/0087.html
Reference: BUGTRAQ:20010912 Is there user Anna at your host ?
Reference: URL:http://www.securityfocus.com/archive/1/213667
Reference: XF:linux-apache-username-exists(7129)
Reference: URL:http://xforce.iss.net/static/7129.php
Reference: BID:3335
Reference: URL:http://www.securityfocus.com/bid/3335

Description:
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists and there is no public_html directory and when the username does not exist, which could allow remote attackers to determine valid usernames on the server.

Votes:

   ACCEPT(3) Cole, Green, Frech
   MODIFY(2) Foat, Cox
   REVIEWING(1) Wall
Voter Comments:
 CHANGE> [Foat changed vote from REVIEWING to MODIFY]
 Foat> This is only true if "indexes" are NOT enabled and the
   "public_html" directory exists for the user.
 Cox> The description says "Apache on Red Hat Linux".  This issue
   affects all versions of Apache that have UserDir enabled, not just
   Linux or RHL.  In Red Hat Linux we enable UserDir by default, but so
   do other distributions.


CAN-2001-1014

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010915 advisory
Reference: URL:http://www.securityfocus.com/archive/1/214456
Reference: BID:3340
Reference: URL:http://www.securityfocus.com/bid/3340
Reference: XF:eshop-script-execute-commands(7128)
Reference: URL:http://xforce.iss.net/static/7128.php

Description:
eshop.pl in WebDiscount(e)shop allows remote attackers to execute arbitrary commands via shell metacharacters in the seite parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-1015

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011016 [ ** Snes9x buffer overflow vulnerability ** ]
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0107.html
Reference: BID:3437
Reference: URL:http://www.securityfocus.com/bid/3437

Description:
Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long command line argument.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:snes9x-rom-bo(7295)


CAN-2001-1018

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010919 lotus domino server 5.08 is very gabby
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100094373621813&w=2
Reference: BID:3350
Reference: URL:http://www.securityfocus.com/bid/3350
Reference: XF:lotus-domino-ip-reveal(7180)
Reference: URL:http://xforce.iss.net/static/7180.php

Description:
Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-1019

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010908 sglMerchant Version 1.0
Reference: URL:http://www.securityfocus.com/archive/1/212825
Reference: BID:3309
Reference: URL:http://www.securityfocus.com/bid/3309
Reference: XF:sglmerchant-dot-directory-traversal(7100)
Reference: URL:http://xforce.iss.net/static/7100.php

Description:
Directory traversal vulnerability in view_item CGI program in sglMerchant 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTML_FILE parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-1021

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010726 def-2001-28 - WS_FTP server 2.0.2 Buffer Overflow and possible DOS
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0610.html
Reference: MISC:http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.html
Reference: XF:wsftp-long-command-bo(6911)
Reference: URL:http://xforce.iss.net/static/6911.php

Description:
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Frech
   NOOP(1) Foat

CAN-2001-1023

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010921 IRM Security Advisory: Xcache Path Disclosure Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0182.html
Reference: XF:xcache-path-disclosure(7159)
Reference: URL:http://xforce.iss.net/static/7159.php
Reference: BID:3352
Reference: URL:http://www.securityfocus.com/bid/3352

Description:
Xcache 2.1 allows remote attackers to determine the absolute path of web server documents by requesting a URL that is not cached by Xcache, which returns the full pathname in the Content-PageName header.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-1024

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010727 Entrust - getAccess
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0662.html
Reference: XF:entrust-getaccess-execute-commands(6915)
Reference: URL:http://xforce.iss.net/static/6915.php

Description:
login.gas.bat and other CGI scripts in Entrust getAccess allow remote attackers to execute Java programs, and possibly arbitrary commands, by specifying an alternate -classpath argument.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Green changed vote from REVIEWING to ACCEPT]


CAN-2001-1025

Phase: Proposed (20020131)
Reference: VULNWATCH:20010803 [VulnWatch] 3 phpnuke bugs (2 possibly lead to admin privs)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0019.html
Reference: BID:3149
Reference: URL:http://www.securityfocus.com/bid/3149

Description:
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:php-nuke-prefix-admin-access(6945)


CAN-2001-1026

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010709 Various problems in Ternd Micro AppletTrap URL filtering
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0129.html
Reference: XF:applettrap-bypass-ip-restrictions(6818)
Reference: URL:http://xforce.iss.net/static/6818.php
Reference: XF:content-slash-bypass-filter(6816)
Reference: URL:http://xforce.iss.net/static/6816.php
Reference: XF:applettrap-unicode-bypass-filter(6817)
Reference: URL:http://xforce.iss.net/static/6817.php
Reference: XF:applettrap-zero-bypass-restrictions(6819)
Reference: URL:http://xforce.iss.net/static/6819.php

Description:
Trend Micro InterScan AppletTrap 2.0 does not properly filter URLs when they are modified in certain ways such as (1) using a double slash (//) instead of a single slash, (2) URL-encoded characters, (3) requesting the IP address instead of the domain name, or (4) using leading a leading 0 in an octet of an IP address.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(4) Wall, Foat, Armstrong, Christey
   REVIEWING(1) Green
Voter Comments:
 Christey> Consider adding BID:2996
 Christey> Consider adding BID:2998
 Christey> Consider adding BID:2999
 Christey> Consider adding BID:3000
 Christey> fix typo: "leading a leading"


CAN-2001-1029

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010920 Local vulnerability in libutil derived with FreeBSD 4.4-RC (and earlier)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0173.html

Description:
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.

Votes:

   ACCEPT(2) Foat, Green
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:bsd-libutil-privilege-dropping(8697)


CAN-2001-1031

Phase: Modified (20020228-01)
Reference: BUGTRAQ:20010927 CARTSA-2001-03 Meteor FTPD 1.0 Directory Traversal
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0231.html
Reference: MISC:http://207.202.218.172/
Reference: XF:meteor-ftpd-directory-traversal(7176)
Reference: URL:http://xforce.iss.net/static/7176.php
Reference: BID:3374
Reference: URL:http://online.securityfocus.com/bid/3374

Description:
Directory traversal vulnerability in Meteor FTP 1.0 allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the ls/LIST command, or (2) a ... in the cd/CWD command.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-1033

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010925 Re: HACMP and port scans
Reference: URL:http://www.securityfocus.com/archive/1/216323
Reference: XF:trucluster-portscan-dos(7171)
Reference: URL:http://xforce.iss.net/static/7171.php
Reference: BID:3362
Reference: URL:http://www.securityfocus.com/bid/3362

Description:
Compaq TruCluster 1.5 allows remote attackers to cause a denial of service via a port scan from a system that does not have a DNS PTR record, which causes the cluster to enter a "split-brain" state.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-1034

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010923 hylafax
Reference: URL:http://www.securityfocus.com/archive/1/215984
Reference: XF:hylafax-hostname-format-string(7164)
Reference: URL:http://xforce.iss.net/static/7164.php
Reference: BID:3357
Reference: URL:http://www.securityfocus.com/bid/3357

Description:
Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Christey
Voter Comments:
 Christey> Acknowledged in:
   BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed 
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html
   Vendor says problem affects all versions "prior to 4.1.3"
 Christey> Confirmed by vendor:
   BUGTRAQ:20020729 HylaFAX - Various Vulnerabilities Fixed
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-07/0358.html
   
   Also affects OSes other than FreeBSD.
   DEBIAN:DSA-148
   URL:http://www.debian.org/security/2002/dsa-148
 Christey> MANDRAKE:MDKSA-2002:055


CAN-2001-1039

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010801 HP Jetdirect passwords don't sync
Reference: URL:http://www.securityfocus.com/archive/1/201160
Reference: BID:3132
Reference: URL:http://www.securityfocus.com/bid/3132

Description:
The JetAdmin web interface for HP JetDirect does not set a password for the telnet interface when the admin password is changed, which allows remote attackers to gain access to the printer.

Votes:

   ACCEPT(2) Foat, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:jetdirect-jetadmin-telnet-access(6950)


CAN-2001-1040

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010802 Re: HP Jetdirect passwords don't sync
Reference: URL:http://www.securityfocus.com/archive/1/201224
Reference: BID:3132
Reference: URL:http://www.securityfocus.com/bid/3132

Description:
HP LaserJet, and possibly other JetDirect devices, resets the admin password when the device is turned off, which could allow remote attackers to access the device without the password.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> Not jetdirect-jetadmin-telnet-access(6950).
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:jetdirect-admin-password-reset(8713)


CAN-2001-1041

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010802 vulnerability in oracle binary in Oracle 8.0.5 - 8.1.6
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99677282117387&w=2
Reference: BUGTRAQ:20011024 Oracle File Overwrite Security Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100395579811880&w=2
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/oracle_race.pdf
Reference: BID:3135
Reference: URL:http://www.securityfocus.com/bid/3135

Description:
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.

Votes:

   ACCEPT(5) Wall, Cole, Armstrong, Green, Baker
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
Voter Comments:
 Frech> XF:oracle-binary-symlink(6940)
   Possible overlap with CAN-2001-0832 (overlapping
   references)?
 Christey> Possible dupe with CAN-2001-0832; need to review more closely.


CAN-2001-1042

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010701 Broker 5.9.5.0 Directory Traversal
Reference: URL:http://www.securityfocus.com/archive/1/194443
Reference: BID:2960
Reference: URL:http://www.securityfocus.com/bid/2960
Reference: XF:ftp-lnk-directory-traversal(6760)
Reference: URL:http://xforce.iss.net/static/6760.php

Description:
Transsoft Broker 5.9.5.0 allows remote attackers to read arbitrary files and directories by uploading a .lnk (link) file that points to the target file.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(3) Wall, Foat, Armstrong
   REVIEWING(1) Green

CAN-2001-1044

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010112 Basilix Webmail System *.class *.inc Permission Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/155897
Reference: XF:basilix-webmail-retrieve-files(5934)
Reference: URL:http://xforce.iss.net/static/5934.php
Reference: BID:2198
Reference: URL:http://www.securityfocus.com/bid/2198

Description:
Basilix Webmail 0.9.7beta, and possibly other versions, stores *.class and *.inc files under the document root and does not restrict access, which could allows remote attackers to obtain sensitive information such as MySQL passwords and usernames from the mysql.class file.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-1045

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010706 basilix bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0114.html
Reference: BID:2995
Reference: URL:http://www.securityfocus.com/bid/2995
Reference: XF:basilix-webmail-view-files(6873)
Reference: URL:http://xforce.iss.net/static/6873.php

Description:
Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the request_id[DUMMY] parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-1047

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010602 Locally exploitable races in OpenBSD VFS
Reference: URL:http://www.securityfocus.com/archive/1/188474
Reference: BID:2817
Reference: URL:http://www.securityfocus.com/bid/2817
Reference: BID:2818
Reference: URL:http://www.securityfocus.com/bid/2818
Reference: XF:openbsd-pipe-race-dos(6661)
Reference: URL:http://xforce.iss.net/static/6661.php
Reference: XF:openbsd-dup2-race-dos(6660)
Reference: URL:http://xforce.iss.net/static/6660.php

Description:
Race condition in OpenBSD VFS allows local users to cause a denial of service (kernel panic) by (1) creating a pipe in one thread and causing another thread to set one of the file descriptors to NULL via a close, or (2) calling dup2 on a file descriptor in one process, then setting the descriptor to NULL via a close in another process that is created via rfork.

Votes:

   ACCEPT(2) Cole, Frech
   MODIFY(1) Green
   NOOP(3) Wall, Foat, Armstrong
Voter Comments:
 CHANGE> [Green changed vote from REVIEWING to MODIFY]
 Green> Should be combined with other item into a single entry


CAN-2001-1050

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011002 results of semi-automatic source code audit
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html
Reference: BID:3389
Reference: URL:http://www.securityfocus.com/bid/3389
Reference: XF:php-includedir-code-execution(7215)
Reference: URL:http://xforce.iss.net/static/7215.php

Description:
CCCSoftware CCC PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

Votes:

   ACCEPT(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2001-1051

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011002 results of semi-automatic source code audit
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html
Reference: MISC:http://sourceforge.net/tracker/index.php?func=detail&aid=440666&group_id=20971&atid=120971
Reference: BID:3390
Reference: URL:http://www.securityfocus.com/bid/3390
Reference: XF:php-includedir-code-execution(7215)
Reference: URL:http://xforce.iss.net/static/7215.php

Description:
Dark Hart Portal (darkportal) PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-1052

Phase: Proposed (20020131)
Reference: BUGTRAQ:20011002 results of semi-automatic source code audit
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0012.html
Reference: BID:3391
Reference: URL:http://www.securityfocus.com/bid/3391
Reference: XF:php-includedir-code-execution(7215)
Reference: URL:http://xforce.iss.net/static/7215.php

Description:
Empris PHP script allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole

CAN-2001-1055

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010730 ARPNuke - 80 kb/s kills a whole subnet
Reference: URL:http://www.securityfocus.com/archive/1/200323
Reference: BID:3113
Reference: URL:http://www.securityfocus.com/bid/3113

Description:
Vulnerability in the Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP request packets with random source IP and MAC addresses.

Votes:

   ACCEPT(1) Foat
   MODIFY(2) Green, Frech
   NOOP(3) Wall, Cole, Armstrong
Voter Comments:
 Green> TOO VAGUE TO REACH ANY CONCLUSION
 Frech> XF:win-arp-packet-flooding-dos(6924)


CAN-2001-1057

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010730 a couple minor issues with mathematica license manager
Reference: URL:http://www.securityfocus.com/archive/1/200462
Reference: BID:3120
Reference: URL:http://www.securityfocus.com/bid/3120
Reference: XF:mathematica-license-dos(6926)
Reference: URL:http://xforce.iss.net/static/6926.php

Description:
The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by connecting to port 16286 and not disconnecting, which prevents users from making license requests.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-1058

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010730 a couple minor issues with mathematica license manager
Reference: URL:http://www.securityfocus.com/archive/1/200462
Reference: BID:3118
Reference: URL:http://www.securityfocus.com/bid/3118
Reference: XF:mathematica-license-retrieval(6927)
Reference: URL:http://xforce.iss.net/static/6927.php

Description:
The License Manager (mathlm) for Mathematica 4.0 and 4.1 allows remote attackers to bypass access control (specified by the -restrict argument) and steal a license via a client request that includes the name of a host that is allowed to obtain the license.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-1060

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010731 New command execution vulnerability in myPhpAdmin
Reference: URL:http://www.securityfocus.com/archive/1/200596
Reference: MISC:http://freshmeat.net/redir/phpmyadmin/8001/url_changelog/
Reference: BID:3121
Reference: URL:http://www.securityfocus.com/bid/3121

Description:
phpMyAdmin 2.2.0rc3 and earlier allows remote attackers to execute arbirtrary commands by inserting them into (1) the strCopyTableOK argument in tbl_copy.php, or (2) the strRenameTableOK argument in tbl_rename.php.

Votes:

   ACCEPT(1) Cole
   MODIFY(2) Green, Frech
   NOOP(3) Wall, Foat, Armstrong
Voter Comments:
 Green> Combining similar issues for the same product sounds reasonable
 Frech> XF:phpmyadmin-eval-execute-commands(6929)


CAN-2001-1061

Phase: Proposed (20020131)
Reference: AIXAPAR:IY22255
Reference: URL:http://archives.neohapsis.com/archives/aix/2001-q3/0003.html

Description:
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.

Votes:

   ACCEPT(4) Cole, Armstrong, Green, Baker
   MODIFY(2) Bollinger, Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Bollinger> Affects AIX 4.3 with bos.diag.util versions less than
   4.3.3.75 and AIX 5.1 with bos.diag.util versions less than 5.1.0.10.
   The 4.3 APAR is IY22255 and the 5.1 APAR is IY22266.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:aix-lsmcode-usage-error(8714) 


CAN-2001-1064

Phase: Proposed (20020131)
Reference: CISCO:20010823 CBOS Web-based Configuration Utility Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml
Reference: BID:3236
Reference: URL:http://www.securityfocus.com/bid/3236
Reference: XF:cisco-cbos-telnet-dos(7025)
Reference: URL:http://xforce.iss.net/static/7025.php
Reference: XF:cisco-cbos-http-dos(7026)
Reference: URL:http://xforce.iss.net/static/7026.php

Description:
Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap allows remote attackers to cause a denial of service via multiple connections to the router on the (1) HTTP or (2) telnet service, which causes the router to become unresponsive and stop forwarding packets.

Votes:

   ACCEPT(5) Cole, Armstrong, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-1065

Phase: Proposed (20020131)
Reference: CISCO:20010823 CBOS Web-based Configuration Utility Vulnerability
Reference: URL:http://www.cisco.com/warp/public/707/cisco-cbos-webserver-pub.shtml
Reference: XF:cisco-cbos-web-config(7027)
Reference: URL:http://xforce.iss.net/static/7027.php

Description:
Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack.

Votes:

   ACCEPT(5) Cole, Armstrong, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-1066

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010827 Dangerous temp file creation during installation of Netscape 6.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99893667921216&w=2

Description:
ns6install installation script for Netscape 6.01 on Solaris allows local users to overwrite files via a symlink attack.

Votes:

   ACCEPT(2) Dik, Green
   MODIFY(1) Frech
   NOOP(4) Foat, Cole, Armstrong, Christey
   REVIEWING(1) Wall
Voter Comments:
 Dik> Verified by code inspection of ns6install from netscape 6.2.1 beta
   Sun bug: 4633888 (just filed)
 Christey> BID:3243
   URL:http://www.securityfocus.com/bid/3243
   XF:netscape-install-tmpfile-symlink(7042)
   URL:http://xforce.iss.net/static/7042.php
 Christey> VULNWATCH:20010827 [VulnWatch] Dangerous temp file creation during installation of Netscape 6.
   URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0036.html
 Frech> XF:netscape-install-tmpfile-symlink(7042)


CAN-2001-1068

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010825 qpopper and pam.d
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0363.html
Reference: XF:qpopper-pam-auth-error(7047)
Reference: URL:http://xforce.iss.net/static/7047.php
Reference: BID:3242
Reference: URL:http://www.securityfocus.com/bid/3242

Description:
qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system.

Votes:

   ACCEPT(3) Foat, Green, Frech
   NOOP(2) Cole, Armstrong
   REVIEWING(1) Wall

CAN-2001-1069

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010822 Adobe Acrobat creates world writable ~/AdobeFnt.lst files
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99849121502399&w=2
Reference: MISC:http://lists.debian.org/debian-security/2001/debian-security-200101/msg00085.html
Reference: BID:3225
Reference: URL:http://www.securityfocus.com/bid/3225
Reference: XF:adobe-acrobat-insecure-permissions(7024)
Reference: URL:http://xforce.iss.net/static/7024.php

Description:
libCoolType library as used in Adobe Acrobat (acroread) on Linux creates the AdobeFnt.lst file with world-writable permissions, which allows local users to modify the file and possibly modify acroread's behavior.

Votes:

   ACCEPT(3) Foat, Green, Frech
   NOOP(3) Cole, Armstrong, Christey
   REVIEWING(1) Wall
Voter Comments:
 Christey> SGI:20020806-01-I points to this candidate, but I'm not so
   sure that's correct; the SGI advisory discusses symlink
   attacks, but this CAN is related to permissions.


CAN-2001-1070

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010821 Bug in MAS90 Accounting Platform remote access?
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0312.html
Reference: XF:mas-telnet-connect-dos(7020)
Reference: URL:http://xforce.iss.net/static/7020.php
Reference: BID:3221
Reference: URL:http://www.securityfocus.com/bid/3221

Description:
Sage Software MAS 200 allows remote attackers to cause a denial of service by connecting to port 10000 and entering a series of control characters.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-1073

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010815 webridge application suite gives up too much error information on Internal Server Error
Reference: URL:http://www.securityfocus.com/archive/1/204725
Reference: XF:webridge-px-reveal-information(6993)
Reference: URL:http://xforce.iss.net/static/6993.php
Reference: BID:3182
Reference: URL:http://www.securityfocus.com/bid/3182

Description:
Webridge PX Application Suite allows remote attackers to obtain sensitive information via a malformed request that generates a server error message, which includes full pathname or internal IP address information in the variables (1) APPL_PHYSICAL_PATH, (2) PATH_TRANSLATED, and (3) LOCAL_ADDR.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Armstrong

CAN-2001-1076

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010705 Solaris whodo Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0076.html
Reference: BID:2935
Reference: URL:http://www.securityfocus.com/bid/2935
Reference: XF:solaris-whodo-bo(6802)
Reference: URL:http://xforce.iss.net/static/6802.php

Description:
Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.

Votes:

   ACCEPT(2) Green, Frech
   MODIFY(1) Dik
   NOOP(3) Foat, Cole, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Dik> Sun bug: 4477380
   Description errors: CFIME -> CFTIME
   Don't understand "SOR" environment variable.  This must
   presumably be TZ


CAN-2001-1077

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010615 Rxvt vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/191510
Reference: DEBIAN:DSA-062
Reference: URL:http://www.debian.org/security/2001/dsa-062
Reference: IMMUNIX:IMNX-2001-70-028-01
Reference: URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-028-01
Reference: MANDRAKE:MDKSA-2001:060
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-060.php
Reference: XF:rxvt-ttprintf-bo(6701)
Reference: URL:http://xforce.iss.net/static/6701.php
Reference: BID:2878
Reference: URL:http://online.securityfocus.com/bid/2878

Description:
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name argument.

Votes:

   ACCEPT(5) Cole, Armstrong, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-1078

Phase: Proposed (20020131)
Reference: BUGTRAQ:20010622 eXtremail Remote Format String ('s)
Reference: URL:http://www.securityfocus.com/archive/1/192791
Reference: CONFIRM:http://www.extremail.com/history.htm
Reference: CONFIRM:http://www.extremail.com/news.htm
Reference: XF:extremail-flog-format-string(6733)
Reference: URL:http://xforce.iss.net/static/6733.php
Reference: BID:2908
Reference: URL:http://www.securityfocus.com/bid/2908

Description:
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.

Votes:

   ACCEPT(5) Cole, Armstrong, Green, Baker, Frech
   NOOP(2) Wall, Foat

CAN-2001-1081

Phase: Proposed (20020131)
Reference: CONFIRM:http://freshmeat.net/releases/52020/
Reference: BID:2994
Reference: URL:http://www.securityfocus.com/bid/2994

Description:
Format string vulnerabilities in Livingston/Lucent RADIUS before 2.1.va.1 may allow local or remote attackers to cause a denial of service and possibly execute arbitrary code via format specifiers that are injected into log messages.

Votes:

   ACCEPT(4) Cole, Armstrong, Green, Baker
   MODIFY(2) Christey, Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> ISS: ISS Security Advisory: Remote Buffer Overflow in Multiple RADIUS
   Implementations
   XF:lucent-radius-authentication-bo(6794)
   CONFIRM reference is no longer available.
 Christey> VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
   URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html
   MISC:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html


CAN-2001-1082

Phase: Proposed (20020131)
Reference: CONFIRM:http://freshmeat.net/releases/52020/

Description:
Directory traversal vulnerability in Livingston/Lucent RADIUS before 2.1.va.1 may allow attackers to read arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(4) Cole, Armstrong, Green, Baker
   MODIFY(1) Christey
   NOOP(2) Wall, Foat
   REJECT(1) Frech
Voter Comments:
 Frech> Reference no longer exists, and has no title for cross
   reference.
 CHANGE> [Frech changed vote from REVIEWING to REJECT]
 Frech> Dead reference; will reconsider revote if valid reference
   presented.
 Christey> MISC:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0009.html


CAN-2001-1086

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010704 xdm cookies fast brute force
Reference: URL:http://www.securityfocus.com/archive/1/194907
Reference: BUGTRAQ:20010705 Re: xdm cookies fast brute force
Reference: URL:http://online.securityfocus.com/archive/1/195008
Reference: BID:2985
Reference: URL:http://www.securityfocus.com/bid/2985
Reference: XF:xdm-cookie-brute-force(6808)
Reference: URL:http://xforce.iss.net/static/6808.php

Description:
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

Votes:

   ACCEPT(6) Cole, Armstrong, Green, Baker, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-1087

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010705 RE: Tunnel ports allowed on NetApp NetCaches
Reference: URL:http://www.securityfocus.com/archive/1/195176
Reference: XF:netcache-tunnel-default-configuration(6807)
Reference: URL:http://xforce.iss.net/static/6807.php
Reference: BID:2990
Reference: URL:http://www.securityfocus.com/bid/2990

Description:
The default configuration of the config.http.tunnel.allow_ports option on NetCache devices is set to +all, which allows remote attackers to connect to arbitrary ports on remote systems behind the device.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Green, Ziese

CAN-2001-1090

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010910 RUS-CERT Advisory 2001-09:01
Reference: URL:http://www.securityfocus.com/archive/1/213331
Reference: BID:3315
Reference: URL:http://www.securityfocus.com/bid/3315
Reference: XF:postgresql-nss-authentication-modules(7111)
Reference: URL:http://xforce.iss.net/static/7111.php

Description:
nss_postgresql 0.6.1 and before allows a remote attacker to execute arbitrary SQL queries by inserting SQL code into an HTTP request.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1091

Phase: Proposed (20020315)
Reference: NETBSD:NetBSD-SA2001-014
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2001-014.txt.asc
Reference: XF:bsd-dump-tty-privileges(7037)
Reference: URL:http://xforce.iss.net/static/7037.php

Description:
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.

Votes:

   ACCEPT(6) Cole, Armstrong, Green, Baker, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-1092

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010910 Digital Unix 4.0x msgchk multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/213238
Reference: CERT-VN:VU#440539
Reference: URL:http://www.kb.cert.org/vuls/id/440539
Reference: BID:3320
Reference: URL:http://www.securityfocus.com/bid/3320
Reference: XF:du-msgchk-symlink(7102)
Reference: URL:http://xforce.iss.net/static/7102.php

Description:
msgchk in Digital UNIX 4.0G and earlier allows a local user to read the first line of arbitrary files via a symlink attack on the .mh_profile file.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Green, Ziese
Voter Comments:
 CHANGE> [Green changed vote from REVIEWING to NOOP]


CAN-2001-1093

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010910 Digital Unix 4.0x msgchk multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/213238
Reference: XF:du-msgchk-bo(7101)
Reference: URL:http://xforce.iss.net/static/7101.php
Reference: BID:3311
Reference: URL:http://www.securityfocus.com/bid/3311

Description:
Buffer overflow in msgchk in Digital UNIX 4.0G and earlier allows local users to execute arbitrary code via a long command line argument.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Green, Ziese

CAN-2001-1094

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010911 NetOP School Admin Vulnerability for Windows 2000 Terminal Services and NT4
Reference: URL:http://www.securityfocus.com/archive/1/213516
Reference: BID:3321
Reference: URL:http://www.securityfocus.com/bid/3321
Reference: XF:netop-school-bypass-authentication(7120)
Reference: URL:http://xforce.iss.net/static/7120.php

Description:
NetOp School 1.5 allows local users to bypass access restrictions on the administration version by logging into the student version, closing the student version, then starting the administration version.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1097

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010724 UDP packet handling weird behaviour of various operating systems
Reference: URL:http://www.securityfocus.com/archive/1/199558
Reference: BUGTRAQ:20010811 Re: UDP packet handling weird behaviour of various operating systems
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99749327219189&w=2
Reference: BID:3096
Reference: URL:http://www.securityfocus.com/bid/3096
Reference: XF:cisco-ios-udp-dos(6319)
Reference: URL:http://xforce.iss.net/static/6913.php

Description:
Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a flood of UDP packets.

Votes:

   ACCEPT(2) Cole, Frech
   NOOP(4) Wall, Foat, Armstrong, Green
   REVIEWING(2) Baker, Ziese
Voter Comments:
 Green> TOO VAGUE
 Frech> XF:cisco-ios-udp-dos(6319) should be
   XF:cisco-ios-udp-dos(6913). URL is correct.


CAN-2001-1098

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011010 Vulnerability: Cisco PIX Firewall Manager
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0071.html
Reference: XF:cisco-pfm-plaintext-password(7265)
Reference: URL:http://xforce.iss.net/static/7265.php

Description:
Cisco PIX firewall manager (PFM) 4.3(2)g logs the enable password in plaintext in the pfm.log file, which could allow local users to obtain the password by reading the file.

Votes:

   ACCEPT(3) Foat, Green, Frech
   NOOP(3) Wall, Cole, Armstrong
   REVIEWING(1) Ziese
Voter Comments:
 CHANGE> [Armstrong changed vote from REVIEWING to NOOP]
 Frech> HAS-INDEPENDENT-CONFIRMATION:http://www.kb.cert.org/vuls/id/6
   39507


CAN-2001-1101

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010908 Bug in remote GUI access in CheckPoint Firewall
Reference: URL:http://www.securityfocus.com/archive/1/212826
Reference: XF:fw1-log-file-overwrite(7095)
Reference: URL:http://xforce.iss.net/static/7095.php
Reference: BID:3303
Reference: URL:http://www.securityfocus.com/bid/3303

Description:
The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1102

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010908 Bug in compile portion for older versions of CheckPoint Firewalls
Reference: URL:http://www.securityfocus.com/archive/1/212824
Reference: XF:fw1-tmp-file-symlink(7094)
Reference: URL:http://xforce.iss.net/static/7094.php
Reference: BID:3300
Reference: URL:http://www.securityfocus.com/bid/3300

Description:
Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Christey, Ziese
Voter Comments:
 Christey> NOTE: CAN-2001-1171 was discovered to be a duplicate of this
   issue.  Use this candidate (CAN-2001-1102) instead of the
   other one.


CAN-2001-1103

Phase: Proposed (20020315)
Reference: CERT-VN:VU#320944
Reference: URL:http://www.kb.cert.org/vuls/id/320944
Reference: XF:ftp-voyager-embedded-script-execution(7119)
Reference: URL:http://xforce.iss.net/static/7119.php

Description:
FTP Voyager ActiveX control before 8.0, when it is marked as safe for scripting (the default) or if allowed by the IObjectSafety interface, allows remote attackers to execute arbitrary commands.

Votes:

   ACCEPT(4) Green, Baker, Frech, Ziese
   NOOP(3) Foat, Cole, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Green> Vendor appears to have acknowledged with a new release of the product, although there is no explicit citing of the vulnerability on the vendor's website 


CAN-2001-1104

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010725 Weak TCP Sequence Numbers in Sonicwall SOHO Firewall
Reference: URL:http://www.securityfocus.com/archive/1/199632
Reference: BID:3098
Reference: URL:http://www.securityfocus.com/bid/3098

Description:
SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.

Votes:

   ACCEPT(1) Foat
   MODIFY(1) Frech
   NOOP(5) Wall, Cole, Armstrong, Green, Ziese
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:tcp-seq-predict(139)


CAN-2001-1105

Phase: Proposed (20020315)
Reference: CIAC:L-141
Reference: URL:http://www.ciac.org/ciac/bulletins/l-141.shtml
Reference: CISCO:20010912 Vulnerable SSL Implementation in iCDN
Reference: URL:http://www.cisco.com/warp/public/707/SSL-J-pub.html
Reference: CONFIRM:http://www.rsasecurity.com/products/bsafe/bulletins/BSAFE_SSL-J_3.x.SecurityBulletin.html
Reference: BID:3329
Reference: URL:http://www.securityfocus.com/bid/3329
Reference: XF:bsafe-ssl-bypass-authentication(7112)
Reference: URL:http://xforce.iss.net/static/7112.php

Description:
RSA BSAFE SSL-J 3.0, 3.0.1 and 3.1, as used in Cisco iCND 2.0, caches session IDs from failed login attempts, which could allow remote attackers to bypass SSL client authentication and gain access to sensitive data by logging in after an initial failure.

Votes:

   ACCEPT(6) Cole, Armstrong, Green, Baker, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-1107

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010726 Snapstream PVS vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0606.html
Reference: CONFIRM:http://discuss.snapstream.com/ubb/Forum1/HTML/000216.html
Reference: XF:snapstream-dot-directory-traversal(6917)
Reference: URL:http://xforce.iss.net/static/6917.php
Reference: BID:3101
Reference: URL:http://www.securityfocus.com/bid/3101

Description:
SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain privileges on the server.

Votes:

   ACCEPT(5) Armstrong, Green, Baker, Frech, Ziese
   NOOP(3) Wall, Foat, Cole

CAN-2001-1109

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010912 EFTP Version 2.0.7.337 vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/213647
Reference: MISC:http://www.eftp.org/releasehistory.html
Reference: XF:eftp-list-directory-traversal(7113)
Reference: URL:http://xforce.iss.net/static/7113.php
Reference: XF:eftp-quote-reveal-information(7114)
Reference: URL:http://xforce.iss.net/static/7114.php
Reference: BID:3331
Reference: URL:http://www.securityfocus.com/bid/3331
Reference: BID:3333
Reference: URL:http://www.securityfocus.com/bid/3333

Description:
Directory traversal vulnerability in EFTP 2.0.7.337 allows remote authenticated users to reveal directory contents via a .. (dot dot) in the (1) LIST, (2) QUOTE SIZE, and (3) QUOTE MDTM commands.

Votes:

   ACCEPT(3) Green, Baker, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Baker> Apparently vendor acknowledgement of the directory problems in the
   release history, located at:
   http://www.eftp.org/releasehistory.html
   2.0.8.345  2001.12.04
   Fixed a problem where the server would give a GPF whn disconnecting a single user
   Added Ratios Feature
   Added Statistics Feature
   Modified User/Group Administration - now much more stable
   Modified Startup Logo
   Modifed all data files to .ini files for easy editing and to save space
   Added Feature to save/load queues
   Added auto reconnect feature on timeout
   Fully Implemented RSA Control Port encryption, so now even commands like USER, PASS, GET, REST etc are encrypted. Total security on both data and commands.
   Added Idle Timout for the Server component
   Fixed some security flaws with directory listings


CAN-2001-1110

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010912 EFTP Version 2.0.7.337 vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/213647

Description:
EFTP 2.0.7.337 allows remote attackers to obtain NETBIOS credentials by requesting information on a file that is in a network share, which causes the server to send the credentials to the host that owns the share, and allows the attacker to sniff the connection.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Frech> XF:eftp-list-directory-traversal(7113)
   In description, NETBIOS should be NetBIOS.


CAN-2001-1111

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010912 EFTP Version 2.0.7.337 vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/213647
Reference: XF:eftp-plaintext-password(7116)
Reference: URL:http://xforce.iss.net/static/7116.php
Reference: BID:3332
Reference: URL:http://www.securityfocus.com/bid/3332

Description:
EFTP 2.0.7.337 stores user passwords in plaintext in the eftp2users.dat file.

Votes:

   ACCEPT(3) Green, Baker, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Baker> It looks like this issue was modified in the changelog, but the basic issue
   still exists.  They moved all data files into the ini file.  Still a
   plain text file, however.  It would have been better in a registry setting
   so it was harder to get to...
   
   2.0.8.345  2001.12.04
   Fixed a problem where the server would give a GPF whn disconnecting a single user
   Added Ratios Feature
   Added Statistics Feature
   Modified User/Group Administration - now much more stable
   Modified Startup Logo
   Modifed all data files to .ini files for easy editing and to save space
   Added Feature to save/load queues
   Added auto reconnect feature on timeout
   Fully Implemented RSA Control Port encryption, so now even commands like USER, PASS, GET, REST etc are encrypted. Total security on both data and commands.
   Added Idle Timout for the Server component
   Fixed some security flaws with directory listings


CAN-2001-1112

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010912 EFTP Version 2.0.7.337 vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/213647
Reference: BID:3330
Reference: URL:http://www.securityfocus.com/bid/3330
Reference: XF:eftp-lnk-bo(7115)
Reference: URL:http://xforce.iss.net/static/7115.php

Description:
Buffer overflow in EFTP 2.0.7.337 allows remote attackers to execute arbitrary code by uploading a .lnk file containing a large number of characters.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1114

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010813 NetCode NC Book 0.2b remote command execution vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/204094
Reference: XF:netcode-book-pipes-command(6986)
Reference: URL:http://xforce.iss.net/static/6986.php
Reference: BID:3178
Reference: URL:http://www.securityfocus.com/bid/3178

Description:
book.cgi in NetCode NC Book 0.2b allows remote attackers to execute arbitrary commands via shell metacharacters in the "current" parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Green
   REVIEWING(1) Ziese

CAN-2001-1115

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010813 SIX-webboard 2.01 "show files" vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/204053
Reference: XF:sixwebboard-dot-directory-traversal(6975)
Reference: URL:http://xforce.iss.net/static/6975.php
Reference: BID:3175
Reference: URL:http://www.securityfocus.com/bid/3175

Description:
generate.cgi in SIX-webboard 2.01 and before allows remote attackers to read arbitrary files via a dot dot (..) in the content parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1120

Phase: Proposed (20020315)
Reference: CONFIRM:http://www.allaire.com/handlers/index.cfm?id=21566
Reference: CERT-VN:VU#135531
Reference: URL:http://www.kb.cert.org/vuls/id/135531
Reference: BUGTRAQ:20010712 New Cold Fusion vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/196452
Reference: XF:coldfusion-unauthorized-file-access(6839)
Reference: URL:http://xforce.iss.net/static/6839.php
Reference: BID:3018
Reference: URL:http://www.securityfocus.com/bid/3018

Description:
Vulnerabilities in ColdFusion 2.0 through 4.5.1 SP 2 allow remote attackers to (1) read or delete arbitrary files, or (2) overwrite ColdFusion Server templates

Votes:

   ACCEPT(7) Foat, Cole, Armstrong, Green, Baker, Frech, Ziese
   NOOP(1) Christey
   REVIEWING(1) Wall
Voter Comments:
 Green> Acknowledged by vendor in Macromedia Product Security Bulletin (MPSB01-07) issued in July, 2001
 Foat> Note that the link to the confirm should be 
   http://www.macomedia.com/v1/handlers/index.cfm?id=21566.
 Christey> Add period to the end of the description.


CAN-2001-1122

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010803 REPOST: A damaging local DoS in WinNT SP6a
Reference: URL:http://www.securityfocus.com/archive/1/201722
Reference: XF:winnt-nt4all-dos(6943)
Reference: URL:http://xforce.iss.net/static/6943.php
Reference: BID:3144
Reference: URL:http://www.securityfocus.com/bid/3144

Description:
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.

Votes:

   ACCEPT(3) Foat, Green, Frech
   NOOP(1) Cole
   REJECT(2) Armstrong, Ziese
   REVIEWING(2) Wall, Baker
Voter Comments:
 Ziese> fact that important system
   files are not appropriately secured from user, a/o admin, level access.
 Green> ACCESS TO THE WINNT/SYSTEM32 DIRECTORY, ALLOWING FOR A DoS TO BE PERFORMED.
 Foat> Our attempts to repair the computer with the Windows NT cd-rom failed. 
   The machine still would not allow logins. Tried two different NT 4.0 CD's. Both 
   CD's gave the error message that the file MSV1_0.dll read okay but is invalid on 
   the hard drive. It says the CD is probably defective.
 Armstrong> I don't believe that a privileged user being able to run code
   on a system is a vulnerability.
 Baker> I generally agree that unless you are elevating your priveleges, this should not be listed as a vulnerability.


CAN-2001-1123

Phase: Proposed (20020315)
Reference: HP:HPSBUX0110-170
Reference: URL:http://www.securityfocus.com/advisories/3585
Reference: HP:HPSBUX0112-177
Reference: URL:http://www.securityfocus.com/advisories/3723
Reference: BID:3399
Reference: URL:http://www.securityfocus.com/bid/3399
Reference: XF:openview-nmm-gain-privileges(7222)
Reference: URL:http://xforce.iss.net/static/7222.php
Reference: CERT-VN:VU#782155
Reference: URL:http://www.kb.cert.org/vuls/id/782155

Description:
Vulnerability in Network Node Manager (NNM) 6.2 and earlier in HP OpenView allows a local user to execute arbitrary code, possibly via a buffer overflow in a long hostname or object ID.

Votes:

   ACCEPT(4) Cole, Green, Baker, Frech
   NOOP(4) Wall, Foat, Armstrong, Ziese

CAN-2001-1124

Phase: Proposed (20020315)
Reference: HP:HPSBUX0110-169
Reference: URL:http://www.securityfocus.com/advisories/3586
Reference: CIAC:M-003
Reference: URL:http://www.ciac.org/ciac/bulletins/m-003.shtml
Reference: XF:hp-rpcbind-dos(7221)
Reference: URL:http://xforce.iss.net/static/7221.php
Reference: BID:3400
Reference: URL:http://www.securityfocus.com/bid/3400

Description:
rpcbind in HP-UX 11.00, 11.04 and 11.11 allows remote attackers to cause a denial of service (core dump) via a malformed RPC portmap requests, possibly related to a buffer overflow.

Votes:

   ACCEPT(4) Cole, Green, Frech, Ziese
   NOOP(3) Wall, Foat, Armstrong
   RECAST(2) Christey, Baker
Voter Comments:
 Christey> typo: "a malformed RPC portmap requests"
 CHANGE> [Christey changed vote from NOOP to RECAST]
 Christey> CAN-2002-0039 (SGI rpcbind) is the same problem as
   CAN-2001-1124 (HP rpcbind).  These 2 candidates need to be
   merged.
 Baker> MERGE with CAN-2002-0039


CAN-2001-1125

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011005 Symantec LiveUpdate attacks
Reference: URL:http://www.securityfocus.com/archive/1/218717
Reference: CONFIRM:http://www.sarc.com/avcenter/security/Content/2001.10.05.html
Reference: BID:3403
Reference: URL:http://www.securityfocus.com/bid/3403
Reference: XF:liveupdate-host-verification(7235)
Reference: URL:http://xforce.iss.net/static/7235.php

Description:
Symantec LiveUpdate before 1.6 does not use cryptography to ensure the integrity of download files, which allows remote attackers to execute arbitrary code via DNS spoofing of the update.symantec.com site.

Votes:

   ACCEPT(7) Cole, Armstrong, Green, Prosser, Baker, Frech, Ziese
   NOOP(2) Wall, Foat
Voter Comments:
 Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html
   
   Good split
 Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html
   
   Good split


CAN-2001-1126

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011005 Symantec LiveUpdate attacks
Reference: URL:http://www.securityfocus.com/archive/1/218717
Reference: CONFIRM:http://www.sarc.com/avcenter/security/Content/2001.10.05.html
Reference: XF:liveupdate-host-verification(7235)
Reference: URL:http://xforce.iss.net/static/7235.php
Reference: BID:3413
Reference: URL:http://www.securityfocus.com/bid/3413

Description:
Symantec LiveUpdate 1.4 through 1.6, and possibly later versions, allows remote attackers to cause a denial of service (flood) via DNS spoofing of the update.symantec.com site.

Votes:

   ACCEPT(7) Cole, Armstrong, Green, Prosser, Baker, Frech, Ziese
   NOOP(2) Wall, Foat
Voter Comments:
 Green> IN ONE VERSION, BUT NOT IN THE OTHER
 Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2001.10.05.html
   
   Concur with Analysis, this should be split.  The DoS would
   include all versions of LiveUpdate, 1.4.x through 1.6.x.  The
   potential for unauthorized code execution only impacts 1.4.x through
   1.5.x.


CAN-2001-1127

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011005 Progress Database vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/218833
Reference: BID:3404
Reference: URL:http://www.securityfocus.com/bid/3404
Reference: XF:progress-strcpy-bo(7236)
Reference: URL:http://xforce.iss.net/static/7236.php

Description:
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv, (2) _mprosrv, (3) _mprshut, (4) orarx, (5) sqlcpp, (6) _probrkr, (7) _sqlschema and (8) _sqldump.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(4) Wall, Foat, Armstrong, Ziese
Voter Comments:
 Green> IN ONE VERSION, BUT NOT IN THE OTHER


CAN-2001-1128

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011008 Progress TERM (protermcap) overflows and PROMSGS overflows
Reference: URL:http://www.securityfocus.com/archive/1/219174
Reference: XF:progress-protermcap-bo(7264)
Reference: URL:http://xforce.iss.net/static/7264.php
Reference: BID:3414
Reference: URL:http://www.securityfocus.com/bid/3414

Description:
Buffer overflow in Progress database 8.3D and 9.1C allows local users to execute arbitrary code via long entries in files that are specified by the (1) PROMSGS or (2) PROTERMCAP environment variables.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Green> FIXED IN ONE VERSION, BUT NOT IN THE OTHER


CAN-2001-1129

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011102 Progres Databse PROMSGS Format strings issue.
Reference: URL:http://www.securityfocus.com/archive/1/224395
Reference: BID:3502
Reference: URL:http://www.securityfocus.com/bid/3502
Reference: XF:progress-promsgs-format-string(7457)
Reference: URL:http://xforce.iss.net/static/7457.php

Description:
Format string vulnerabilities in (1) _probuild, (2) _dbutil, (3) _mprosrv, (4) _mprshut, (5) _proapsv, (6) _progres, (7) _proutil, (8) _rfutil and (9) prolib in Progress database 9.1C allows a local user to execute arbitrary code via format string specifiers in the file used by the PROMSGS environment variable.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Green> FIXED IN ONE VERSION, BUT NOT IN THE OTHER


CAN-2001-1131

Phase: Proposed (20020315)
Reference: MISC:http://www.securiteam.com/windowsntfocus/5RP0L0055O.html

Description:
Directory traversal vulnerability in WhitSoft Development SlimFTPd 2.2 allows an attacker to read arbitrary files and directories via a ... (modified dot dot) in the CD command.

Votes:

   ACCEPT(1) Green
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
   REVIEWING(1) Frech

CAN-2001-1133

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010821 BSDi (3.0/3.1) reboot machine code as any user (non-specific)
Reference: URL:http://www.securityfocus.com/archive/1/209192
Reference: XF:bsd-kernel-dos(7023)
Reference: URL:http://www.iss.net/security_center/static/7023.php
Reference: BID:3220
Reference: URL:http://www.securityfocus.com/bid/3220

Description:
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1134

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010720 Re: Two birds with one worm
Reference: URL:http://www.securityfocus.com/archive/1/198381
Reference: BUGTRAQ:20010809 Xerox N40 printers and Code Red worm
Reference: URL:http://www.securityfocus.com/archive/1/203025
Reference: XF:xerox-docuprint-dos(6976)
Reference: URL:http://www.iss.net/security_center/static/6976.php
Reference: BID:3170
Reference: URL:http://online.securityfocus.com/bid/3170

Description:
Xerox DocuPrint N40 Printers allow remote attackers to cause a denial of service via malformed data, such as that produced by the Code Red worm.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1135

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010814 Fwd: ZyXEL Prestige 642 Router Administration Interface Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/204439
Reference: BUGTRAQ:20010810 Re: ZyXEL Prestige 642R: Exposed Admin Services on WAN with Default Password
Reference: URL:http://www.securityfocus.com/archive/1/203592
Reference: BUGTRAQ:20010809 ZyXEL Prestige 642R: Exposed Admin Services on WAN with Default Password
Reference: URL:http://www.securityfocus.com/archive/1/203022
Reference: BUGTRAQ:20010918 SECURITY RISK: ZyXEL ADSL Router 642R - WAN filter bypass from internal network
Reference: URL:http://www.securityfocus.com/archive/1/214971
Reference: BID:3346
Reference: URL:http://www.securityfocus.com/bid/3346
Reference: XF:prestige-wan-bypass-filter(7146)
Reference: URL:http://xforce.iss.net/static/7146.php

Description:
ZyXEL Prestige 642R and 642R-I routers do not filter the routers' Telnet and FTP ports on the external WAN interface from inside access, allowing someone on an internal computer to reconfigure the router, if the password is known.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1136

Phase: Proposed (20020315)
Reference: HP:HPSBUX0109-166
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q3/0063.html
Reference: CIAC:L-143
Reference: URL:http://www.ciac.org/ciac/bulletins/l-143.shtml
Reference: XF:hp-virtualvault-libsecurity-dos(7124)
Reference: URL:http://xforce.iss.net/static/7124.php
Reference: BID:3338
Reference: URL:http://online.securityfocus.com/bid/3338

Description:
The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.

Votes:

   ACCEPT(6) Cole, Armstrong, Green, Baker, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-1137

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010906 Malformed Fragmented Packets DoS Dlink Firewall/Routers
Reference: URL:http://www.securityfocus.com/archive/1/212532
Reference: XF:dlink-fragmented-packet-dos(7090)
Reference: URL:http://xforce.iss.net/static/7090.php
Reference: BID:3306
Reference: URL:http://online.securityfocus.com/bid/3306

Description:
D-Link DI-704 Internet Gateway firmware earlier than V2.56b6 allows remote attackers to cause a denial of service (reboot) via malformed IP datagram fragments.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Green> WITHOUT COMMENT


CAN-2001-1138

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010907 *** Security Advisory *** Power UP HTML
Reference: URL:http://www.securityfocus.com/archive/1/212679
Reference: BID:3304
Reference: URL:http://www.securityfocus.com/bid/3304
Reference: XF:powerup-rcgi-directory-traversal(7092)
Reference: URL:http://xforce.iss.net/static/7092.php

Description:
Directory traversal vulnerability in r.pl (aka r.cgi) of Randy Parker Power Up HTML 0.8033beta allows remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the FILE parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1139

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010822 [SNS Advisory No.39] WinWrapper Professional 2.0 Remote Arbitrary File Disclosure Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/209414
Reference: MISC:http://www.tsc.ant.co.jp/products/download.htm
Reference: BID:3219
Reference: URL:http://www.securityfocus.com/bid/3219
Reference: XF:winwrapper-dot-directory-traversal(7015)
Reference: URL:http://www.iss.net/security_center/static/7015.php

Description:
Directory traversal vulnerability in ASCII NT WinWrapper Professional allows remote attackers to read arbitrary files via a .. (dot dot) in the server request.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1140

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010822 -- [ iSecureLabs BadBlue v1.02 beta for Windows 98, ME and 2000 Advisory ] --
Reference: URL:http://www.securityfocus.com/archive/1/209545
Reference: XF:badblue-file-source-disclosure (7021)
Reference: URL:http://xforce.iss.net/static/7021.php
Reference: BID:3222
Reference: URL:http://www.securityfocus.com/bid/3222

Description:
BadBlue Personal Edition v1.02 beta allows remote attackers to read source code for executable programs by appending a %00 (null byte) to the request.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1142

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010712 ArGoSoft FTP Server 1.2.2.2 Weak password encryption
Reference: URL:http://www.securityfocus.com/archive/1/196968
Reference: BID:3029
Reference: URL:http://www.securityfocus.com/bid/3029
Reference: XF:argosoft-ftp-weak-encryption(6848)
Reference: URL:http://www.iss.net/security_center/static/6848.php

Description:
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the password file to gain privileges.

Votes:

   ACCEPT(2) Baker, Frech
   NOOP(7) Wall, Foat, Cole, Armstrong, Green, Christey, Ziese
Voter Comments:
 Christey> In an e-mail response, the vendor stated that they were
   not a crypto expert and were using their own home-grown
   crypto.
 CHANGE> [Baker changed vote from REVIEWING to ACCEPT]
 Baker> I received an email from Artchil Gogava, of Argosoft, author
   of the program in question.  I think this is sufficient verification
   that the problem is probably as identified.  He states he is not an
   encryption expert, and that he invented his own encryption mechanism
   for this.  Need I say more?
   
   >>>EMAIL<<<
   \/\/\/\/\/
   Subject:  Re: Encryption in ArgoSoft FTP Server
   Date:     Thu, 9 May 2002 15:14:29 -0400
   From:     "Artchil Gogava" <archie@argosoft.com>
   To:       "David Baker" <bakerd@mitre.org>
   References:      1
   
   Hello David,
   
   lnk problem, described in the document, has been fixed ages ago, and it does
   not present in 1.2.2.2.  As of password encryption.  I am not an encryption
   expert.  I am using a method invented by myself, and I am sure that whatever
   I do, someone, who has spare time to play around with it, will find the
   method to decrypt it.
   
   Archie


CAN-2001-1143

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010711 IBM Windows DB2 DoS
Reference: URL:http://www.securityfocus.com/archive/1/196140
Reference: BID:3010
Reference: URL:http://www.securityfocus.com/bid/3010
Reference: XF:ibm-db2-ccs-dos(6832)
Reference: URL:http://www.iss.net/security_center/static/6832.php
Reference: XF:ibm-db2-jds-dos(6833)
Reference: URL:http://www.iss.net/security_center/static/6833.php

Description:
IBM DB2 7.0 allows a remote attacker to cause a denial of service (crash) via a single byte to (1) db2ccs.exe on port 6790, or (2) db2jds.exe on port 6789.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Green
   REVIEWING(1) Ziese
Voter Comments:
 Ziese> HAS ANYONE BEEN ABLE TO REPRODUCE THIS?


CAN-2001-1148

Phase: Proposed (20020315)
Reference: VULN-DEV:20010613 SCO atcronsh auditsh termsh overflows
Reference: URL:http://www.securityfocus.com/archive/82/191216
Reference: CALDERA:CSSA-2001-SCO.25
Reference: URL:http://www.securityfocus.com/archive/1/219966

Description:
Buffer overflows in programs used by scoadmin and sysadmsh in SCO OpenServer 5.0.6a and earlier allows local users to gain privileges via a long TERM environment variable to (1) atcronsh, (2) auditsh, (3) authsh, (4) backupsh, (5) lpsh, (6) sysadm.menu, or (7) termsh.

Votes:

   ACCEPT(4) Cole, Armstrong, Green, Baker
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Ziese
Voter Comments:
 Frech> XF:openserver-scoadmin-sysadm-bo(7281)


CAN-2001-1150

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010822 [SNS Advisory No.38] Trend Micro Virus Buster (Ver.3.5x) Remote
Reference: URL:http://www.securityfocus.com/archive/1/209375
Reference: BUGTRAQ:20010824 [SNS Advisory No.40] TrendMicro OfficeScan Corp Edition ver.3.54 Remote read file of IUSER authority Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/210087
Reference: BID:3216
Reference: URL:http://www.securityfocus.com/bid/3216
Reference: XF:officescan-iuser-read-files(7014)
Reference: URL:http://www.iss.net/security_center/static/7014.php

Description:
Vulnerability in cgiWebupdate.exe in Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.5.2 through 3.5.4 allows remote attackers to read arbitrary files.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1151

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011015 [SNS Advisory No.44] Trend Micro OfficeScan Corporate Edition(Virus Buster Corporate Edition)
Reference: URL:http://www.securityfocus.com/archive/1/220666
Reference: MISC:http://www.trendmicro.co.jp/esolution/solutionDetail.asp?solutionID=318
Reference: XF:officescan-config-file-access(7286)
Reference: URL:http://xforce.iss.net/static/7286.php

Description:
Trend Micro OfficeScan Corporate Edition (aka Virus Buster) 3.53 allows remote attackers to access sensitive information from the hotdownload directory without authentication, such as the ofcscan.ini configuration file, which contains a weakly encrypted password.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1152

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010905 Various problems in Baltimore WebSweeper URL filtering
Reference: URL:http://www.securityfocus.com/archive/1/212283
Reference: MISC:http://www.mimesweeper.com/support/technotes/notes/1043.asp
Reference: BID:3296
Reference: URL:http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3296

Description:
Baltimore Technologies WEBsweeper 4.02, when used to manage URL blacklists, allows remote attackers to bypass blacklist restrictions and connect to unauthorized web servers by modifying the requested URL, including (1) a // (double slash), (2) a /SUBDIR/.. where the desired file is in the parentdir, (3) a /./, or (4) URL-encoded characters.

Votes:

   ACCEPT(2) Foat, Baker
   MODIFY(1) Frech
   NOOP(4) Wall, Cole, Armstrong, Green
   REJECT(1) Ziese
Voter Comments:
 Ziese> ACCEPT REASON: Rejection logic makes sense, products have to be used as
   intended.  Misuse is not a security vulnerability per se.
 Frech> XF:content-slash-bypass-filter(6816)
 Baker> I would say that this is a vulnerability, since their website
   touts URL filtering as a feature of the product.  If the product has to
   filter URL's then the product needs to be able to filter URL's properly,
   or the product fails.
   Here is the list of features, quoted from their product page for
   web sweeper:
   
   "Key Features
   Policy based web security implementation for information posted to and downloaded from the web
   Protects against unauthorized users accessing the web utilizing user authentication
   Provides URL filtering blocking stopping inappropriate site access
   Protects against loss of confidential information, viruses, portable code, and inappropriate content entering and
   leaving via web based e-mail accounts such as hotmail and Yahoo
   Auditing and reporting on individual and group web traffic
   Customizable "Block" and "Progress Message" pages "


CAN-2001-1154

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010830 Possible Denial of Service with PHP and Cyrus IMAP on BSDi 4.2
Reference: URL:http://www.securityfocus.com/archive/1/211056
Reference: BID:3260
Reference: URL:http://www.securityfocus.com/bid/3260
Reference: XF:cyrus-imap-php-dos(7053)
Reference: URL:http://xforce.iss.net/static/7053.php

Description:
Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1156

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011008 [ASGUARD-LABS] TYPSoft FTP Server v0.95 STOR/RETR Denial of Service Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/219167
Reference: CONFIRM:http://membres.lycos.fr/typsoft/eng/history.html
Reference: BID:3409
Reference: URL:http://www.securityfocus.com/bid/3409
Reference: XF:typsoft-ftp-retr-stor-dos(7247)
Reference: URL:http://www.iss.net/security_center/static/7247.php

Description:
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1) STOR or (2) RETR.

Votes:

   ACCEPT(6) Cole, Armstrong, Green, Baker, Frech, Ziese
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> http://membres.lycos.fr/typsoft/eng/history.html currently
   shows as 404.
   New page is
   http://www.typsoft.com/history.php?prog=ftp&PHPSESSID=3c2ef43838699c79
   efab517f60af5349


CAN-2001-1157

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010812 Various problems in Baltimore's WEBSweeper Script filter ing
Reference: URL:http://www.securityfocus.com/archive/1/203821
Reference: BID:3172
Reference: URL:http://www.securityfocus.com/bid/3172
Reference: BID:3173
Reference: URL:http://www.securityfocus.com/bid/3173

Description:
Baltimore Technologies WEBsweeper 4.0 and 4.02 does not properly filter Javascript from HTML pages, which could allow remote attackers to bypass the filtering via (1) an extra leading < and one or more characters before the SCRIPT tag, or (2) tags using Unicode.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Frech> XF:content-script-bypass-filtering(6580)
   XF:content-unicode-bypass-script(6980)


CAN-2001-1159

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010702 (SRADV00010) Remote command execution vulnerabilities in SquirrelMail
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0029.html
Reference: MISC:http://www.squirrelmail.org/changelog.php
Reference: BID:2968
Reference: URL:http://www.securityfocus.com/bid/2968
Reference: XF:squirrelmail-loadprefs-execute-code(6775)
Reference: URL:http://www.iss.net/security_center/static/6775.php

Description:
load_prefs.php and supporting include files in SquirrelMail 1.0.4 and earlier do not properly initialize certain PHP variables, which allows remote attackers to (1) view sensitive files via the config_php and data_dir options, and (2) execute arbitrary code by using options_order.php to upload a message that could be interpreted as PHP.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
   REVIEWING(1) Baker

CAN-2001-1163

Phase: Proposed (20020315)
Reference: BID:2885
Reference: URL:http://www.securityfocus.com/bid/2885

Description:
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT argument to port 6500.

Votes:

   MODIFY(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Green, Ziese
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:netsql-connect-bo(11231)


CAN-2001-1164

Phase: Proposed (20020315)
Reference: CALDERA:CSSA-2001-SCO.4
Reference: URL:ftp://stage.caldera.com/pub/security/unixware/CSSA-2001-SCO.4/CSSA-2001-SCO.4.txt

Description:
Buffer overflow in uucp utilities in UnixWare 7 allows local users to execute arbitrary code via long command line arguments to (1) uucp, (2) uux, (3) bnuconvert, (4) uucico, (5) uuxcmd, or (6) uuxqt.

Votes:

   ACCEPT(5) Cole, Armstrong, Green, Baker, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:unixware-uucp-bo(6762)
   XF:unixware-uucp-uux-bo(6763)
   XF:unixware-uucp-bnuconvert-bo(6764)
   XF:unixware-uucp-uucico-bo(6765)
   XF:unixware-uucp-uuxcmd-bo(6766)
   XF:unixware-uucp-uuxqt-bo(6767)


CAN-2001-1165

Phase: Proposed (20020315)
Reference: MISC:http://www.securemac.com/fileguard.php#disengage
Reference: XF:fileguard-weak-password-encryption(7018)
Reference: URL:http://www.iss.net/security_center/static/7018.php
Reference: BID:3213
Reference: URL:http://www.securityfocus.com/bid/3213

Description:
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain privileges by decrypting the information, e.g., with the Disengage tool.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Green, Ziese

CAN-2001-1167

Phase: Proposed (20020315)
Reference: HP:HPSBUX0108-165
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q3/0048.html

Description:
Vulnerability in /opt/prm/bin of HP Process Resource Manager (PRM) C.01.08.2 and earlier allows local users to gain root privileges by altering libraries or environment variables.

Votes:

   ACCEPT(3) Cole, Green, Baker
   NOOP(4) Wall, Foat, Armstrong, Ziese
   REJECT(2) Christey, Frech
Voter Comments:
 Frech> DUPE:CAN-2001-0976
   References and descriptions overlap. Currently assigned to
   XF:hp-prm-privilege-elevation(7050).
 Christey> Agreed, it's a dupe.  CAN-2001-0976 will be preferred, since
   it's been public longer.


CAN-2001-1168

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010829 eRisk Security Advisory: PhpMyExplorer vulnerable to directory traversal.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0408.html
Reference: BUGTRAQ:20010830 Re: eRisk Security Advisory: PhpMyExplorer vulnerable to directory traversal.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0418.html

Description:
Directory traversal vulnerability in index.php in PhpMyExplorer before 1.2.1 allows remote attackers to read arbitrary files via a ..%2F (modified dot dot) in the chemin parameter.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
Voter Comments:
 Frech> XF:phpmyexplorer-dot-directory-traversal(7049)


CAN-2001-1169

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010902 S/Key keyinit(1) authentication (lack thereof) + sudo(1)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0441.html

Description:
keyinit in S/Key does not require authentication to initialize a one-time password sequence, which allows an attacker who has gained privileges to a user account to create new one-time passwords for use in other activities that may use S/Key authentication, such as sudo.

Votes:

   ACCEPT(1) Green
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
   REVIEWING(1) Frech

CAN-2001-1170

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010929 Vulnerability in Amtote International homebet self service wagering system.
Reference: URL:http://www.securityfocus.com/cgi-bin/archive.pl?id=1&mid=217373&start=2001-09-27&end=2001-10-03
Reference: BID:3370
Reference: URL:http://www.securityfocus.com/bid/3370
Reference: XF:homebet-view-logfile(7186)
Reference: URL:http://xforce.iss.net/static/7186.php

Description:
AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote attackers to steal account and PIN numbers.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese

CAN-2001-1171

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010907 Bug in compile portion for older versions of CheckPoint Firewalls
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0046.html

Description:
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.

Votes:

   ACCEPT(1) Green
   NOOP(5) Wall, Foat, Cole, Armstrong, Ziese
   REJECT(2) Christey, Frech
Voter Comments:
 Frech> Both candidates assigned to XF:fw1-tmp-file-symlink(7094);
   CAN-2001-1171 has subset of references in CAN-201-1102.
 Christey> Agreed, it's a dupe.  CAN-2001-1102 will be preferred, since
   it has more complete references.


CAN-2001-1173

Phase: Proposed (20020315)
Reference: CONFIRM:ftp://innominate.org/oku/masqmail/ChangeLog-stable

Description:
Vulnerability in MasqMail before 0.1.15 allows local users to gain privileges via piped aliases.

Votes:

   ACCEPT(5) Cole, Armstrong, Green, Baker, Ziese
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Christey> VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
   URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:masqmail-gain-privileges(8717)


CAN-2001-1178

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010711 suid xman 3.1.6 overflows
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0234.html
Reference: BID:3030
Reference: URL:http://www.securityfocus.com/bid/3030
Reference: XF:xfree86-xman-manpath-bo(6853)
Reference: URL:http://xforce.iss.net/static/6853.php

Description:
Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Green, Ziese
   REVIEWING(1) Baker

CAN-2001-1179

Phase: Proposed (20020315)
Reference: BUGTRAQ:20010717 xman (suid) exploit, made easier.
Reference: URL:http://www.securityfocus.com/archive/1/197498

Description:
xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.

Votes:

   MODIFY(1) Frech
   NOOP(6) Wall, Foat, Cole, Armstrong, Green, Ziese
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:xfree86-xman-manpath-privileges(8716)


CAN-2001-1181

Phase: Proposed (20020315)
Reference: HP:HPSBUX0107-159
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q3/0013.html
Reference: CIAC:L-115
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-115.shtml
Reference: XF:hpux-dlkm-gain-privileges(6861)
Reference: URL:http://xforce.iss.net/static/6861.php

Description:
Dynamically Loadable Kernel Module (dlkm) static kernel symbol table in HP-UX 11.11 is not properly configured, which allows local users to gain privileges.

Votes:

   ACCEPT(6) Cole, Armstrong, Green, Baker, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-1182

Phase: Proposed (20020315)
Reference: HP:HPSBUX0107-160
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q3/0014.html

Description:
Vulnerability in login in HP-UX 11.00, 11.11, and 10.20 allows restricted shell users to bypass certain security checks and gain privileges.

Votes:

   ACCEPT(5) Cole, Armstrong, Green, Baker, Ziese
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:hpux-login-unauthorized-access(6860)
 Christey> CIAC:L-114
   URL:http://ciac.llnl.gov/ciac/bulletins/l-114.shtml
   BID:3068
   URL:http://online.securityfocus.com/bid/3068
   
   This would appear to be a dupe of CAN-2001-0797, but the HP advisory
   from CAN-2001-0797 is too vague to be certain.  As quoted in
   the CERT advisory for CAN-2001-0797, HP says:
   "HP-UX does have a benign buffer overflow... [which] has been
   fixed by HP."  HP:HPSBUX0107-160 (CAN-2001-1182) states that
   "The login(1) command allows restricted shell users to
   circumvent security checks" which could be interpreted as
   meaning that HP has found a slightly less-than-benign aspect
   of the overflow, but since (a) the advisory says nothing about
   overflows and (b) the advisory does not include any
   cross-references, it cannot be clear.  There is a difference
   in the release dates as well, however, since the HP advisory
   was released in July 2001 and this CAN was publicized in
   December 2001, which may be sufficient evidence that the
   problems are different.
   
   This probably is not the same issue in login as CAN-2001-0978,
   since different patches are referenced in that CAN.
   
   There is insufficient information to know whether this is the
   same issue as CVE-2001-0094 (kerberos library issues that
   affect kerberized login).


CAN-2001-1184

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011208 Winsock RSHD/NT 2.20.00 CPU overusage when invalid data is send
Reference: URL:http://www.securityfocus.com/archive/1/244580
Reference: BUGTRAQ:20011213 WRSHDNT 2.21.00 CPU overusage
Reference: URL:http://online.securityfocus.com/archive/1/245405
Reference: CONFIRM:http://www.denicomp.com/rshdnt.htm
Reference: XF:winsock-rshdnt-error-dos(7694)
Reference: URL:http://www.iss.net/security_center/static/7694.php
Reference: BID:3659
Reference: URL:http://www.securityfocus.com/bid/3659

Description:
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU consumption) via (1) in 2.20.00 and earlier, an invalid port number such as a negative number, which causes a connection attempt to that port and all ports below 1024, and (2) in 2.21.00, a port number of 1024.

Votes:

   ACCEPT(4) Cole, Green, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-1186

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011211 Microsoft IIS/5 bogus Content-length bug.
Reference: URL:http://www.securityfocus.com/archive/1/244892
Reference: BUGTRAQ:20011211 Microsoft IIS/5 bogus Content-length bug Memory attack
Reference: URL:http://online.securityfocus.com/archive/1/244931
Reference: BUGTRAQ:20011212 Microsoft IIS/5.0 Content-Length DoS (proved)
Reference: URL:http://online.securityfocus.com/archive/1/245100
Reference: BID:3667
Reference: URL:http://www.securityfocus.com/bid/3667
Reference: XF:iis-false-content-length-dos(7691)
Reference: URL:http://www.iss.net/security_center/static/7691.php

Description:
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(2) Foat, Ziese
   REVIEWING(1) Wall

CAN-2001-1187

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011211 CSVForm (Perl CGI) Remote Execution Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/244908
Reference: BID:3668
Reference: URL:http://online.securityfocus.com/bid/3668
Reference: XF:csvform-cgi-execute-commands(7692)
Reference: URL:http://www.iss.net/security_center/static/7692.php

Description:
csvform.pl 0.1 allows remote attackers to execute arbitrary commands via metacharacters in the file parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1188

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011211 SPAMMERS DELIGHT: as feeble as feeble can be
Reference: URL:http://www.securityfocus.com/archive/1/244909
Reference: BID:3669
Reference: URL:http://www.securityfocus.com/bid/3669

Description:
mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote servers by modifying the sendto, email, server, subject, and resulturl hidden form fields.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
Voter Comments:
 Frech> XF:mailto-form-field-modify(9119)


CAN-2001-1189

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011213 IBM WebSphere on UNIX security alert !
Reference: URL:http://www.securityfocus.com/archive/1/245324
Reference: BID:3682
Reference: URL:http://www.securityfocus.com/bid/3682
Reference: XF:websphere-java-plaintext-passwords(7698)
Reference: URL:http://www.iss.net/security_center/static/7698.php

Description:
IBM Websphere Application Server 3.5.3 and earlier stores a password in cleartext in the sas.server.props file, which allows local users to obtain the passwords via a JSP script.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1190

Phase: Proposed (20020315)
Reference: MANDRAKE:MDKSA-2001:091
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-091.php3
Reference: BID:3683
Reference: URL:http://www.securityfocus.com/bid/3683
Reference: XF:linux-passwd-weak-encryption(7706)
Reference: URL:http://www.iss.net/security_center/static/7706.php

Description:
The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended.

Votes:

   ACCEPT(4) Wall, Cole, Green, Frech
   NOOP(1) Foat
   REJECT(1) Ziese
Voter Comments:
 Ziese> This candidate should be explicitly defined.


CAN-2001-1191

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011211 Webseal 3.8
Reference: URL:http://www.securityfocus.com/archive/1/245283
Reference: BID:3685
Reference: URL:http://www.securityfocus.com/bid/3685

Description:
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Christey, Ziese
Voter Comments:
 Frech> XF:tivoli-webseal-dos(7716)
   http://online.securityfocus.com/archive/1/268124
 Christey> BUGTRAQ:20020417 IBM Security Advisory: IBM Tivoli Policy Director WebSEAL
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0223.html
   
   The vendor says that "there is no denial of service
   vulnerability" but goes on to describe "a defect related to
   the use of SSL junctions between the WebSEAL component and Web
   Servers. This defect can cause the WebSEAL component to fail if SSL
   junctions are being used, and certain URLs are then passed across
   these junctions."  This still sounds like a DoS to me, albeit
   one that might not appear in all configurations.
   
   Fix capitalization: "WebSEAL"


CAN-2001-1192

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011213 Kikkert Security Advisory: Potentially serious security flaw in Citrix Client
Reference: URL:http://www.securityfocus.com/archive/1/245342
Reference: BID:3688
Reference: URL:http://www.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3688

Description:
Citrix Independent Computing Architecture (ICA) Client for Windows 6.1 allows remote malicious web sites to execute arbitrary code via a.ICA file, which is downloaded and automatically executed by the client.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
Voter Comments:
 Frech> XF:citrix-ica-gain-root(7697)


CAN-2001-1194

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011214 Zyxel Prestige 681 and 1600 (possibly other?) remote DoS
Reference: URL:http://www.securityfocus.com/archive/1/245498
Reference: BUGTRAQ:20011218 Re: Zyxel Prestige 681 and 1600 (possibly other?) remote DoS
Reference: URL:http://www.securityfocus.com/archive/1/246182
Reference: BID:3695
Reference: URL:http://www.securityfocus.com/bid/3695

Description:
Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with (1) an IP length less than actual packet size, or (2) fragmented packets whose size exceeds 64 kilobytes after reassembly.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   RECAST(1) Christey
Voter Comments:
 Christey> This should probably be SPLIT.  The 2 vulnerabilities, while
   both related to malformed input, are clearly different types
   of malformed input.
   XF:prestige-dsl-frag-packet-dos(7723)
   URL:http://xforce.iss.net/static/7723.php
   XF:prestige-dsl-frag-packet-dos(7723)
   URL:http://xforce.iss.net/static/7723.php
   BID:3711
   URL:http://www.securityfocus.com/bid/3711
 Frech> XF:prestige-dsl-packet-length-dos(7704)


CAN-2001-1195

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011215 Novell Groupwise servlet gateway default username and password
Reference: URL:http://www.securityfocus.com/archive/1/245871
Reference: CONFIRM:http://support.novell.com/cgi-bin/search/searchtid.cgi?/10067329.htm
Reference: XF:groupwise-servlet-manager-default(7701)
Reference: URL:http://www.iss.net/security_center/static/7701.php
Reference: BID:3697
Reference: URL:http://online.securityfocus.com/bid/3697

Description:
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager, which allows remote attackers to gain privileges.

Votes:

   ACCEPT(4) Cole, Green, Frech, Ziese
   NOOP(2) Wall, Foat

CAN-2001-1196

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011217 webmin 0.91 ../.. problem
Reference: URL:http://www.securityfocus.com/archive/1/245980
Reference: BUGTRAQ:20011218 Re: webmin 0.91 ../.. problem
Reference: URL:http://marc.theaimsgroup.com/?l=webmin-l&m=100865390306103&w=2
Reference: BID:3698
Reference: URL:http://www.securityfocus.com/bid/3698
Reference: XF:webmin-dot-directory-traversal(7711)
Reference: URL:http://www.iss.net/security_center/static/7711.php

Description:
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a '..' (dot dot) in the argument.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Green, Ziese
Voter Comments:
 Green> SINCE ROOT PRIVILEGES ARE REQUIRED TO USE THE TOOL, WHAT FURTHER 
   ESCALATION OF PRIVILEGE CAN OBTAINED?


CAN-2001-1197

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011214 klprfax_filter symlink vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/245500
Reference: BUGTRAQ:20011214 Re: klprfax_filter symlink vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100837486611350&w=2
Reference: BID:3694
Reference: URL:http://www.securityfocus.com/bid/3694

Description:
klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
Voter Comments:
 Frech> XF:kdeutils-klprfax-symlink(7700)


CAN-2001-1198

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011215 HP-UX setuid rlpdaemon induced to make illicit file writes
Reference: URL:http://www.securityfocus.com/archive/1/245690
Reference: BID:3701
Reference: URL:http://www.securityfocus.com/bid/3701
Reference: XF:hp-rlpd-create-log(7729)
Reference: URL:http://www.iss.net/security_center/static/7729.php

Description:
RLPDaemon in HP-UX 10.20 and 11.0 allows local users to overwrite arbitrary files and gain privileges by specifying the target file in the -L option.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1200

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011217 Hot keys permissions bypass under XP
Reference: URL:http://www.securityfocus.com/archive/1/246014
Reference: BID:3703
Reference: URL:http://www.securityfocus.com/bid/3703
Reference: XF:winxp-hotkey-execute-programs(7713)
Reference: URL:http://www.iss.net/security_center/static/7713.php

Description:
Microsoft Windows XP allows local users to bypass a locked screen and run certain programs that are associated with Hot Keys.

Votes:

   ACCEPT(3) Foat, Green, Frech
   NOOP(2) Cole, Ziese
   REVIEWING(1) Wall

CAN-2001-1202

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011228 DeleGate Cross Site Scripting Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100956050432351&w=2
Reference: BID:3749
Reference: URL:http://online.securityfocus.com/bid/3749
Reference: XF:delegate-proxy-css(7745)
Reference: URL:http://www.iss.net/security_center/static/7745.php

Description:
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Green, Ziese
Voter Comments:
 Green> Change history at the DeleGate is not specific enough to determine if 
   the java scripting problem has been addressed.  


CAN-2001-1204

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011228 PHP Rocket Add-in (file transversal vulnerability)
Reference: URL:http://www.securityfocus.com/archive/1/247559
Reference: BID:3751
Reference: URL:http://www.securityfocus.com/bid/3751

Description:
Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Green, Ziese
Voter Comments:
 Frech> XF:phprocket-directory-traversal(7749)


CAN-2001-1205

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011230 lastlines.cgi path traversal and command execution vulns
Reference: URL:http://www.securityfocus.com/archive/1/247710
Reference: BID:3754
Reference: URL:http://www.securityfocus.com/bid/3754

Description:
Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via a '..' (dot dot) attack.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Green, Ziese
Voter Comments:
 Green> WHEN AND IF IT IS SPLIT..........
 Frech> XF:lastlines-cgi-directory-traversal(7753)


CAN-2001-1206

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011230 lastlines.cgi path traversal and command execution vulns
Reference: URL:http://www.securityfocus.com/archive/1/247710
Reference: BID:3755
Reference: URL:http://www.securityfocus.com/bid/3755

Description:
Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands by failing to validate shell meta characters.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Green, Ziese
Voter Comments:
 Green> WHEN AND IF IT IS SPLIT..........
 Frech> XF:lastlines-cgi-command-execution(7754)


CAN-2001-1207

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011230 DayDream BBS buffer overflows
Reference: URL:http://www.securityfocus.com/archive/1/247708
Reference: CONFIRM:http://www.cs.uku.fi/~hlyytine/daydream-2.11/ChangeLog
Reference: BID:3757
Reference: URL:http://www.securityfocus.com/bid/3757
Reference: XF:daydream-bbs-control-code-bo(7755)
Reference: URL:http://www.iss.net/security_center/static/7755.php

Description:
Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.

Votes:

   ACCEPT(4) Cole, Green, Frech, Ziese
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> Corrected link to DayDream BBS ChangeLog:
   http://daydream.iwn.fi/history.html


CAN-2001-1208

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011231 Daydream BBS Format strings issue.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100977623710528&w=2

Description:
Format string vulnerability in DayDream BBS allows remote attackers to execute arbitrary code via format string specifiers in a file containing a ~#RA control code.

Votes:

   MODIFY(1) Frech
   NOOP(5) Wall, Foat, Cole, Green, Ziese
Voter Comments:
 Frech> XF:daydream-bbs-format-string(9120)


CAN-2001-1209

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011231 blackshell2: zml.cgi remote exploit
Reference: URL:http://www.securityfocus.com/archive/1/247742
Reference: VULNWATCH:20011231 [VulnWatch] blackshell2: zml.cgi remote exploit
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0086.html
Reference: MISC:http://www.jero.cc/zml/zml.html
Reference: BID:3759
Reference: URL:http://www.securityfocus.com/bid/3759
Reference: XF:zml-cgi-directory-traversal(7751)
Reference: URL:http://www.iss.net/security_center/static/7751.php

Description:
Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese
   REVIEWING(1) Christey
Voter Comments:
 Christey> INCLUSION: The author of the zml.cgi program says that the vulnerable
   version is not his, and that zml.cgi does not take a file parameter.
   If this is an adaptation of that zml.cgi program, and the adaptation
   is not generally available, then it should not be included in CVE.
   Almost all of the hits on Google for "zml.cgi" are references to the
   reported vulnerability, and a search for "zml" doesn't turn up any
   obvious web pages, so it cannot be determined if there is another
   product that happens to use a script named zml.cgi.


CAN-2001-1210

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011230 Possible security problem with Cisco ubr900 series routers
Reference: URL:http://www.securityfocus.com/archive/1/247718
Reference: BID:3758
Reference: URL:http://online.securityfocus.com/bid/3758
Reference: XF:cisco-docsis-default-strings(7806)
Reference: URL:http://www.iss.net/security_center/static/7806.php

Description:
Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Ziese

CAN-2001-1211

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011231 IMail Web Service User Aliases / Mailing Lists Admin Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/247786
Reference: MISC:http://support.ipswitch.com/kb/IM-20020301-DM02.htm
Reference: MISC:http://support.ipswitch.com/kb/IM-20011219-DM01.htm
Reference: BID:3766
Reference: URL:http://www.securityfocus.com/bid/3766
Reference: XF:imail-admin-domain-change(7752)
Reference: URL:http://www.iss.net/security_center/static/7752.php

Description:
Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1212

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011218 Aktivate Shopping System Cross Site Scripting Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/246274
Reference: XF:aktivate-shopping-css(7717)
Reference: URL:http://www.iss.net/security_center/static/7717.php
Reference: BID:3714
Reference: URL:http://online.securityfocus.com/bid/3714

Description:
Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascript via the desc parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1213

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011218 FTPXQ default install read/write capabilities
Reference: URL:http://www.securityfocus.com/archive/1/246285
Reference: XF:ftpxq-default-permissions(7715)
Reference: URL:http://www.iss.net/security_center/static/7715.php
Reference: BID:3716
Reference: URL:http://online.securityfocus.com/bid/3716

Description:
The default configuration of DataWizard FtpXQ 2.0 and 2.1 includes a default username and password, which allows remote attackers to read and write arbitrary files in the root folder.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1214

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011215 *ALERT* "Unix Manual" PHP-Script allows arbitrary code execution
Reference: URL:http://www.securityfocus.com/archive/1/247332
Reference: XF:unixmanual-php-command-execution(7719)
Reference: URL:http://www.iss.net/security_center/static/7719.php
Reference: BID:3718
Reference: URL:http://online.securityfocus.com/bid/3718

Description:
manual.php in Marcus S. Xenakis Unix Manual 1.0 allows remote attackers to execute arbitrary code via a URL that contains shell metacharacters.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Wall, Foat, Cole, Green, Christey, Ziese
Voter Comments:
 Christey> I can't find anything about "Marcus S. Xenakis" on the web at
   all, except for vulnerability reports.
 CHANGE> [Green changed vote from ACCEPT to NOOP]
 Green> The more I looked again today the more circular the references
   were getting.  And there's no single pointer to a Marcus
   Xenakis site.  So, I'll have to modify the vote to a NOOP.
 Christey> A similar issue is in CAN-2002-0434, but CAN-2002-0434 is for
   manual.php.


CAN-2001-1216

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011221 Buffer Overflow in Oracle 9iAS (#NISR20122001)
Reference: URL:http://www.securityfocus.com/archive/1/246663
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/modplsql.pdf
Reference: CERT-VN:VU#500203
Reference: URL:http://www.kb.cert.org/vuls/id/500203
Reference: XF:oracle-appserver-modplsql-bo(7727)
Reference: URL:http://www.iss.net/security_center/static/7727.php
Reference: BID:3726
Reference: URL:http://www.securityfocus.com/bid/3726

Description:
Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.

Votes:

   ACCEPT(6) Wall, Foat, Cole, Green, Frech, Ziese
   NOOP(1) Christey
Voter Comments:
 Christey> CERT:CA-2002-08


CAN-2001-1217

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011221 Buffer Overflow in Oracle 9iAS (#NISR20122001)
Reference: URL:http://www.securityfocus.com/archive/1/246663
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/modplsql.pdf
Reference: XF:oracle-appserver-modplsql-traversal(7728)
Reference: URL:http://www.iss.net/security_center/static/7728.php
Reference: BID:3727
Reference: URL:http://www.securityfocus.com/bid/3727
Reference: CERT-VN:VU#758483
Reference: URL:http://www.kb.cert.org/vuls/id/758483

Description:
Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

Votes:

   ACCEPT(6) Wall, Foat, Cole, Green, Frech, Ziese
   NOOP(1) Christey
Voter Comments:
 Christey> CERT:CA-2002-08


CAN-2001-1218

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011220 E5 (SP1) crash the X server on Solaris2.6 chinese edition
Reference: URL:http://www.securityfocus.com/archive/1/246611
Reference: BID:3729
Reference: URL:http://online.securityfocus.com/bid/3729

Description:
Microsoft Internet Explorer for Unix 5.0SP1 allows local users to possibly cause a denial of service (crash) in CDE or the X server on Solaris 2.6 by rapidly scrolling Chinese characters or maximizing the window.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Ziese
Voter Comments:
 Green> From scanning MS-TechNet there are sufficient similar conundrums 
   between Solaris and IE to assume that this rings true
 Frech> XF:ie-unix-chinchar-dos(9121)


CAN-2001-1219

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011220 MSIE DoS Using javascript
Reference: URL:http://www.securityfocus.com/archive/1/246649
Reference: BID:3730
Reference: URL:http://online.securityfocus.com/bid/3730

Description:
Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
   REJECT(1) Ziese
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:ie-javascript-selflocation-dos(9122)


CAN-2001-1220

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011221 D-Link DWL-1000AP can be compromised because of SNMP configuration
Reference: URL:http://www.securityfocus.com/archive/1/246849
Reference: BID:3735
Reference: URL:http://www.securityfocus.com/bid/3735
Reference: XF:dlink-ap-public-mib(7733)
Reference: URL:http://www.iss.net/security_center/static/7733.php

Description:
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1221

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011221 D-Link DWL-1000AP can be compromised because of SNMP configuration
Reference: URL:http://www.securityfocus.com/archive/1/246849
Reference: BID:3736
Reference: URL:http://www.securityfocus.com/bid/3736

Description:
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point uses a default SNMP community string of 'public' which allows remote attackers to gain sensitive information.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REJECT(1) Ziese
Voter Comments:
 Ziese> candidate?
 Frech> XF:nwn-ap-default-snmp-read(6559)


CAN-2001-1222

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011221 twlc advisory: plesk (psa) allows reading of .php files
Reference: URL:http://www.securityfocus.com/archive/1/246861
Reference: BID:3737
Reference: URL:http://www.securityfocus.com/bid/3737
Reference: XF:psa-php-reveal-source(7735)
Reference: URL:http://www.iss.net/security_center/static/7735.php

Description:
Plesk Server Administrator (PSA) 1.0 allows remote attackers to obtain PHP source code via an HTTP request containing the target's IP address and a valid account name for the domain.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1223

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011226 Phoenix Sistemi Security Advisory: ELSA Lancom 1100 Office Security Problems
Reference: URL:http://www.securityfocus.com/archive/1/247274
Reference: BID:3746
Reference: URL:http://www.securityfocus.com/bid/3746
Reference: XF:elsa-lancom-web-administration(7739)
Reference: URL:http://www.iss.net/security_center/static/7739.php

Description:
The web administration server for ELSA Lancom 1100 Office does not require authentication, which allows arbitrary remote attackers to gain administrative privileges by connecting to the server.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1224

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011223 GOBBLES CGI MARATHON #001
Reference: URL:http://www.securityfocus.com/archive/1/246994
Reference: BID:3739
Reference: URL:http://www.securityfocus.com/bid/3739
Reference: XF:adrotate-sql-execute-commands(7736)
Reference: URL:http://www.iss.net/security_center/static/7736.php

Description:
get_input in adrotate.pm for Les VanBrunt AdRotate Pro 2.0 allows remote attackers to modify the database and possibly execute arbitrary commands via a SQL code injection attack.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1225

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011226 msql DoS
Reference: URL:http://www.securityfocus.com/archive/1/247222
Reference: BID:3742
Reference: URL:http://www.securityfocus.com/bid/3742
Reference: XF:msql-char-array-dos(7746)
Reference: URL:http://www.iss.net/security_center/static/7746.php

Description:
Hughes Technology Mini SQL 2.0.10 through 2.0.12 allows local users to cause a denial of service by creating a very large array in a table, which causes miniSQL to crash when the table is queried.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Ziese

CAN-2001-1226

Phase: Proposed (20020315)
Reference: BUGTRAQ:20011225 GOBBLES CGI MARATHON #002
Reference: URL:http://www.securityfocus.com/archive/1/247126
Reference: BID:3741
Reference: URL:http://www.securityfocus.com/bid/3741
Reference: XF:adcycle-modify-sql-query(7762)
Reference: URL:http://www.iss.net/security_center/static/7762.php

Description:
AdCycle 1.17 and earlier allow remote attackers to modify SQL queries, which are not properly sanitized before being passed to the MySQL database.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Christey, Ziese
Voter Comments:
 Christey> CERT-VN:VU#282403
   URL:http://www.kb.cert.org/vuls/id/282403


CAN-2001-1228

Phase: Modified (20020817-01)
Reference: VULN-DEV:20011118 New bugs discovered!
Reference: VULN-DEV:20011120 New bugs, old bugs
Reference: VULN-DEV:20011119 Killing Thread (New bugs discovered!)
Reference: BUGTRAQ:20011230 gzip bug w/ patch..
Reference: URL:http://online.securityfocus.com/archive/1/247717
Reference: MANDRAKE:MDKSA-2002:011
Reference: DEBIAN:DSA-100
Reference: SGI:20020401-01-P
Reference: NETBSD:NetBSD-SA2002-002
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-002.txt.asc
Reference: BID:3712
Reference: URL:http://online.securityfocus.com/bid/3712
Reference: XF:gzip-long-filename-bo(7882)
Reference: URL:http://www.iss.net/security_center/static/7882.php

Description:
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.

Votes:

   ACCEPT(3) Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(3) Foat, Christey, Cox
Voter Comments:
 Christey> NETBSD:NetBSD-SA2002-002
   URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-002.txt.asc
 Frech> XF:gzip-long-filename-bo(7882)


CAN-2001-1229

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010312 Icecast / Libshout remote vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98438880622976&w=2
Reference: CONFIRM:http://www.xiph.org/archives/icecast/0074.html
Reference: CONECTIVA:CLA-2001:387
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000387
Reference: REDHAT:RHSA-2002:063
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-063.html

Description:
Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Christey> CALDERA:CSSA-2002-020.0
 Frech> XF:icecast-libshout-multiple-bo(9245)


CAN-2001-1230

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010313 More Icecast remote vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98455723123298&w=2
Reference: DEBIAN:DSA-089
Reference: URL:http://www.debian.org/security/2001/dsa-089
Reference: REDHAT:RHSA-2002:063
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-063.html

Description:
Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Christey> CALDERA:CSSA-2002-020.0
 Christey> CONECTIVA:CLSA-2001:387
 Frech> XF:icecast-multiple-bo(9246)


CAN-2001-1232

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010815 Groupwise Webaccess, NetWare web server, and Novell
Reference: URL:http://www.securityfocus.com/archive/1/204875
Reference: XF:netware-get-directory-listing(6988)
Reference: URL:http://xforce.iss.net/static/6988.php
Reference: BID:3188
Reference: URL:http://www.securityfocus.com/bid/3188

Description:
GroupWise WebAccess 5.5 with directory indexing enabled allows a remote attacker to view arbitrary directory contents via an HTTP request with a lowercase "get".

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1233

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010815 Groupwise Webaccess, NetWare web server, and Novell
Reference: URL:http://www.securityfocus.com/archive/1/204875
Reference: XF:netware-nds-information-leak(6987)
Reference: URL:http://xforce.iss.net/static/6987.php

Description:
Netware Enterprise Web Server 5.1 running GroupWise WebAccess 5.5 with Novell Directory Services (NDS) enabled allows remote attackers to enumerate user names, group names and other system information by accessing ndsobj.nlm.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1238

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010716 W2k: Unkillable Applications
Reference: URL:http://www.securityfocus.com/archive/1/197195
Reference: XF:win2k-taskmanager-unkillable-process(6919)
Reference: URL:http://xforce.iss.net/static/6919.php
Reference: BID:3033
Reference: URL:http://www.securityfocus.com/bid/3033

Description:
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(2) Foat, Cox
   REJECT(1) Baker
   REVIEWING(1) Wall
Voter Comments:
 Baker> I don't think this is really a vulnerability.  If I am not mistaken,
   those are "services" which have to be managed by the services control
   in windows 2K.  This keeps users from killing things the system has
   to have.  I don't think it is possible to kill another of other services
   in this manner either.  Try it on almost any W2K system, and there are any
   number of services that you cannot kill from the process tab, rather you
   must go to the services controller to stop the service.
   I vote to reject this, as this is not a vulnerability, since you would have
   to be administrator on the system to change one of these services to a trojan
   version anyway.


CAN-2001-1239

Phase: Proposed (20020502)
Reference: BID:2992
Reference: URL:http://online.securityfocus.com/bid/2992

Description:
PowerNet IX allows remote attackers to cause a denial of service via a port scan.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:powernet-ix-portscan-dos(9994)


CAN-2001-1241

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010717 multiple vulnerabilities in un-cgi
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0287.html
Reference: BUGTRAQ:20010718 Re: [Khamba Staring <purrcat@edoropolis.org>] multiple
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0349.html
Reference: CONFIRM:http://www.midwinter.com/~koreth/uncgi.html
Reference: CONFIRM:http://www.midwinter.com/~koreth/uncgi-changes.html
Reference: BID:3057
Reference: URL:http://online.securityfocus.com/bid/3057
Reference: XF:uncgi-unexecutable-cgi(6847)
Reference: URL:http://www.iss.net/security_center/static/6847.php

Description:
Un-CGI 1.9 and earlier does not verify that a CGI script has the execution bits set before executing it, which allows remote attackers to execute arbitrary commands by directing Un-CGI to a document that begins with "#!" and the desired program name.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1242

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010717 multiple vulnerabilities in un-cgi
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0287.html
Reference: BUGTRAQ:20010718 Re: [Khamba Staring <purrcat@edoropolis.org>] multiple vulnerabilities in un-cgi
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0349.html
Reference: CONFIRM:http://www.midwinter.com/~koreth/uncgi-changes.html
Reference: BID:3056
Reference: URL:http://online.securityfocus.com/bid/3056
Reference: XF:uncgi-dot-directory-traversal(6846)
Reference: URL:http://www.iss.net/security_center/static/6846.php

Description:
Directory traversal vulnerability in Un-CGI 1.9 and earlier allows remote attackers to execute arbitrary code via a .. (dot dot) in an HTML form.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1243

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010704 NERF Advisory #4: MS IIS local and remote DoS
Reference: URL:http://www.securityfocus.com/archive/1/194919
Reference: BID:2973
Reference: URL:http://www.securityfocus.com/bid/2973
Reference: XF:iis-device-asp-dos(6800)
Reference: URL:http://www.iss.net/security_center/static/6800.php

Description:
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial of service (crash) via (1) creating an ASP program that uses Scripting.FileSystemObject to open a file with an MS-DOS device name, or (2) remotely injecting the device name into ASP programs that internally use Scripting.FileSystemObject.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(2) Foat, Cox
   REVIEWING(1) Wall

CAN-2001-1244

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010708 Small TCP packets == very large overhead == DoS?
Reference: URL:http://www.securityfocus.com/archive/1/195457
Reference: BID:2997
Reference: URL:http://www.securityfocus.com/bid/2997
Reference: XF:tcp-mss-dos(6824)
Reference: URL:http://xforce.iss.net/static/6824.php

Description:
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume more server CPU to process.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1245

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010712 Re: Opera Browser Heap Overflow (Session Replay Attack)
Reference: URL:http://online.securityfocus.com/archive/1/196980
Reference: XF:opera-browser-header-bo(6838)
Reference: URL:http://www.iss.net/security_center/static/6838.php
Reference: BID:3012
Reference: URL:http://www.securityfocus.com/bid/3012

Description:
Opera 5.0 for Linux does not properly handle malformed HTTP headers, which allows remote attackers to cause a denial of service, possibly with a header whose value is the same as a MIME header name.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 CHANGE> [Green changed vote from REVIEWING to ACCEPT]


CAN-2001-1248

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010629 4 New vulns. vWebServer and SmallHTTP
Reference: URL:http://online.securityfocus.com/archive/1/194418
Reference: BID:2975
Reference: URL:http://online.securityfocus.com/bid/2975
Reference: XF:vwebserver-asp-reveal-source(6769)
Reference: URL:http://www.iss.net/security_center/static/6769.php

Description:
vWebServer 1.2.0 allows remote attackers to view arbitrary ASP scripts via a request for an ASP script that ends with a URL-encoded space character (%20).

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1249

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010629 4 New vulns. vWebServer and SmallHTTP
Reference: URL:http://online.securityfocus.com/archive/1/194418
Reference: BID:2978
Reference: URL:http://online.securityfocus.com/bid/2978

Description:
vWebServer 1.2.0 allows remote attackers to cause a denial of service via a URL that contains MS-DOS device names.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:vwebserver-device-dos(6770)


CAN-2001-1250

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010629 4 New vulns. vWebServer and SmallHTTP
Reference: URL:http://online.securityfocus.com/archive/1/194418
Reference: BID:2979
Reference: URL:http://online.securityfocus.com/bid/2979
Reference: XF:vwebserver-long-url-dos(6771)
Reference: URL:http://www.iss.net/security_center/static/6771.php

Description:
vWebServer 1.2.0 allows remote attackers to cause a denial of service (hang) via a small number of long URL requests, possibly due to a buffer overflow.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1253

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010927 Two problems with Alexis/InternetPBX from COM2001
Reference: URL:http://online.securityfocus.com/archive/1/217200
Reference: XF:alexis-http-plaintext-information(7205)
Reference: URL:http://www.iss.net/security_center/static/7205.php

Description:
Alexis 2.0 and 2.1 in COM2001 InternetPBX stores voicemail passwords in plain text in the com2001.ini file, which could allow local users to make long distance calls as other users.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1254

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010927 Two problems with Alexis/InternetPBX from COM2001
Reference: URL:http://online.securityfocus.com/archive/1/217200
Reference: BID:3373
Reference: URL:http://online.securityfocus.com/bid/3373

Description:
Web Access component for COM2001 Alexis 2.0 and 2.1 in InternetPBX sends username and voice mail passwords in the clear via a Java applet that sends the information to port 8888 of the server, which could allow remote attackers to steal the passwords via sniffing.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:alexis-http-plaintext-information(7205)


CAN-2001-1255

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011002 WinMySQLadmin 1.1 Store MySQL password in clear text
Reference: URL:http://online.securityfocus.com/archive/1/217848
Reference: BID:3381
Reference: URL:http://online.securityfocus.com/bid/3381
Reference: XF:winmysqladmin-password-plaintext(7206)
Reference: URL:http://www.iss.net/security_center/static/7206.php

Description:
WinMySQLadmin 1.1 stores the MySQL password in plain text in the my.ini file, which allows local users to obtain unathorized access the MySQL database.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Christey, Cox
Voter Comments:
 Christey> fix typos: 'unathorized'; "[TO] the database"


CAN-2001-1256

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010604 yet another sym link followers
Reference: URL:http://www.securityfocus.com/archive/1/188568
Reference: CERT-VN:VU#127435
Reference: URL:http://www.kb.cert.org/vuls/id/127435
Reference: CIAC:L-093
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-093.shtml
Reference: HP:HPSBUX0106-153
Reference: URL:http://online.securityfocus.com/advisories/3354
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/TJSL-4Z5Q92
Reference: XF:hpux-kmmodreg-symlink(6656)
Reference: URL:http://xforce.iss.net/static/6656.php
Reference: BID:2821
Reference: URL:http://www.securityfocus.com/bid/2821

Description:
kmmodreg in HP-UX 11.11, 11.04 and 11.00 allows local users to create arbitrary world-writeable files via a symlink attack on the (1) /tmp/.kmmodreg_lock and (2) /tmp/kmpath.tmp temporary files.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1257

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010721 IMP 2.2.6 (SECURITY) released
Reference: URL:http://online.securityfocus.com/archive/1/198495
Reference: CALDERA:CSSA-2001-027.0
Reference: URL:http://www.caldera.com/support/security/advisories/CSSA-2001-027.0.txt
Reference: DEBIAN:DSA-073
Reference: URL:http://www.debian.org/security/2001/dsa-073
Reference: CONFIRM:http://online.securityfocus.com/archive/1/198495
Reference: CONECTIVA:CLA-2001:410
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000410
Reference: BID:3082
Reference: URL:http://www.securityfocus.com/bid/3082
Reference: XF:imp-cross-site-scripting(6905)
Reference: URL:http://www.iss.net/security_center/static/6905.php

Description:
Cross-site scripting vulnerability in Horde Internet Messaging Program (IMP) before 2.2.6 and 1.2.6 allows remote attackers to execute arbitrary Javascript embedded in an email.

Votes:

   ACCEPT(4) Cole, Green, Frech, Cox
   NOOP(2) Wall, Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]


CAN-2001-1258

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010721 IMP 2.2.6 (SECURITY) released
Reference: URL:http://online.securityfocus.com/archive/1/198495
Reference: CALDERA:CSSA-2001-027.0
Reference: URL:http://www.caldera.com/support/security/advisories/CSSA-2001-027.0.txt
Reference: CONECTIVA:CLA-2001:410
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000410
Reference: CONFIRM:http://online.securityfocus.com/archive/1/198495
Reference: DEBIAN:DSA-073
Reference: URL:http://www.debian.org/security/2001/dsa-073
Reference: XF:imp-prefslang-gain-privileges(6906)
Reference: URL:http://www.iss.net/security_center/static/6906.php
Reference: BID:3083
Reference: URL:http://www.securityfocus.com/bid/3083

Description:
Horde Internet Messaging Program (IMP) before 2.2.6 allows local users to read IMP configuration files and steal the Horde database password by placing the prefs.lang file containing PHP code on the server.

Votes:

   ACCEPT(4) Cole, Green, Frech, Cox
   NOOP(2) Wall, Foat
Voter Comments:
 Cox> VERIFYING.
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]


CAN-2001-1259

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010807 Multiple vulnerabilities in Avaya Argent Office
Reference: URL:http://online.securityfocus.com/archive/1/202344
Reference: XF:argent-office-udp-dos(6953)
Reference: URL:http://www.iss.net/security_center/static/6953.php

Description:
Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no payload.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1260

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010807 Multiple vulnerabilities in Avaya Argent Office
Reference: URL:http://online.securityfocus.com/archive/1/202344
Reference: XF:argent-office-weak-encryption(6954)
Reference: URL:http://www.iss.net/security_center/static/6954.php

Description:
Avaya Argent Office uses weak encryption (trivial encoding) for passwords, which allows remote attackers to gain administrator privileges by sniffing and decrypting the sniffing the passwords during a system reboot.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Christey, Cox
Voter Comments:
 Christey> Remove extra "the sniffing" phrase.


CAN-2001-1261

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010807 Multiple vulnerabilities in Avaya Argent Office
Reference: URL:http://online.securityfocus.com/archive/1/202344
Reference: XF:argent-office-change-music(6956)
Reference: URL:http://www.iss.net/security_center/static/6956.php

Description:
Avaya Argent Office 2.1 may allow remote attackers to change hold music by spoofing a legitimate server's response to a TFTP broadcast and providing an alternate HoldMusic file.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1262

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010807 Multiple vulnerabilities in Avaya Argent Office
Reference: URL:http://online.securityfocus.com/archive/1/202344
Reference: XF:argent-office-community-string(6955)
Reference: URL:http://www.iss.net/security_center/static/6955.php

Description:
Avaya Argent Office 2.1 compares a user-provided SNMP community string with the correct string only up to the length of the user-provided string, which allows remote attackers to bypass authentication with a 0 length community string.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1263

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010606 advisory for Pragma Interaccess
Reference: URL:http://online.securityfocus.com/archive/1/189327
Reference: BID:2834
Reference: URL:http://online.securityfocus.com/bid/2834
Reference: XF:pragma-interaccess-dos(6658)
Reference: URL:http://xforce.iss.net/static/6658.php

Description:
telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large number of characters to port 23, possibly due to a buffer overflow.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1264

Phase: Proposed (20020502)
Reference: HP:HPSBUX0107-161
Reference: URL:http://www.securityfocus.com/advisories/3459
Reference: CIAC:L-119
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-119.shtml
Reference: CERT-VN:VU#420475
Reference: URL:http://www.kb.cert.org/vuls/id/420475
Reference: XF:hp-virtualvault-mkacct-privilege-elevation(6867)
Reference: URL:http://xforce.iss.net/static/6867.php
Reference: BID:3072
Reference: URL:http://www.securityfocus.com/bid/3072

Description:
Vulnerability in mkacct in HP-UX 11.04 running Virtualvault Operating System (VVOS) 4.0 and 4.5 allows attackers to elevate privileges.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1265

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010720 IBM TFTP Server for Java vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/198297
Reference: BID:3076
Reference: URL:http://www.securityfocus.com/bid/3076
Reference: XF:ibm-tftp-directory-traversal(6864)
Reference: URL:http://xforce.iss.net/static/6864.php

Description:
Directory traversal vulnerability in IBM alphaWorks Java TFTP server 1.21 allows remote attackers to conduct unauthorized operations on arbitrary files via a .. (dot dot) attack.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1267

Phase: Modified (20030318-01)
Reference: BUGTRAQ:20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers
Reference: URL:http://online.securityfocus.com/archive/1/196445
Reference: CONFIRM:ftp://alpha.gnu.org/gnu/tar/tar-1.13.25.tar.gz
Reference: MANDRAKE:MDKSA-2002:066
Reference: URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2002:066
Reference: REDHAT:RHSA-2002:096
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-096.html
Reference: CONECTIVA:CLA-2002:538
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538
Reference: HP:HPSBTL0209-068
Reference: URL:http://online.securityfocus.com/advisories/4514
Reference: XF:archive-extraction-directory-traversal(10224)
Reference: URL:http://www.iss.net/security_center/static/10224.php

Description:
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(2) Frech, Cox
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Christey> MANDRAKE:MDKSA-2002:066
 CHANGE> [Cox changed vote from REVIEWING to MODIFY]
 Cox> ADDREF: RHSA-2002:096
 Frech> XF:archive-extraction-directory-traversal(10224)
 Christey> MANDRAKE:MDKSA-2002:066
   URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2002:066
   CONECTIVA:CLA-2002:538
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538
   HP:HPSBTL0209-068
   URL:http://online.securityfocus.com/advisories/4514
   REDHAT:RHSA-2002:096
   URL:http://www.redhat.com/support/errata/RHSA-2002-096.html
 Christey> There are a couple directory traversal variants for GNU tar
   out there.  Can we be sure the references line up correctly?


CAN-2001-1268

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers
Reference: URL:http://online.securityfocus.com/archive/1/196445
Reference: CONFIRM:http://www.info-zip.org/pub/infozip/UnZip.html

Description:
Directory traversal vulnerability in Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) in an extracted filename.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Christey> MANDRAKE:MDKSA-2002:065
 Frech> XF:archive-extraction-directory-traversal(10224)
 Christey> CONECTIVA:CLA-2002:538
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538
   HP:HPSBTL0209-068
   URL:http://online.securityfocus.com/advisories/4514
   REDHAT:RHSA-2002:096
   URL:http://www.redhat.com/support/errata/RHSA-2002-096.html


CAN-2001-1269

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers
Reference: URL:http://online.securityfocus.com/archive/1/196445
Reference: CONFIRM:http://www.info-zip.org/pub/infozip/UnZip.html

Description:
Info-ZIP UnZip 5.42 and earlier allows attackers to overwrite arbitrary files during archive extraction via filenames in the archive that begin with the '/' (slash) character.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Christey> MANDRAKE:MDKSA-2002:065
 Frech> XF:archive-extraction-directory-traversal(10224)
 Christey> CONECTIVA:CLA-2002:538
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538
   REDHAT:RHSA-2002:096
   URL:http://www.redhat.com/support/errata/RHSA-2002-096.html


CAN-2001-1270

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers
Reference: URL:http://online.securityfocus.com/archive/1/196445
Reference: MISC:http://www.security.nnov.ru/advisories/archdt.asp

Description:
Directory traversal vulnerability in the console version of PKZip (pkzipc) 4.00 and earlier allows attackers to overwrite arbitrary files during archive extraction with the -rec (recursive) option via a .. (dot dot) attack on the archived files.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:archive-extraction-directory-traversal(10224)


CAN-2001-1271

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010712 SECURITY.NNOV: directory traversal and path globing in multiple archivers
Reference: URL:http://online.securityfocus.com/archive/1/196445
Reference: MISC:http://www.security.nnov.ru/advisories/archdt.asp

Description:
Directory traversal vulnerability in rar 2.02 and earlier allows attackers to overwrite arbitrary files during archive extraction via a .. (dot dot) attack on archived filenames.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:archive-extraction-directory-traversal(10224)


CAN-2001-1272

Phase: Proposed (20020502)
Reference: DEBIAN:DSA-092
Reference: URL:http://www.debian.org/security/2001/dsa-092
Reference: XF:wmtv-execute-commands(7669)
Reference: URL:http://www.iss.net/security_center/static/7669.php
Reference: BID:3658
Reference: URL:http://www.securityfocus.com/bid/3658

Description:
wmtv 0.6.5 and earlier does not properly drop privileges, which allows local users to execute arbitrary commands via the -e (external command) option.

Votes:

   ACCEPT(4) Wall, Cole, Green, Frech
   NOOP(2) Foat, Cox

CAN-2001-1273

Phase: Proposed (20020502)
Reference: CIAC:L-045
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-045.shtml
Reference: REDHAT:RHSA-2001:013
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-013.html

Description:
The "mxcsr P4" vulnerability in the Linux kernel before 2.2.17-14, when running on certain Intel CPUs, allows local users to cause a denial of service (system halt).

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:kernel-mxcsr-p4-dos(9995)


CAN-2001-1274

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010119 Re: MySQL Overflow + exploit [ops..sent a broken exploit :P]
Reference: BUGTRAQ:20010118 Buffer overflow in MySQL < 3.23.31
Reference: BUGTRAQ:20010119 Re: MySQL < 3.23.31 Overflow [exploit]
Reference: DEBIAN:DSA-013
Reference: URL:http://www.debian.org/security/2001/dsa-013
Reference: CALDERA:CSSA-2001-006.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txt
Reference: CONECTIVA:CLA-2001:375
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000375
Reference: FREEBSD:FreeBSD-SA-01:16
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98089552030459&w=2
Reference: CONFIRM:http://www.mysql.com/documentation/mysql/bychapter/manual_News.html#News-3.23.3
Reference: MANDRAKE:MDKSA-2001:014
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3
Reference: REDHAT:RHSA-2001:003
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-003.html

Description:
Buffer overflow in MySQL before 3.23.31 allows attackers to cause a denial of service and possibly gain privileges.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:mysql-select-bo(5969)


CAN-2001-1275

Phase: Proposed (20020502)
Reference: CALDERA:CSSA-2001-006.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2001-006.0.txt
Reference: FREEBSD:FreeBSD-SA-01:16
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98089552030459&w=2
Reference: MANDRAKE:MDKSA-2001:014
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-014.php3
Reference: REDHAT:RHSA-2001:003
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-003.html

Description:
MySQL before 3.23.31 allows users with a MySQL account to use the SHOW GRANTS command to obtain the encrypted administrator password from the mysql.user table and possibly gain privileges via password cracking.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
   REVIEWING(1) Christey
Voter Comments:
 Christey> CALDERA:CSSA-2001-006.0 specifically says they're not
   vulnerable to this issue.  So, do we remove the reference
   (because they aren't affected by this problem), or do we
   keep the reference because it specifically mentions this
   issue?
   
   Need to review the other advisories; they don't necessarily
   have the details to know whether they're addressing this
   problem or not (the overflow mentioned in these refs is
   covered by CAN-2001-1274).  MANDRAKE:MDKSA-2001:014
   clearly identifies this issue.
   
   FREEBSD:FreeBSD-SA-01:16 discussed "remote vulerabilities"
   (plural), which *could* include this issue, but it is not
   absolutely certain.  REDHAT:RHSA-2001:003 refers to
   "information protection issues," but that's not clear enough
   either.
   
   Thanks to John Segura of secureinfo.com for noticing this
   issue.
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:mysql-show-grants-password(9996)


CAN-2001-1278

Phase: Proposed (20020502)
Reference: REDHAT:RHSA-2001:115
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-115.html
Reference: MANDRAKE:MDKSA-2001:080
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-080.php3
Reference: BID:3425
Reference: URL:http://online.securityfocus.com/bid/3425

Description:
Zope before 2.2.4 allows partially trusted users to bypass security controls for certain methods by accessing the methods through the fmt attribute of dtml-var tags.

Votes:

   ACCEPT(3) Wall, Cole, Green
   NOOP(1) Foat
   REJECT(3) Christey, Frech, Cox
Voter Comments:
 Christey> Agreed; dupe of CVE-2001-1227


CAN-2001-1279

Phase: Interim (20030326)
Reference: REDHAT:RHSA-2001:089
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-089.html
Reference: FREEBSD:FreeBSD-SA-01:48
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-01:48.tcpdump.asc
Reference: CONECTIVA:CLA-2002:480
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000480
Reference: MANDRAKE:MDKSA-2002:032
Reference: URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-032.php
Reference: CALDERA:CSSA-2002-025.0
Reference: URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-025.0.txt
Reference: XF:tcpdump-afs-rpc-bo(7006)
Reference: URL:http://www.iss.net/security_center/static/7006.php
Reference: BID:3065
Reference: URL:http://online.securityfocus.com/bid/3065
Reference: CERT-VN:VU#797201
Reference: URL:http://www.kb.cert.org/vuls/id/797201

Description:
Buffer overflow in print-rx.c of tcpdump 3.x (probably 3.6x) allows remote attackers to cause a denial of service and possibly execute arbitrary code via AFS RPC packets with invalid lengths that trigger an integer signedness error, a different vulnerability than CVE-2000-1026.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Christey> ADDREF CONECTIVA:CLA-2002:480
   The Conectiva advisory references the FreeBSD advisory used in
   this CAN, along with other issues that are addressed.
 Christey> CONECTIVA:CLA-2002:480
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000480
 Christey> MANDRAKE:MDKSA-2002:032
   CONECTIVA:CLA-2002:480
   CALDERA:CSSA-2002-025.0
 Frech> XF:tcpdump-afs-rpc-bo(7006)
 Christey> Consider whether SUSE:SuSE-SA:2002:020 addresses this
   issue or not.


CAN-2001-1280

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011011 Vulnerabilities in Ipswitch IMail Server 7.04
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3424
Reference: URL:http://online.securityfocus.com/bid/3424

Description:
POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users on the system.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:imail-account-brute-force(7272)


CAN-2001-1281

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011011 Vulnerabilities in Ipswitch IMail Server 7.04
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0076.html
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3429
Reference: URL:http://online.securityfocus.com/bid/3429

Description:
Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser parameter in the "Change User Information" web form.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:imail-change-user-info(7273)


CAN-2001-1282

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011011 Ipswitch Imail 7.04 vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3426
Reference: URL:http://online.securityfocus.com/bid/3426

Description:
Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially sensitive configuration information.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:imail-attachment-path-disclosure(7276)


CAN-2001-1283

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011011 Ipswitch Imail 7.04 vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3427
Reference: URL:http://online.securityfocus.com/bid/3427

Description:
The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . (dot) or other characters to programs such as (1) readmail.cgi or (2) printmail.cgi, possibly due to a buffer overflow that may allow execution of arbitrary code.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:imail-dot-mailbox-dos(7277)


CAN-2001-1284

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011011 Ipswitch Imail 7.04 vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3428
Reference: URL:http://online.securityfocus.com/bid/3428

Description:
Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:imail-session-id-predictable(7278)


CAN-2001-1285

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011011 Ipswitch Imail 7.04 vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3432
Reference: URL:http://online.securityfocus.com/bid/3432

Description:
Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (dot dot) in the mbx parameter.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:imail-mailbox-directory-traversal(7275)


CAN-2001-1286

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011011 Ipswitch Imail 7.04 vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0082.html
Reference: BUGTRAQ:20020310 IMail Account hijack through the Web Interface
Reference: URL:http://online.securityfocus.com/archive/1/261096
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3432
Reference: URL:http://online.securityfocus.com/bid/3432

Description:
Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HTML email that causes the Referrer to be sent to a URL under the attacker's control.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:imail-mailbox-directory-traversal(7275)


CAN-2001-1287

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011012 def-2001-29
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-10/0083.html
Reference: MISC:http://www.ipswitch.com/Support/IMail/news.html
Reference: BID:3431
Reference: URL:http://online.securityfocus.com/bid/3431

Description:
Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:imail-web-calendaring-bo(7279)


CAN-2001-1288

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010727 bug w2k
Reference: URL:http://online.securityfocus.com/archive/1/200118
Reference: BUGTRAQ:20010801 F7-Enter bug details & workaround
Reference: URL:http://online.securityfocus.com/archive/1/201151
Reference: VULN-DEV:20010730 RE: bug w2k
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=99651044701417&w=2
Reference: BUGTRAQ:20010729 Re: w2k dos
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99640583014377&w=2
Reference: BUGTRAQ:20010731 NT TS / Win 2K and F7 - Enter bug
Reference: URL:http://online.securityfocus.com/archive/1/200985
Reference: BID:3115
Reference: URL:http://online.securityfocus.com/bid/3115

Description:
Windows 2000 and Windows NT allows local users to cause a denial of service (reboot) by executing a command at the command prompt and pressing the F7 and enter keys several times while the command is executing, possibly related to an exception handling error in csrss.exe.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(1) Cox
   REJECT(1) Foat
   REVIEWING(1) Wall
Voter Comments:
 Foat> Unable to duplicate vulnerability
 Frech> XF:win-command-prompt-dos(11216)


CAN-2001-1289

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010730 ADV: Quake 3 Arena 1.29f/g Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0748.html
Reference: BID:3123
Reference: URL:http://online.securityfocus.com/bid/3123

Description:
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection packet that begins with several char-255 characters.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Frech> XF:quake3-arena-connectre-bo(6930)


CAN-2001-1290

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010627 Active Web Classifieds failure to authenticate leads to arbitrary code execution
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0386.html
Reference: BID:2942
Reference: URL:http://online.securityfocus.com/bid/2942
Reference: XF:active-classifieds-admin-access(6754)
Reference: URL:http://xforce.iss.net/static/6754.php

Description:
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify the configuration, gain privileges, and execute arbitrary Perl code via the table_width parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1292

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010813 Sambar Telnet Proxy/Server multiple vulnerablietis
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0160.html
Reference: XF:sambar-telnet-bo(6973)
Reference: URL:http://www.iss.net/security_center/static/6973.php

Description:
Sambar Telnet Proxy/Server allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long password.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1293

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010926 3Com(r) HomeConnect(r) Cable Modem Denial of Service
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0217.html
Reference: CERT-VN:VU#500027
Reference: URL:http://www.kb.cert.org/vuls/id/500027
Reference: BID:3366
Reference: URL:http://online.securityfocus.com/bid/3366

Description:
Buffer overflow in web server of 3com HomeConnect Cable Modem External with USB (#3CR29223) allows remote attackers to cause a denial of service (crash) via a long HTTP request.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:3com-officeconnect-http-dos(6573)


CAN-2001-1294

Phase: Proposed (20020502)
Reference: NTBUGTRAQ:20000117 Remote Buffer Exploit - InetServ 3.0
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0001&L=ntbugtraq&F=P&S=&P=4592
Reference: BUGTRAQ:20010822 AVTronics InetServer DoS and BoF Vulnerabilities
Reference: BID:3224
Reference: URL:http://online.securityfocus.com/bid/3224
Reference: XF:inetserv-webmail-bo(7022)
Reference: URL:http://www.iss.net/security_center/static/7022.php

Description:
Buffer overflow in A-V Tronics Inetserv 3.2.1 and earlier allows remote attackers to cause a denial of service (crash) in the Webmail interface via a long username and password.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1298

Phase: Proposed (20020502)
Reference: BUGTRAQ:20011002 results of semi-automatic source code audit
Reference: URL:http://www.securityfocus.com/archive/1/218000
Reference: BID:3385
Reference: URL:http://www.securityfocus.com/bid/3385
Reference: XF:php-includedir-code-execution(7215)
Reference: URL:http://www.iss.net/security_center/static/7215.php

Description:
Webodex PHP script 1.0 and earlier allows remote attackers to include arbitrary files from remote web sites via an HTTP request that sets the includedir variable.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1300

Phase: Proposed (20020502)
Reference: MISC:http://www.securiteam.com/windowsntfocus/5KP0N0A55M.html
Reference: XF:dynuftp-dot-directory-traversal(7045)
Reference: URL:http://www.iss.net/security_center/static/7045.php

Description:
Directory traversal vulnerability in Dynu FTP server 1.05 and earlier allows remote attackers to read arbitrary files via a .. in the CD (CWD) command.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1302

Phase: Proposed (20020502)
Reference: NTBUGTRAQ:20010718 Changing NT/2000 accounts password from the command line
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0107&L=ntbugtraq&F=P&S=&P=1911
Reference: BID:3063
Reference: URL:http://www.securityfocus.com/bid/3063
Reference: XF:win2k-change-network-passwords(6876)
Reference: URL:http://xforce.iss.net/static/6876.php

Description:
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.

Votes:

   ACCEPT(4) Foat, Cole, Green, Frech
   NOOP(1) Cox
   REVIEWING(1) Wall

CAN-2001-1304

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010803 Denial of Service in SHOUTcast Server 1.8.2 Linux/w32/?
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0048.html
Reference: XF:shoutcast-http-field-bo(6938)
Reference: URL:http://www.iss.net/security_center/static/6938.php

Description:
Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or (2) host HTTP header.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1305

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010822 Hexyn / Securax Advisory #22 - ICQ Forced Auto-Add Users
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99851887024728&w=2
Reference: BID:3226
Reference: URL:http://online.securityfocus.com/bid/3226
Reference: XF:icq-auto-add-user(7028)
Reference: URL:http://www.iss.net/security_center/static/7028.php

Description:
ICQ 2001a Alpha and earlier allows remote attackers to automatically add arbitrary UINs to an ICQ user's contact list via a URL to a web page with a Content-Type of application/x-icq, which is processed by Internet Explorer.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1306

Phase: Proposed (20020502)
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CERT-VN:VU#276944
Reference: URL:http://www.kb.cert.org/vuls/id/276944
Reference: SGI:20011102-01-I
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20011102-01-I
Reference: MISC:http://www.kb.cert.org/vuls/id/JPLA-4WESMM
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/

Description:
iPlanet Directory Server 4.1.4 and earlier (LDAP) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid BER length of length fields, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(3) Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(2) Foat, Cox
Voter Comments:
 Frech> XF:iplanet-ldap-protos-bo(6893)


CAN-2001-1307

Phase: Proposed (20020502)
Reference: CERT-VN:VU#276944
Reference: URL:http://www.kb.cert.org/vuls/id/276944
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: SGI:20011102-01-I
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20011102-01-I
Reference: MISC:http://www.kb.cert.org/vuls/id/JPLA-4WESMM
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: XF:iplanet-ldap-protos-bo(6893)
Reference: URL:http://xforce.iss.net/static/6893.php
Reference: BID:3038
Reference: URL:http://www.securityfocus.com/bid/3038

Description:
Buffer overflows in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(4) Wall, Cole, Green, Frech
   NOOP(2) Foat, Cox

CAN-2001-1308

Phase: Proposed (20020502)
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CERT-VN:VU#276944
Reference: URL:http://www.kb.cert.org/vuls/id/276944
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: SGI:20011102-01-I
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20011102-01-I
Reference: MISC:http://www.kb.cert.org/vuls/id/JPLA-4WESMM
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: BID:3039
Reference: URL:http://www.securityfocus.com/bid/3039
Reference: XF:iplanet-ldap-protos-format-string(6898)
Reference: URL:http://xforce.iss.net/static/6898.php

Description:
Format string vulnerabilities in iPlanet Directory Server 4.1.4 and earlier (LDAP) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(4) Wall, Cole, Green, Frech
   NOOP(2) Foat, Cox

CAN-2001-1309

Phase: Proposed (20020502)
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CERT-VN:VU#505564
Reference: URL:http://www.kb.cert.org/vuls/id/505564
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: MISC:http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y
Reference: BID:3040
Reference: URL:http://www.securityfocus.com/bid/3040
Reference: XF:secureway-ldap-protos-dos(6894)
Reference: URL:http://xforce.iss.net/static/6894.php

Description:
Buffer overflows in IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1310

Phase: Proposed (20020502)
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CERT-VN:VU#505564
Reference: URL:http://www.kb.cert.org/vuls/id/505564
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: MISC:http://www.kb.cert.org/vuls/id/CFCR-4YQ33Y
Reference: BID:3040
Reference: URL:http://www.securityfocus.com/bid/3040
Reference: XF:secureway-ldap-protos-dos(6894)
Reference: URL:http://xforce.iss.net/static/6894.php

Description:
IBM SecureWay 3.2.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for the L field of a BER encoding, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1311

Phase: Proposed (20020502)
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT-VN:VU#583184
Reference: URL:http://www.kb.cert.org/vuls/id/583184
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CONFIRM:http://www.notes.net/r5fixlist.nsf/Search!SearchView&Query=DWUU4W6NC8
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: XF:domino-ldap-protos-bo(6895)
Reference: URL:http://xforce.iss.net/static/6895.php
Reference: BID:3041
Reference: URL:http://www.securityfocus.com/bid/3041

Description:
Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Green, Frech
   NOOP(1) Cox
   REVIEWING(1) Christey
Voter Comments:
 Christey> Need to decide if regression errors should get their own CVE's
   or not.  A regression error was introduced as explained in:
   
   VULNWATCH:20030313 R7-0012: Lotus Notes/Domino R6-beta PROTOS LDAP Denial of Service Regression
   URL:http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0127.html
   
   This affects Domino R5.0.7 and earlier, and R6 pre-release/beta


CAN-2001-1312

Phase: Proposed (20020502)
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT-VN:VU#583184
Reference: URL:http://www.kb.cert.org/vuls/id/583184
Reference: CONFIRM:http://www.notes.net/r5fixlist.nsf/Search!SearchView&Query=DWUU4W6NC8
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: XF:domino-ldap-protos-format-string(6896)
Reference: URL:http://xforce.iss.net/static/6896.php
Reference: BID:3042
Reference: URL:http://www.securityfocus.com/bid/3042

Description:
Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(4) Wall, Cole, Green, Frech
   NOOP(2) Foat, Cox

CAN-2001-1313

Phase: Proposed (20020502)
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT-VN:VU#583184
Reference: URL:http://www.kb.cert.org/vuls/id/583184
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CONFIRM:http://www.notes.net/r5fixlist.nsf/Search!SearchView&Query=DWUU4W6NC8
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/

Description:
Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(3) Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(2) Foat, Cox
Voter Comments:
 Frech> XF:domino-ldap-protos-format-string(6896)


CAN-2001-1314

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010731 RE: CERT Advisory CA-2001-18, Critical Path directory products ar e vulnerable
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0770.html
Reference: CERT-VN:VU#657547
Reference: URL:http://www.kb.cert.org/vuls/id/657547
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: BID:3124
Reference: URL:http://www.securityfocus.com/bid/3124

Description:
Buffer overflows in Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:injoin-ldap-protos-bo(6978)


CAN-2001-1315

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010731 RE: CERT Advisory CA-2001-18, Critical Path directory products ar e vulnerable
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0770.html
Reference: CERT-VN:VU#657547
Reference: URL:http://www.kb.cert.org/vuls/id/657547
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JPLA-4ZKLEM
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/

Description:
Critical Path (1) InJoin Directory Server or (2) LiveContent Directory allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:injoin-ldap-protos-bo(6978)


CAN-2001-1316

Phase: Proposed (20020502)
Reference: CERT-VN:VU#688960
Reference: URL:http://www.kb.cert.org/vuls/id/688960
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JPLA-4WESNA
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: XF:teamware-ldap-protos-bo(6897)
Reference: URL:http://xforce.iss.net/static/6897.php
Reference: BID:3044
Reference: URL:http://www.securityfocus.com/bid/3044

Description:
Buffer overflows in Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1317

Phase: Proposed (20020502)
Reference: CERT-VN:VU#688960
Reference: URL:http://www.kb.cert.org/vuls/id/688960
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JPLA-4WESNA
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/

Description:
Teamware Office Enterprise Directory allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, via invalid encodings for certain BER object types, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:teamware-ldap-protos-bo(6897)


CAN-2001-1318

Phase: Proposed (20020502)
Reference: CERT-VN:VU#717380
Reference: URL:http://www.kb.cert.org/vuls/id/717380
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JPLA-4WESNA
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: BID:3043
Reference: URL:http://www.securityfocus.com/bid/3043

Description:
Vulnerabilities in Qualcomm Eudora WorldMail Server may allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:eudora-ldap-protos-bo(7940)


CAN-2001-1319

Phase: Proposed (20020502)
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CERT-VN:VU#763400
Reference: URL:http://www.kb.cert.org/vuls/id/763400
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/CFCN-4YAQC7
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: BID:3045
Reference: URL:http://www.securityfocus.com/bid/3045
Reference: XF:exchange-ldap-protos-dos(6899)
Reference: URL:http://xforce.iss.net/static/6899.php

Description:
Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(4) Wall, Cole, Green, Frech
   NOOP(2) Foat, Cox

CAN-2001-1320

Phase: Proposed (20020502)
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CERT-VN:VU#765256
Reference: URL:http://www.kb.cert.org/vuls/id/765256
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JPLA-4WESNK
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/
Reference: BID:3046
Reference: URL:http://www.securityfocus.com/bid/3046
Reference: XF:pgp-keyserver-ldap-bo(6900)
Reference: URL:http://xforce.iss.net/static/6900.php

Description:
Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via exceptional BER encodings (possibly buffer overflows), as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1321

Phase: Proposed (20020502)
Reference: CIAC:L-116
Reference: URL:http://ciac.llnl.gov/ciac/bulletins/l-116.shtml
Reference: CERT-VN:VU#869184
Reference: URL:http://www.kb.cert.org/vuls/id/869184
Reference: CERT:CA-2001-18
Reference: URL:http://www.cert.org/advisories/CA-2001-18.html
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JPLA-4WESNV
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/

Description:
Oracle Internet Directory Server 2.1.1.x and 3.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via invalid encodings of BER OBJECT-IDENTIFIER values, as demonstrated by the PROTOS LDAPv3 test suite.

Votes:

   ACCEPT(3) Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(2) Foat, Cox
Voter Comments:
 Frech> XF:oracle-ldap-protos-bo(6902)


CAN-2001-1323

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010426 Security advisory: krb5 ftpd buffer overflows
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98826223517788&w=2
Reference: IMMUNIX:IMNX-2001-70-022-01
Reference: URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-022-01
Reference: CONFIRM:http://web.mit.edu/kerberos/www/advisories/ftpbuf.txt
Reference: REDHAT:RHSA-2001:060
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-060.html

Description:
Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via base-64 encoded data, which is not properly handled when the radix_encode function processes file glob output from the ftpglob function.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:kerberos-inject-base64-encode(6454)


CAN-2001-1324

Phase: Proposed (20020502)
Reference: CONFIRM:http://multivac.cwru.edu/idtools/admin_idtools.tar.bz2
Reference: MISC:http://securitytracker.com/alerts/2001/Jun/1001839.html
Reference: BID:2934
Reference: URL:http://www.securityfocus.com/bid/2934

Description:
cvmlogin and statfile in Paul Jarc idtools before 2001.06.27 do not properly check the return value of a call to the pathexec_env function, which could cause the setstate utility to setuid to the UID environment variable and allow local users to gain privileges.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:idtools-cmvlogin-root-privileges(9987)


CAN-2001-1325

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010420 XML scripting in IE, Outlook Express
Reference: URL:http://www.securityfocus.com/archive/1/3AE02004.57FDF958@guninski.com
Reference: XF:ie-xml-stylesheets-scripting(6448)
Reference: URL:http://xforce.iss.net/static/6448.php
Reference: BID:2633
Reference: URL:http://www.securityfocus.com/bid/2633

Description:
Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerability in Windows Scripting Host (WSH).

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(2) Foat, Cox
   REVIEWING(1) Wall

CAN-2001-1326

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010528 feeble.hey!dora.exploit part.II
Reference: URL:http://www.securityfocus.com/archive/1/187128
Reference: BID:2796
Reference: URL:http://www.securityfocus.com/bid/2796

Description:
Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via an HTML email with a form that is activated from an image that the attacker spoofs as a link, which causes the user to execute the form and access embedded attachments.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:eudora-msviewer-execute-attachment(6635)


CAN-2001-1328

Phase: Proposed (20020502)
Reference: CIAC:L-103
Reference: AUSCERT:AA-2001.03
Reference: URL:ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2001.03
Reference: SUN:00203
Reference: XF:solaris-ypbind-bo(6828)

Description:
Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Foat, Cole, Cox
   REVIEWING(1) Wall
Voter Comments:
 Green> Sun Security bulletin 00203


CAN-2001-1329

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010611 rsh bufferoverflow on AIX 4.2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0133.html

Description:
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root priveleges via a long command line argument.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Cox
   REJECT(1) Christey
Voter Comments:
 Christey> Acknowledged by vendor (Troy Bollinger no less ;-) in:
   BUGTRAQ:20010612 Re: (forw) rsh bufferoverflow on AIX 4.2
   URL:http://online.securityfocus.com/archive/1/190630
   
   HOWEVER... this looks like a rediscovery of CVE-1999-0101.
   Troy's June 2001 response mentions a gethostbyname() problem
   in 1996, which is CVE-1999-0101.
 Frech> XF:dns-leng-ovf(637)
   XF:ghbn-bo(1751)
   Also assigned: CVE-1999-0101
   In description, 'privileges' is misspelled.


CAN-2001-1330

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010611 rsh bufferoverflow on AIX 4.2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0133.html

Description:
Buffer overflow in rsh on AIX 4.2.0.0 may allow local users to gain root privileges via a long command line argument.

Votes:

   ACCEPT(1) Green
   NOOP(4) Wall, Foat, Cole, Cox
   REJECT(2) Christey, Frech
Voter Comments:
 Christey> Reject this for 2 reasons:
   (1) It's a carbon copy of CAN-2001-1329
   (2) CAN-2001-1329 is a dupe of CVE-1999-0101, which means
   CAN-2001-1330 is, too.
 Frech> CAN-2001-1330 is the same as CAN-2001-1329


CAN-2001-1331

Phase: Proposed (20020502)
Reference: CONFIRM:http://online.securityfocus.com/advisories/3307
Reference: DEBIAN:DSA-056
Reference: URL:http://www.debian.org/security/2001/dsa-056
Reference: BID:2720
Reference: URL:http://online.securityfocus.com/bid/2720

Description:
mandb in the man-db package before 2.3.16-3 allows local users to overwrite arbitrary files via the command line options (1) -u or (2) -c, which do not drop privileges and follow symlinks.

Votes:

   ACCEPT(3) Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(2) Foat, Cox
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:mandb-tmpfile-symlink(9989)


CAN-2001-1332

Phase: Proposed (20020502)
Reference: CONECTIVA:CLA-2001:384
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000384
Reference: CONECTIVA:CLA-2001:386
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000386
Reference: MANDRAKE:MDKSA-2001:048
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-048.php3
Reference: SUSE:SuSE-SA:2002:005
Reference: URL:http://lists2.suse.com/archive/suse-security-announce/2001-Mar/0000.html

Description:
Buffer overflows in Linux CUPS before 1.1.6 may allow remote attackers to execute arbitrary code.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Cox> ADDREF: RHSA-2002:032
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:cups-password-bo(9997)


CAN-2001-1333

Phase: Proposed (20020502)
Reference: CONECTIVA:CLA-2001:384
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000384
Reference: CONECTIVA:CLA-2001:386
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000386
Reference: MANDRAKE:MDKSA-2001:048
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-048.php3
Reference: SUSE:SuSE-SA:2002:005
Reference: URL:http://lists2.suse.com/archive/suse-security-announce/2001-Mar/0000.html

Description:
Linux CUPS before 1.1.6 does not securely handle temporary files, possibly due to a symlink vulnerability that could allow local users to overwrite files.

Votes:

   ACCEPT(3) Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Cox> ADDREF: RHSA-2002:032
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:cups-tmpfile-symlink(9998)
   Correction SUSE:SuSE-SA:2002:005 should be
   SUSE:SuSE-SA:2001:05


CAN-2001-1335

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010527 CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0252.html
Reference: XF:cesarftp-directory-traversal(6606)
Reference: URL:http://www.iss.net/security_center/static/6606.php
Reference: BID:2786
Reference: URL:http://online.securityfocus.com/bid/2786

Description:
Directory traversal vulnerability in CesarFTP 0.98b and earlier allows remote authenticated users (such as anonymous) to read arbitrary files via a GET with a filename that contains a ...%5c (modified dot dot).

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1336

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010527 CesarFTP v0.98b triple dot Directory Traversal / Weak password encryption
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0252.html
Reference: BID:2785
Reference: URL:http://online.securityfocus.com/bid/2785
Reference: XF:cesarftp-settings-plaintext-password(6608)
Reference: URL:http://www.iss.net/security_center/static/6608.php

Description:
CesarFTP 0.98b and earlier stores usernames and passwords in plaintext in the settings.ini file, which allows attackers to gain privileges.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1337

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010524 IPC@Chip Security
Reference: URL:http://www.securityfocus.com/archive/1/186418
Reference: BID:2774
Reference: URL:http://www.securityfocus.com/bid/2774
Reference: XF:ipcchip-http-dos(6594)
Reference: URL:http://www.iss.net/security_center/static/6594.php

Description:
Beck IPC GmbH IPC@CHIP Embedded-Webserver allows remote attackers to cause a denial of service via a long HTTP request.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Wall, Foat, Cole, Green, Cox
Voter Comments:
 Green> Vendor disputes vulnerability, insufficient follow-up to render an opinion


CAN-2001-1338

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010602 IPC@Chip - Fixes
Reference: URL:http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html
Reference: BUGTRAQ:20010524 IPC@Chip Security
Reference: URL:http://www.securityfocus.com/archive/1/186418
Reference: CERT-VN:VU#198979
Reference: URL:http://www.kb.cert.org/vuls/id/198979
Reference: BID:2773
Reference: URL:http://www.securityfocus.com/bid/2773
Reference: XF:ipcchip-telnet-verify-account(6595)
Reference: URL:http://www.iss.net/security_center/static/6595.php

Description:
Beck IPC GmbH IPC@CHIP TelnetD server generates different responses when given valid and invalid login names, which allows remote attackers to determine accounts on the system.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1339

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010602 IPC@Chip - Fixes
Reference: URL:http://cert.uni-stuttgart.de/archive/bugtraq/2001/06/msg00010.html
Reference: BUGTRAQ:20010524 IPC@Chip Security
Reference: URL:http://www.securityfocus.com/archive/1/186418
Reference: CERT-VN:VU#198979
Reference: URL:http://www.kb.cert.org/vuls/id/198979
Reference: BID:2771
Reference: URL:http://www.securityfocus.com/bid/2771
Reference: XF:ipcchip-telnet-bruteforce-passwords(6605)
Reference: URL:http://www.iss.net/security_center/static/6605.php

Description:
Beck IPC GmbH IPC@CHIP telnet service does not delay or disconnect users from the service when bas passwords are entered, which makes it easier for remote attackers to conduct brute force password guessing attacks.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Christey, Cox
Voter Comments:
 Christey> "bas" = "bad"


CAN-2001-1340

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010602 IPC@Chip - Fixes
Reference: URL:http://www.securityfocus.com/archive/1/188219
Reference: BUGTRAQ:20010524 IPC@Chip Security
Reference: URL:http://www.securityfocus.com/archive/1/186418
Reference: CERT-VN:VU#756019
Reference: URL:http://www.kb.cert.org/vuls/id/756019
Reference: XF:ipcchip-telnet-admin-lockout(6596)
Reference: URL:http://www.iss.net/security_center/static/6596.php
Reference: BID:2772
Reference: URL:http://www.securityfocus.com/bid/2772

Description:
Beck GmbH IPC@Chip TelnetD service supports only one connection and does not disconnect a user who does not complete the login process, which allows remote attackers to lock out the administrator account by connecting to the service.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1341

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010602 IPC@Chip - Fixes
Reference: URL:http://www.securityfocus.com/archive/1/188219
Reference: BUGTRAQ:20010524 IPC@Chip Security
Reference: URL:http://www.securityfocus.com/archive/1/186418
Reference: CERT-VN:VU#574739
Reference: URL:http://www.kb.cert.org/vuls/id/574739
Reference: BID:2767
Reference: URL:http://www.securityfocus.com/bid/2767
Reference: XF:ipcchip-chipcfg-gain-information(6600)
Reference: URL:http://www.iss.net/security_center/static/6600.php

Description:
The Beck GmbH IPC@Chip embedded web server installs the chipcfg.cgi program by default, which allows remote attackers to obtain sensitive network information via a request to the program.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1343

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010612 bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0142.html
Reference: BID:2861
Reference: URL:http://www.securityfocus.com/bid/2861
Reference: XF:webstore-cgi-command-execution(6685)
Reference: URL:http://xforce.iss.net/static/6685.php

Description:
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via shell metacharacters in the kill parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Green> As this vulnerability requires the exploiter to have an authenticated administrative login, is it an oxymoron?


CAN-2001-1344

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010612 bug
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-06/0142.html
Reference: BID:2860
Reference: URL:http://www.securityfocus.com/bid/2860
Reference: XF:webstore-cgi-command-execution(6685)
Reference: URL:http://xforce.iss.net/static/6685.php

Description:
WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that exists, which is made easier by (1) inserting a null character or (2) .. (dot dot).

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox

CAN-2001-1346

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010518 tmp-races in ARCservIT Unix Client
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0184.html
Reference: BID:2748
Reference: URL:http://online.securityfocus.com/bid/2748
Reference: BID:2741
Reference: URL:http://online.securityfocus.com/bid/2741

Description:
Computer Associates ARCserveIT 6.61 and 6.63 (also called ARCservIT) allows local users to overwrite arbitrary files via a symlink attack on the temporary files (1) asagent.tmp or (2) inetd.tmp.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:arcserveit-inetd-tmpfile-symlink(10006)
   XF:arcserveit-asagent-tmpfile-symlink(10007)


CAN-2001-1347

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010524 Elevation of privileges with debug registers on Win2K
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0232.html
Reference: XF:win2k-debug-elevate-privileges(6590)
Reference: URL:http://www.iss.net/security_center/static/6590.php
Reference: BID:2764
Reference: URL:http://www.securityfocus.com/bid/2764

Description:
Windows 2000 allows local users to cause a denial of service and possibly gain privileges by setting a hardware breakpoint that is handled using global debug registers, which could cause other processes to terminate due to an exception, and allow hijacking of resources such as named pipes.

Votes:

   ACCEPT(4) Foat, Cole, Green, Frech
   NOOP(1) Cox
   REVIEWING(1) Wall

CAN-2001-1348

Phase: Proposed (20020502)
Reference: BUGTRAQ:20010528 TWIG SQL query bugs
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0260.html
Reference: MISC:http://twig.screwdriver.net/index.php3
Reference: XF:twig-webmail-query-modification(6619)
Reference: URL:http://www.iss.net/security_center/static/6619.php
Reference: BID:2791
Reference: URL:http://www.securityfocus.com/bid/2791

Description:
TWIG 2.6.2 and earlier allows remote attackers to perform unauthorized database operations via a SQL injection attack on the id parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Wall, Foat, Cole, Cox
Voter Comments:
 Green> Even if vague, there is acknowledgement.


CAN-2001-1350

Phase: Proposed (20020611)
Reference: REDHAT:RHSA-2001:162
Reference: MISC:http://search.namazu.org/ml/namazu-devel-ja/msg02114.html

Description:
Cross-site scripting vulnerability in namazu.cgi for Namazu 2.0.7 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the lang parameter.

Votes:

   ACCEPT(4) Wall, Cole, Green, Cox
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
Voter Comments:
 Frech> XF:linux-namazu-bo(7876)
 Christey> This is not a buffer overflow as suggested by the XF
   reference, it's a CSS/XSS issue (XF:linux-namazu-css(7875))


CAN-2001-1351

Phase: Modified (20030318-01)
Reference: REDHAT:RHSA-2001:162
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&w=2&r=1&s=namazu&q=b
Reference: XF:linux-namazu-css(7875)
Reference: URL:http://www.iss.net/security_center/static/7875.php

Description:
Cross-site scripting vulnerability in Namazu 2.0.8 and earlier allows remote attackers to execute arbitrary Javascript as other web users via the index file name that is displayed when displaying hit numbers.

Votes:

   ACCEPT(4) Cole, Alderson, Green, Cox
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:linux-namazu-css(7875)


CAN-2001-1352

Phase: Proposed (20020611)
Reference: REDHAT:RHSA-2001:179
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101060476404565&w=2
Reference: BUGTRAQ:20011227 Re: [RHSA-2001:162-04] Updated namazu packages are available
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100947261916155&w=2
Reference: BUGTRAQ:20020109 Details on the updated namazu packages that are available
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101068116016472&w=2

Description:
Cross-site scripting vulnerability in Namazu 2.0.9 and earlier allows remote attackers to execute arbitrary Javascript as other web users via an error message that is returned when an invalid index file is specified in the idxname parameter.

Votes:

   ACCEPT(5) Wall, Cole, Alderson, Green, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:linux-namazu-css(7875)


CAN-2001-1353

Phase: Proposed (20020611)
Reference: MISC:http://marc.theaimsgroup.com/?l=lprng&m=100083210910857&w=2
Reference: REDHAT:RHSA-2001:138
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-138.html

Description:
ghostscript before 6.51 allows local users to read and write arbitrary files as the 'lp' user via the file operator, even with -dSAFER enabled.

Votes:

   ACCEPT(4) Wall, Cole, Alderson, Green
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
   REVIEWING(1) Cox
Voter Comments:
 Christey> [See Mark Cox' email to me 20020617, subject "can-2001-1353"]
 Frech> XF:ghostscript-dsafer-read-files(7412)


CAN-2001-1354

Phase: Proposed (20020611)
Reference: BUGTRAQ:20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflows
Reference: URL:http://online.securityfocus.com/archive/1/198293
Reference: XF:netwin-nwauth-weak-encryption(6866)
Reference: URL:http://xforce.iss.net/static/6866.php
Reference: BID:3075
Reference: URL:http://www.securityfocus.com/bid/3075

Description:
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses weak password hashing, which could allow local users to decrypt passwords or use a different password that has the same hash value as the correct password.

Votes:

   ACCEPT(3) Cole, Alderson, Frech
   NOOP(4) Wall, Foat, Green, Cox

CAN-2001-1355

Phase: Proposed (20020611)
Reference: BUGTRAQ:20010720 NetWin Authentication Module 3.0b password storage vulnerabilities / buffer overflows
Reference: URL:http://online.securityfocus.com/archive/1/198293
Reference: BID:3077
Reference: URL:http://www.securityfocus.com/bid/3077
Reference: XF:netwin-nwauth-bo(6865)
Reference: URL:http://xforce.iss.net/static/6865.php

Description:
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, could allow attackers to execute arbitrary code via long arguments to (1) the -del command or (2) the -lookup command.

Votes:

   ACCEPT(3) Cole, Alderson, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1356

Phase: Proposed (20020611)
Reference: BUGTRAQ:20010804 SurgeFTP admin account bruteforcable
Reference: URL:http://online.securityfocus.com/archive/1/201951
Reference: XF:surgeftp-weak-password-encryption(6961)
Reference: URL:http://www.iss.net/security_center/static/6961.php
Reference: BID:3157
Reference: URL:http://www.securityfocus.com/bid/3157

Description:
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.

Votes:

   ACCEPT(3) Cole, Alderson, Frech
   NOOP(3) Wall, Foat, Cox

CAN-2001-1357

Phase: Proposed (20020611)
Reference: CONFIRM:http://www.phpheaven.net/projects/phpMyChat/changes.php3

Description:
Multiple vulnerabilities in phpMyChat before 0.14.5 exist in (1) input.php3, (2) handle_inputH.php3, or (3) index.lib.php3 with unknown consequences, possibly related to user spoofing or improperly initialized variables.

Votes:

   ACCEPT(3) Cole, Alderson, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Alderson> Given the fact that there is limited information concerning
   these "multiple" vulnerabilities mixed with the importance of time.  It
   appears that the information obtained so far is as sepcific as its going to
   get.
 Frech> XF:phpmychat-weak-input(9831)


CAN-2001-1358

Phase: Proposed (20020611)
Reference: CONFIRM:http://www.phpheaven.net/projects/phpMyChat/changes.php3

Description:
Vulnerabilities in phpMyChat before 0.14.4 allow local and possibly remote attackers to gain privileges by specifying an alternate library file in the L (localization) parameter.

Votes:

   ACCEPT(3) Cole, Alderson, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Alderson> We should be ready to break this out into more seperate
   Candidates should more information come to light on this.
 Frech> XF:phpmychat-weak-input(9831)


CAN-2001-1360

Phase: Proposed (20020611)
Reference: CONFIRM:ftp://ftp.mostang.com/pub/sane/sane-1.0.8/sane-backends-1.0.8.tar.gz
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html

Description:
Vulnerability in Scanner Access Now Easy (SANE) before 1.0.5, related to pnm and saned.

Votes:

   ACCEPT(3) Cole, Alderson, Green
   MODIFY(2) Frech, Cox
   NOOP(2) Wall, Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to MODIFY]
 Cox> I'm not sure how to vote on this, I did the research and read
   the changlog and it appears that the issue you mention here has not
   been fixed at all; merely documented as of sane version 1.0.5
   
   Change description based on the information in the Sane tarball; note that 
   this affects all versions to date and is not fixed.
   
   ---cut---
   
   - Security problems with pnm
   If the pnm backend is installed and saned is used to allow users on
   remote computers to scan on the local machine, pnm files can be read by
   the remote user. This is limited to the files saned can access (usually
   it's running as user "sane"). All pnm files can be read if saned runs
   as root which isn't recommended anyway. The pnm backend is disabled
   by default. If you want to use it, enable it with configure (see 
   configure --help for details). Be sure that only trusted users can
   access the pnm backend over saned.
   
   ---cut---
 Frech> XF:sane-prm-read-files(9853)


CAN-2001-1361

Phase: Proposed (20020611)
Reference: CONFIRM:http://twig.screwdriver.net/file.php3?file=CHANGELOG
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html

Description:
Vulnerability in The Web Information Gateway (TWIG) 2.7.1, possibly related to incorrect security rights and/or the generation of mailto links.

Votes:

   ACCEPT(3) Cole, Alderson, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
Voter Comments:
 Frech> XF:twig-mailto(9871)


CAN-2001-1362

Phase: Proposed (20020611)
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html
Reference: CONFIRM:http://freshmeat.net/releases/51981/

Description:
Vulnerability in the server for nPULSE before 0.53p4.

Votes:

   ACCEPT(3) Cole, Alderson, Green
   NOOP(3) Wall, Foat, Cox
   REVIEWING(1) Frech

CAN-2001-1363

Phase: Proposed (20020611)
Reference: CONFIRM:http://phpwebsite.appstate.edu/downloads/0.7.9/phpWebSite-en-0.7.9.tar.gz
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html

Description:
Vulnerability in phpWebSite before 0.7.9 related to running multiple instances in the same domain, which may allow attackers to gain administrative privileges.

Votes:

   ACCEPT(3) Cole, Alderson, Green
   NOOP(3) Wall, Foat, Cox
   REVIEWING(1) Frech

CAN-2001-1364

Phase: Proposed (20020611)
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html
Reference: CONFIRM:ftp://ftp.earth.li/pub/projectpurple/autodns-0.0.4.tar.gz

Description:
Vulnerability in autodns.pl for AutoDNS before 0.0.4 related to domain names that are not fully qualified.

Votes:

   ACCEPT(4) Foat, Cole, Alderson, Green
   NOOP(2) Wall, Cox
   REVIEWING(1) Frech

CAN-2001-1365

Phase: Proposed (20020611)
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html
Reference: CONFIRM:http://archives.neohapsis.com/archives/apps/freshmeat/2001-07/0011.html

Description:
Vulnerability in IntraGnat before 1.4.

Votes:

   ACCEPT(3) Cole, Alderson, Green
   NOOP(3) Wall, Foat, Cox
   REVIEWING(1) Frech
Voter Comments:
 Alderson> Even though this should be included as a candidate, I'm not sure
   how one would ever actually derive a handle to this candidate
   for any useful purpose other than an obscure reference.


CAN-2001-1366

Phase: Proposed (20020611)
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html
Reference: CONFIRM:http://netscript.sourceforge.net/netscript-1.6.2.tgz

Description:
netscript before 1.6.3 parses dynamic variables, which could allow remote attackers to alter program behavior or obtain sensitive information.

Votes:

   ACCEPT(4) Foat, Cole, Alderson, Green
   NOOP(2) Wall, Cox
   REVIEWING(1) Frech

CAN-2001-1367

Phase: Proposed (20020611)
Reference: CONFIRM:http://phpslice.org/comments.php?aid=1031&
Reference: VULNWATCH:20010719 [VulnWatch] Changelog maddness (14 various broken apps)
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0005.html

Description:
The checkAccess function in PHPSlice 0.1.4, and all other versions between 0.1.1 and 0.1.6, does not properly verify the administrative access level, which could allow remote attackers to gain privileges.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cox
   REVIEWING(1) Alderson
Voter Comments:
 Alderson> Is there a candidate already in existence for the problem as it
   relates to 0.1.4?  If so, since this problem was not fixed, perhaps that one
   needs to be modified to include 0.1.7.
 Frech> XF:phpslice-checkaccess-function-privileges(9649)


CAN-2001-1368

Phase: Proposed (20020611)
Reference: HP:HPSBUX0106-152
Reference: URL:http://archives.neohapsis.com/archives/hp/2001-q2/0059.html
Reference: XF:hp-virtualvault-iws-corrupt-data(6697)
Reference: URL:http://xforce.iss.net/static/6697.php

Description:
Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data.

Votes:

   ACCEPT(3) Cole, Green, Frech
   NOOP(3) Wall, Foat, Cox
   REVIEWING(1) Alderson
Voter Comments:
 Alderson> Although the CD:VAGUE is a great way to handle issues, what do we
   gain from adding an entry to describe that which might have
   already been described by any number of 4 others except as a
   palceholder.


CAN-2001-1376

Phase: Proposed (20020611)
Reference: BUGTRAQ:20011113 More problems with RADIUS (protocol and implementations)
Reference: URL:http://online.securityfocus.com/archive/1/239784
Reference: BUGTRAQ:20020305 SECURITY.NNOV: few vulnerabilities in multiple RADIUS implementations
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101537153021792&w=2
Reference: CERT:CA-2002-06
Reference: URL:http://www.cert.org/advisories/CA-2002-06.html
Reference: CERT-VN:VU#589523
Reference: URL:http://www.kb.cert.org/vuls/id/589523
Reference: SUSE:SuSE-SA:2002:013
Reference: URL:http://archives.neohapsis.com/archives/linux/suse/2002-q2/0362.html
Reference: CONECTIVA:CLA-2002:466
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000466
Reference: REDHAT:RHSA-2002:030
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-030.html
Reference: BID:3530
Reference: URL:http://www.securityfocus.com/bid/3530
Reference: XF:radius-message-digest-bo(7534)

Description:
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.

Votes:

   ACCEPT(5) Cole, Alderson, Green, Frech, Cox
   NOOP(2) Wall, Foat

CAN-2001-1377

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 SECURITY.NNOV: few vulnerabilities in multiple RADIUS implementations
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101537153021792&w=2
Reference: CERT-VN:VU#936683
Reference: URL:http://www.kb.cert.org/vuls/id/936683
Reference: CERT:CA-2002-06
Reference: URL:http://www.cert.org/advisories/CA-2002-06.html
Reference: FREEBSD:FreeBSD-SN-02:02
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:02.asc
Reference: REDHAT:RHSA-2002:030
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-030.html
Reference: SUSE:SuSE-SA:2002:013
Reference: URL:http://archives.neohapsis.com/archives/linux/suse/2002-q2/0362.html
Reference: CONECTIVA:CLA-2002:466
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000466
Reference: XF:radius-vendor-attribute-dos(8354)
Reference: URL:http://www.iss.net/security_center/static/8354.php
Reference: BID:4230
Reference: URL:http://www.securityfocus.com/bid/4230

Description:
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.

Votes:

   ACCEPT(5) Cole, Alderson, Green, Frech, Cox
   NOOP(2) Wall, Foat

CAN-2001-1379

Phase: Proposed (20020726)
Reference: BUGTRAQ:20010829 RUS-CERT Advisory 2001-08:01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99911895901812&w=2
Reference: VULNWATCH:20010829 [VulnWatch] RUS-CERT Advisory 2001-08:01
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2001-q3/0040.html
Reference: FREEBSD:FreeBSD-SA-02:03
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:03.mod_auth_pgsql.asc
Reference: CONECTIVA:CLA-2001:427
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000427
Reference: REDHAT:RHSA-2001:124
Reference: URL:http://rhn.redhat.com/errata/RHSA-2001-124.html
Reference: XF:apache-postgresql-authentication-module(7054)
Reference: URL:http://www.iss.net/security_center/static/7054.php
Reference: BID:3251
Reference: URL:http://online.securityfocus.com/bid/3251
Reference: BID:3253
Reference: XF:apache-postgresqlsys-authentication-module(7059)

Description:
The PostgreSQL authentication modules (1) mod_auth_pgsql 0.9.5, and (2) mod_auth_pgsql_sys 0.9.4, allow remote attackers to bypass authentication and execute arbitrary SQL via a SQL injection attack on the user name.

Votes:

   ACCEPT(4) Cole, Armstrong, Baker, Cox
   NOOP(2) Wall, Foat

CAN-2001-1384

Phase: Proposed (20020830)
Reference: BUGTRAQ:20011018 Flaws in recent Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100343090106914&w=2
Reference: REDHAT:RHSA-2001:129
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-129.html
Reference: REDHAT:RHSA-2001:130
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-130.html
Reference: SUSE:SuSE-SA:2001:036
Reference: URL:http://www.suse.de/de/support/security/2001_036_kernel_txt.html
Reference: IMMUNIX:IMNX-2001-70-035-01
Reference: URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-035-01
Reference: CALDERA:CSSA-2001-036.0
Reference: URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2001-036.0.txt
Reference: MANDRAKE:MDKSA-2001:079
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-079.php3
Reference: MANDRAKE:MDKSA-2001:082
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-082.php3
Reference: ENGARDE:ESA-20011019-02
Reference: URL:http://www.linuxsecurity.com/advisories/other_advisory-1650.html
Reference: HP:HPSBTL0112-003
Reference: URL:http://online.securityfocus.com/advisories/3713
Reference: BUGTRAQ:20011019 TSLSA-2001-0028
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100350685431610&w=2
Reference: BID:3447
Reference: URL:http://online.securityfocus.com/bid/3447
Reference: XF:linux-ptrace-race-condition(7311)
Reference: URL:http://www.iss.net/security_center/static/7311.php

Description:
ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp.

Votes:

   ACCEPT(7) Wall, Cole, Armstrong, Green, Baker, Frech, Cox
   NOOP(1) Foat

CAN-2001-1386

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010701 WFTPD v3.00 R5 Directory Traversal
Reference: URL:http://www.securityfocus.com/archive/1/194442
Reference: XF:ftp-lnk-directory-traversal(6760)
Reference: URL:http://www.iss.net/security_center/static/6760.php
Reference: BID:2957
Reference: URL:http://www.securityfocus.com/bid/2957

Description:
WFTPD 3.00 allows remote attackers to read arbitrary files by uploading a (link) file that ends in a ".lnk." extension, which bypasses WFTPD's check for a ".lnk" extension.

Votes:

   ACCEPT(3) Green, Baker, Frech
   MODIFY(1) Foat
   NOOP(3) Cole, Armstrong, Cox
   REVIEWING(1) Wall
Voter Comments:
 Foat> If a windows shortcut file (*.lnk) linked to a directory is uploaded,
   an ftp user would be3 able to have access to the directory link points by typing
   'cd <file>.lnk'. If an ftp user uploads a *.lnk file to a known file for which
   the user does not have access and then does a 'GET' on the link, the file will
   be downloaded.


CAN-2001-1387

Phase: Proposed (20020830)
Reference: REDHAT:RHSA-2001:144
Reference: URL:http://rhn.redhat.com/errata/RHSA-2001-144.html
Reference: CONFIRM:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=50500

Description:
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "--reject-with tcp-reset," which causes iptables to generate different responses than specified by the administrator, possibly leading to an information leak.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:iptables-iptablessave-information-leak(11116)
   XF:iptables-save-files-option(7489)


CAN-2001-1388

Phase: Proposed (20020830)
Reference: REDHAT:RHSA-2001:144
Reference: URL:http://rhn.redhat.com/errata/RHSA-2001-144.html
Reference: CONFIRM:http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=53325

Description:
iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:iptables-m-change-traffic(11117)
   XF:iptables-save-files-option(7489)


CAN-2001-1389

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010830 xinetd 2.3.0 audit status
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99913751525583&w=2
Reference: REDHAT:RHSA-2001:109
Reference: URL:http://rhn.redhat.com/errata/RHSA-2001-109.html
Reference: IMMUNIX:IMNX-2001-70-033-01
Reference: URL:http://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-033-01
Reference: ENGARDE:ESA-20011019-03
Reference: CONECTIVA:CLA-2001:416
Reference: MANDRAKE:MDKSA-2001:076
Reference: URL:http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-076.php3
Reference: BID:3257
Reference: URL:http://online.securityfocus.com/bid/3257

Description:
Multiple vulnerabilities in xinetd 2.3.0 and earlier, and additional variants until 2.3.3, may allow remote attackers to cause a denial of service or execute arbitrary code, primarily via buffer overflows or improper NULL termination.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:xinetd-multiple-bo(11150)


CAN-2001-1390

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:18
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-binfmtmisc-gain-privileges(11161)


CAN-2001-1391

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
off-by-one vulnerability in CPIA driver of Linux kernel before 2.2.19 allows users to modify kernel memory.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
Voter Comments:
 Frech> XF:linux-ptrace-modify-process(6080)
 Christey> fix typo: "off-by-one" should be "Off-by-one"


CAN-2001-1392

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
The Linux kernel before 2.2.19 does not have unregister calls for (1) CPUID and (2) MSR drivers, which could cause a DoS (crash) by unloading and reloading the drivers.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:Linux-msr-cpuid-dos(11163)


CAN-2001-1393

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Unknown vulnerability in classifier code for Linux kernel before 2.2.19 could result in denial of service (hang).

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:Linux-classifier-code-dos(11164)


CAN-2001-1394

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Signedness error in (1) getsockopt and (2) setsockopt for Linux kernel before 2.2.19 allows local users to cause a denial of service.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-getsockopt-setsockopt-dos(11165)


CAN-2001-1395

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with unknown impact.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-sockfilter(11166)


CAN-2001-1396

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-strnlen-user(11167)


CAN-2001-1397

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
The System V (SYS5) shared memory implementation for Linux kernel before 2.2.19 could allow attackers to modify recently freed memory.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-sys5-shm(11168)


CAN-2001-1398

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Masquerading code for Linux kernel before 2.2.19 does not fully check packet lengths in certain cases, which may lead to a vulnerability.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-masquerade-packet-bo(11169)


CAN-2001-1399

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Certain operations in Linux kernel before 2.2.19 on the x86 architecture copy the wrong number of bytes, which might allow attackers to modify memory, aka "User access asm bug on x86."

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-x86-asm-copy(11170)


CAN-2001-1400

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010405 Trustix Security Advisory #2001-0003 - kernel
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98653252326445&w=2
Reference: BUGTRAQ:20010409 PROGENY-SA-2001-01: execve()/ptrace() exploit in Linux kernels
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98684172109474&w=2
Reference: CONFIRM:http://www.linux.org.uk/VERSION/relnotes.2219.html
Reference: IMMUNIX:IMNX-2001-70-010-01
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98575345009963&w=2
Reference: CALDERA:CSSA-2001-012.0
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98637996127004&w=2
Reference: MANDRAKE:MDKSA-2001:037
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98759029811377&w=2
Reference: DEBIAN:DSA-047
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98741381506142&w=2
Reference: SUSE:SuSE-SA:2001:018
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99013830726309&w=2
Reference: CONECTIVA:CLA-2001:394
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=98775114228203&w=2
Reference: REDHAT:RHSA-2001:047
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-047.html

Description:
Unknown vulnerabilities in the UDP port allocation for Linux kernel before 2.2.19 could allow local users to cause a denial of service (deadlock).

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:linux-udp-port-dos(11171)


CAN-2001-1401

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010829 Security Advisory for Bugzilla v2.13 and older
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99912899900567
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=82781
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=39531
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=39524
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=39533
Reference: REDHAT:RHSA-2001:107
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-107.html
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=39526
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=39527
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=70189

Description:
Bugzilla before 2.14 does not properly restrict access to confidential bugs, which could allow Bugzilla users to bypass viewing permissions via modified bug id parameters in (1) process_bug.cgi, (2) show_activity.cgi, (3) showvotes.cgi, (4) showdependencytree.cgi, (5) showdependencygraph.cgi, (6) showattachment.cgi, or (7) describecomponents.cgi.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:bugzilla-describe-components(7058)
   XF:bugzilla-show-dependency-graph(7060)
   XF:bugzilla-show-dependency-tree(7061)
   XF:bugzilla-show-votes(7065)
   XF:bugzilla-show-activity(7066)
   XF:bugzilla-process-bug(7067)
   XF:bugzilla-show-attachment(7070)


CAN-2001-1402

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010829 Security Advisory for Bugzilla v2.13 and older
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99912899900567
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=38854
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=38855
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=87701
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=38859
Reference: REDHAT:RHSA-2001:107
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-107.html
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=39536
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=95235

Description:
Bugzilla before 2.14 does not properly escape untrusted parameters, which could allow remote attackers to conduct unauthorized activities via cross-site scripting (CSS) and possibly SQL injection attacks on (1) the product or output form variables for reports.cgi, (2) the voteon, bug_id, and user variables for showvotes.cgi, (3) an invalid email address in createaccount.cgi, (4) an invalid ID in showdependencytree.cgi, (5) invalid usernames and other fields in process_bug.cgi, and (6) error messages in buglist.cgi.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:bugzilla-create-account-crosssite(7062)
   XF:bugzilla-show-votes-crosssite(7063)
   XF:bugzilla-reports-crosssite(7064)
   XF:bugzilla-showdependencytree-xss(10482)
   XF:bugzilla-processbug-xss(10485)
   XF:bugzilla-buglist-displayerror-xss(10480)


CAN-2001-1403

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010829 Security Advisory for Bugzilla v2.13 and older
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99912899900567
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=15980
Reference: REDHAT:RHSA-2001:107
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-107.html

Description:
Bugzilla before 2.14 includes the username and password in URLs, which could allow attackers to gain privileges by reading the information from the web server logs, or by "shoulder-surfing" and observing the web browser's location bar.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:bugzilla-location-bar-passwords(10484)


CAN-2001-1404

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010829 Security Advisory for Bugzilla v2.13 and older
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99912899900567
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=74032
Reference: REDHAT:RHSA-2001:107
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-107.html

Description:
Bugzilla before 2.14 stores user passwords in plaintext and sends password requests in an email message, which could allow attackers to gain privileges.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Frech> XF:bugzilla-plaintext-passwords(10483)


CAN-2001-1405

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010829 Security Advisory for Bugzilla v2.13 and older
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=99912899900567
Reference: CONFIRM:http://bugzilla.mozilla.org/show_bug.cgi?id=54556
Reference: REDHAT:RHSA-2001:107
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-107.html

Description:
Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.

Votes:

   ACCEPT(6) Wall, Cole, Armstrong, Green, Baker, Cox
   MODIFY(1) Frech
   NOOP(1) Foat
Voter Comments:
 Cox> Right CD?
 Frech> XF:bugzilla-sanitycheck-dos(10481)


CAN-2001-1408

Phase: Proposed (20020830)
Reference: BUGTRAQ:20010705 Cobalt Cube Webmail directory traversal
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-07/0092.html
Reference: BUGTRAQ:20010818 Cobalt update for my Webmail issue.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-08/0245.html
Reference: XF:cobalt-qube-directory-traversal(6805)
Reference: URL:http://xforce.iss.net/static/6805.php

Description:
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbitrary files via a .. (dot dot) in the mailbox parameter.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(5) Wall, Foat, Cole, Armstrong, Cox

CAN-2001-1409

Phase: Assigned (20030611)
Reference: CONFIRM:http://groups.google.com/groups?selm=20010829121505.A16004%40compusol.com.au
Reference: REDHAT:RHSA-2003:067
Reference: URL:http://www.redhat.com/support/errata/RHSA-2003-067.html

Description:
dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.

Votes:







CAN-2001-1410

Phase: Assigned (20030715)
Reference: BUGTRAQ:20011021 Javascript in IE may spoof the whole screen
Reference: URL:http://www.securityfocus.com/archive/1/221883
Reference: MISC:http://www.guninski.com/popspoof.html
Reference: BUGTRAQ:20030713 IE chromeless window vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=105820229407274&w=2
Reference: MISC:http://www.doxdesk.com/personal/posts/bugtraq/20030713-ie/
Reference: BUGTRAQ:20030715 Internet Explorer Full-Screen mode threats
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=105829174431769&w=2
Reference: MISC:http://www.systemintegra.com/ie-fullscreen/
Reference: XF:ie-javascript-spoof-dialog(7313)
Reference: URL:http://xforce.iss.net/xforce/xfdb/7313
Reference: BID:3469
Reference: URL:http://www.securityfocus.com/bid/3469

Description:
Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via social engineering.

Votes:







CAN-2002-0001

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20020101 [Announce] SECURITY: mutt-1.2.5.1 and mutt-1.3.25 released.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100994648918287&w=2
Reference: CONFIRM:http://www.mutt.org/announce/mutt-1.2.5.1-1.3.25.html
Reference: DEBIAN:DSA-096
Reference: URL:http://www.debian.org/security/2002/dsa-096
Reference: REDHAT:RHSA-2002:003
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-003.html
Reference: SUSE:SuSE-SA:2002:001
Reference: URL:http://www.suse.de/de/security/2002_001_mutt_txt.html
Reference: CONECTIVA:CLA-2002:449
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000449
Reference: FREEBSD:FreeBSD-SA-02:04
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:04.mutt.asc
Reference: HP:HPSBTL0201-011
Reference: URL:http://online.securityfocus.com/advisories/3778
Reference: CALDERA:CSSA-2002-002.0
Reference: URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-002.0.txt
Reference: BID:3774
Reference: URL:http://www.securityfocus.com/bid/3774

Description:
Vulnerability in RFC822 address parser in mutt before 1.2.5.1 and mutt 1.3.x before 1.3.25 allows remote attackers to execute arbitrary commands via an improperly terminated comment or phrase in the address list.

Votes:

   ACCEPT(4) Baker, Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
Voter Comments:
 Christey> I need to review this for accuracy; is it just a buffer
   overflow?  See Mark Cox' comments in his "Chinese Whisper"
   article.
 Frech> XF:mutt-address-handling-bo(7759)
 Christey> See Caldera advisory for a good, short description of the
   issue.
   BID:3774
   URL:http://www.securityfocus.com/bid/3774
   SUSE:SuSE-SA:2002:001
   URL:http://www.suse.de/de/support/security/2002_001_mutt_txt.html
   CONECTIVA:CLA-2002:449
   DEBIAN:DSA-096
   FREEBSD:FreeBSD-SA-02:04
   HP:HPSBTL0201-011
   URL:http://online.securityfocus.com/advisories/3778
   CALDERA:CSSA-2002-002.0
   URL:http://www.calderasystems.com/support/security/advisories/CSSA-2002-002.0.txt


CAN-2002-0008

Phase: Proposed (20020131)
Reference: BUGTRAQ:20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-01/0034.html
Reference: CONFIRM:http://www.bugzilla.org/security2_14_1.html
Reference: MISC:http://bugzilla.mozilla.org/show_bug.cgi?id=108385
Reference: MISC:http://bugzilla.mozilla.org/show_bug.cgi?id=108516

Description:
Bugzilla before 2.14.1 allows remote attackers to (1) spoof a user comment via an HTTP request process_bug.cgi using the "who" parameter, instead of the Bugzilla_login cookie, or (2) post a bug as another user by modifying the reporter parameter to enter_bug.cgi, which is passed to post_bug.cgi.

Votes:

   ACCEPT(3) Baker, Cole, Green
   MODIFY(1) Frech
   NOOP(2) Wall, Foat
Voter Comments:
 Frech> XF:bugzilla-processbug-comment-spoofing(7805)
   XF:bugzilla-postbug-report-spoofing(7804)


CAN-2002-0010

Phase: Proposed (20020131)
Reference: BUGTRAQ:20020105 Security Advisory for Bugzilla v2.15 (cvs20020103) and older
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-01/0034.html
Reference: BUGTRAQ:20020106 Inproper input validation in Bugzilla <=2.14 - exploit
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-01/0052.html
Reference: CONFIRM:http://www.bugzilla.org/security2_14_1.html
Reference: MISC:http://bugzilla.mozilla.org/show_bug.cgi?id=108812
Reference: MISC:http://bugzilla.mozilla.org/show_bug.cgi?id=108822
Reference: MISC:http://bugzilla.mozilla.org/show_bug.cgi?id=108821
Reference: MISC:http://bugzilla.mozilla.org/show_bug.cgi?id=109690
Reference: MISC:http://bugzilla.mozilla.org/show_bug.cgi?id=109679
Reference: MISC:http://www.bugzilla.org/bugzilla2.14to2.14.1.patch

Description:
Bugzilla before 2.14.1 allows remote attackers to inject arbitrary SQL code and create files or gain privileges via (1) the sql parameter in buglist.cgi, (2) invalid field names from the "boolean chart" query in buglist.cgi, (3) the mybugslink parameter in userprefs.cgi, (4) a malformed bug ID in the buglist parameter in long_list.cgi, and (5) the value parameter in editusers.cgi, which allows groupset privileges to be modified by attackers with blessgroupset privileges.

Votes:

   ACCEPT(3) Baker, Cole, Green
   NOOP(2) Wall, Foat
   REVIEWING(1) Frech
Voter Comments:
 Frech> XF:bugzilla-buglist-modify-sql(7807)
   XF:bugzilla-userprefs-change-groupset(7809)
   XF:bugzilla-longlist-modify-sql(7811)
   XF:bugzilla-editusers-change-groupset(7814)
   XF:bugzilla-buglist-sql-logic(7813)


CAN-2002-0012

Phase: Proposed (20020315)
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html
Reference: CERT:CA-2002-03
Reference: URL:http://www.cert.org/advisories/CA-2002-03.html
Reference: ISS:20020212 PROTOS Remote SNMP Attack Tool
Reference: URL:http://www.iss.net/security_center/alerts/advise110.php
Reference: CERT-VN:VU#107186
Reference: URL:http://www.kb.cert.org/vuls/id/107186
Reference: REDHAT:RHSA-2001:163
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-163.html
Reference: CALDERA:CSSA-2002-SCO.4
Reference: SGI:20020201-01-A
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20020201-01-A
Reference: MS:MS02-006
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS02-006.asp

Description:
Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.

Votes:

   ACCEPT(6) Ziese, Jones, Wall, Foat, Cole, Green
   REVIEWING(1) Christey
Voter Comments:
 Christey> This candidate is at a higher level of abstraction (more
   general) than most other candidates.  CVE's content
   decisions suggest that we should provide different candidates
   for each implementation and type of bug that is affected by
   the PROTOS suite.
   
   However, as of this writing (Feb 12, 2002), there is
   insufficient information to assign the proper number of
   candidates.  This high-level candidate will serve as a
   "catch-all," but we will be assigning lower-level (more
   specific) candidates when there is more information.
   
   Due to the size and extent of this problem, it is better to
   have a high-level candidate than no candidate at all.
 Ziese> ACKNOWLEDGED-BY-VENDOR
 Christey> DEBIAN:DSA-111
   MANDRAKE:MDKSA-2002:014
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> CALDERA:CSSA-2002-004.0
 Christey> Consider adding BID:4088
 Christey> ADDREF SGI:20020404-01-P, which discusses the "hpsnmpd" daemon.
 Christey> COMPAQ:SSRT0799
   CONECTIVA:CLA-2002:462
   BID:4088
   DEBIAN:DSA-111
   HP:HPSBUX0202-184
   URL:http://online.securityfocus.com/advisories/4032
   CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities
   CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities for Cisco Non-IOS Products
   MANDRAKE:MDKSA-2002:014
   FREEBSD:FreeBSD-SA-02:11
 Christey> SUSE:SuSE-SA:2002:012
   
   Should also mention ucd-snmp package by name.
   BUGTRAQ:20020824 NOVL-2002-2961546 - SNMPv1 Trap and Request Handling Vulnerabilities
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-08/0295.html
   HP:HPSBMP0206-015
   URL:http://archives.neohapsis.com/archives/hp/2002-q4/0010.html
   CALDERA:CSSA-2002-SCO.25
   URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0024.html
   CALDERA:CSSA-2002-004.1
   URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2002-004.1
   BUGTRAQ:20020227 nCipher Security Advisory #2: SNMP vulnerabilities
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-02/0353.html


CAN-2002-0013

Phase: Proposed (20020315)
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html
Reference: CERT:CA-2002-03
Reference: URL:http://www.cert.org/advisories/CA-2002-03.html
Reference: ISS:20020212 PROTOS Remote SNMP Attack Tool
Reference: URL:http://www.iss.net/security_center/alerts/advise110.php
Reference: CERT-VN:VU#854306
Reference: URL:http://www.kb.cert.org/vuls/id/854306
Reference: REDHAT:RHSA-2001:163
Reference: URL:http://www.redhat.com/support/errata/RHSA-2001-163.html
Reference: CALDERA:CSSA-2002-SCO.4
Reference: SGI:20020201-01-A
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20020201-01-A
Reference: MS:MS02-006
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS02-006.asp

Description:
Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.

Votes:

   ACCEPT(6) Ziese, Jones, Wall, Foat, Cole, Green
   REVIEWING(1) Christey
Voter Comments:
 Christey> This candidate is at a higher level of abstraction (more
   general) than most other candidates.  CVE's content
   decisions suggest that we should provide different candidates
   for each implementation and type of bug that is affected by
   the PROTOS suite.
   
   However, as of this writing (Feb 12, 2002), there is
   insufficient information to assign the proper number of
   candidates.  This high-level candidate will serve as a
   "catch-all," but we will be assigning lower-level (more
   specific) candidates when there is more information.
   
   Due to the size and extent of this problem, it is better to
   have a high-level candidate than no candidate at all.
 Christey> BID:4089
 Christey> DEBIAN:DSA-111
   MANDRAKE:MDKSA-2002:014
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> CALDERA:CSSA-2002-004.0
 Christey> ADDREF SGI:20020404-01-P, which discusses the "hpsnmpd" daemon.
 Christey> COMPAQ:SSRT0799
   CONECTIVA:CLA-2002:462
   DEBIAN:DSA-111
   HP:HPSBUX0202-184
   URL:http://online.securityfocus.com/advisories/4032
   CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities
   CISCO:20020212 Malformed SNMP Message-Handling Vulnerabilities for Cisco Non-IOS Products
   MANDRAKE:MDKSA-2002:014
   FREEBSD:FreeBSD-SA-02:11
 Christey> SUSE:SuSE-SA:2002:012
   
   Should also mention ucd-snmp package by name.
   BUGTRAQ:20020824 NOVL-2002-2961546 - SNMPv1 Trap and Request Handling Vulnerabilities
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-08/0295.html
   HP:HPSBMP0206-015
   URL:http://archives.neohapsis.com/archives/hp/2002-q4/0010.html
   CALDERA:CSSA-2002-SCO.25
   URL:http://archives.neohapsis.com/archives/linux/caldera/2002-q2/0024.html
   CALDERA:CSSA-2002-004.1
   URL:ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2002-004.1
   BUGTRAQ:20020227 nCipher Security Advisory #2: SNMP vulnerabilities
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-02/0353.html


CAN-2002-0015

Phase: Assigned (20020111)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0016

Phase: Assigned (20020111)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0019

Phase: Assigned (20020114)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0029

Phase: Proposed (20030317)
Reference: CONFIRM:http://www.isc.org/products/BIND/bind-security.html
Reference: CERT:CA-2002-31
Reference: URL:http://www.cert.org/advisories/CA-2002-31.html
Reference: CERT-VN:VU#844360
Reference: URL:http://www.kb.cert.org/vuls/id/844360
Reference: NETBSD:NetBSD-SA2002-028
Reference: URL:ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2002-028.txt.asc
Reference: SGI:20021201-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20021201-01-P
Reference: XF:bind-dns-libresolv-bo(10624)
Reference: URL:http://www.iss.net/security_center/static/10624.php
Reference: BID:6186
Reference: URL:http://www.securityfocus.com/bid/6186

Description:
Buffer overflows in the DNS stub resolver library in ISC BIND 4.9.2 through 4.9.10, and other derived libraries such as BSD libc and GNU glibc, allow remote attackers to execute arbitrary code via DNS server responses that trigger the overflow in the (1) getnetbyname, or (2) getnetbyaddr functions, aka "LIBRESOLV: buffer overrun" and a different vulnerability than CAN-2002-0684.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(1) Wall
   REVIEWING(1) Cox

CAN-2002-0030

Phase: Assigned (20020116)
Reference: FULLDISC:20030324 Vulnerability (critical): Digital signature for Adobe Acrobat/Reader plug-in can be forged
Reference: URL:http://lists.netsys.com/pipermail/full-disclosure/2003-March/004612.html
Reference: VULNWATCH:20030324 Vulnerability (critical): Digital signature for Adobe Acrobat/Reader plug-in can be forged
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0148.html
Reference: CERT-VN:VU#549913
Reference: URL:http://www.kb.cert.org/vuls/id/549913
Reference: CONFIRM:http://www.kb.cert.org/vuls/id/JSHA-5EZQGZ

Description:
The digital signature mechanism for the Adobe Acrobat PDF viewer only verifies the PE header of executable code for a plug-in, which can allow attackers to execute arbitrary code in certified mode by making the plug-in appear to be signed by Adobe.

Votes:







CAN-2002-0031

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020527 Yahoo Messenger - Multiple Vulnerabilities
Reference: URL:http://online.securityfocus.com/archive/1/274223
Reference: CERT:CA-2002-16
Reference: URL:http://www.cert.org/advisories/CA-2002-16.html
Reference: CERT-VN:VU#137115
Reference: URL:http://www.kb.cert.org/vuls/id/137115
Reference: BID:4837
Reference: URL:http://www.securityfocus.com/bid/4837

Description:
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend.

Votes:

   ACCEPT(4) Baker, Wall, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) Cox, Foat, Christey
Voter Comments:
 Christey> XF:yahoo-messenger-ymsgr-bo(9183)
   URL:http://www.iss.net/security_center/static/9183.php
 Frech> XF:yahoo-messenger-ymsgr-bo(9183)


CAN-2002-0034

Phase: Assigned (20020116)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0035

Phase: Assigned (20020116)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0036

Phase: Proposed (20030317)
Reference: CONFIRM:http://web.mit.edu/kerberos/www/advisories/MITKRB5-SA-2003-001-multiple.txt
Reference: CERT-VN:VU#587579
Reference: URL:http://www.kb.cert.org/vuls/id/587579

Description:
Integer signedness error in MIT Kerberos V5 ASN.1 decoder allows remote attackers to cause a denial of service via a large unsigned data element length, which is later used as a negative value.

Votes:

   ACCEPT(3) Baker, Wall, Cole
   MODIFY(2) Frech, Cox
   NOOP(1) Christey
Voter Comments:
 Cox> This is fixed in krb5 version 1.2.5
 Cox> Addref RHSA-2003:051
 Cox> Addref REDHAT:RHSA-2003:052
 Christey> MANDRAKE:MDKSA-2003:043
   (as suggested by Vincent Danen of Mandrake)
 Frech> XF:kerberos-kdc-neglength-bo(11190)


CAN-2002-0037

Phase: Modified (20030319-01)
Reference: CERT-VN:VU#657899
Reference: URL:http://www.kb.cert.org/vuls/id/657899
Reference: XF:lotus-domino-nsfdbreadobject(10095)
Reference: URL:http://www.iss.net/security_center/static/10095.php

Description:
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call that directly accesses the object.

Votes:

   ACCEPT(3) Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(4) Cox, Foat, Armstrong, Christey
Voter Comments:
 Christey> Need to find some references for these... probably in
   the CERT/CC vulnerability notes.
 Frech> XF:lotus-domino-nsfdbreadobject(10095)
   http://www.kb.cert.org/vuls/id/657899
   CONFIRM:
   http://www-1.ibm.com/support/docview.wss?rs=1&org=sims&doc=CCA46CF459B
   A6E4A85256AE3007C92C1
 Christey> Is this the same issue here?
   BUGTRAQ:20011217 Lotus Notes: File attachments may be extracted regardless of document security
   URL:http://archives.neohapsis.com/archives/bugtraq/2001-09/0147.html


CAN-2002-0039

Phase: Proposed (20020502)
Reference: SGI:20020306-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20020306-01-P

Description:
rpcbind in SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows remote attackers to cause a denial of service (crash) via malformed RPC packets with invalid lengths.

Votes:

   ACCEPT(2) Cole, Green
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Armstrong
   RECAST(3) Baker, Levy, Christey
Voter Comments:
 Christey> CAN-2002-0039 (SGI rpcbind) is the same problem as
   CAN-2001-1124 (HP rpcbind).  These 2 candidates need to be
   merged.
 Christey> Consider adding BID:4386
 Christey> XF:irix-invalid-rpc-dos(8668)
   URL:http://www.iss.net/security_center/static/8668.php
   BID:4386
   URL:http://www.securityfocus.com/bid/4386
 Levy> BID 4386 will be merged into BID 3400.
 Frech> XF:irix-invalid-rpc-dos(8668)


CAN-2002-0041

Phase: Proposed (20020502)
Reference: SGI:20020401-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20020401-01-P

Description:
Vulnerability in Mail for SGI IRIX 6.5 through 6.5.15f, and possibly earlier versions, allows local and remote attackers to cause a core dump.

Votes:

   ACCEPT(3) Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Frech> XF:irix-mail-core-dump(8835)


CAN-2002-0048

Phase: Modified (20020817-01)
Reference: SUSE:SuSE-SA:2002:004
Reference: URL:http://lists.suse.com/archives/suse-security-announce/2002-Jan/0003.html
Reference: DEBIAN:DSA-106
Reference: URL:http://www.debian.org/security/2002/dsa-106
Reference: MANDRAKE:MDKSA-2002:009
Reference: URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-009.php
Reference: REDHAT:RHSA-2002:018
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-018.html
Reference: BUGTRAQ:20020128 TSLSA-2002-0025 - rsync
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101223214906963&w=2
Reference: BUGTRAQ:20020127 rsync-2.5.2 has security fix (was: Re: [RHSA-2002:018-05] New rsync packages available)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101223603321315&w=2
Reference: CONECTIVA:CLA-2002:458
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000458
Reference: ENGARDE:ESA-20020125-004
Reference: URL:http://www.linuxsecurity.com/advisories/other_advisory-1853.html
Reference: CALDERA:CSSA-2002-003.0
Reference: URL:http://www.caldera.com/support/security/advisories/CSSA-2002-003.0.txt
Reference: FREEBSD:FreeBSD-SA-02:10
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:10.rsync.asc
Reference: HP:HPSBTL0201-022
Reference: URL:http://online.securityfocus.com/advisories/3839
Reference: XF:linux-rsync-root-access(7993)
Reference: URL:http://www.iss.net/security_center/static/7993.php
Reference: BID:3958
Reference: URL:http://online.securityfocus.com/bid/3958

Description:
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other versions allow remote attackers to cause a denial of service and execute arbitrary code in the rsync client or server.

Votes:

   ACCEPT(4) Baker, Wall, Cole, Green
   MODIFY(1) Frech
   NOOP(2) Foat, Christey
Voter Comments:
 Frech> XF:linux-rsync-root-access(7993)
 Christey> CALDERA:CSSA-2002-003.0
 Christey> Consider adding BID:3958


CAN-2002-0053

Phase: Proposed (20020315)
Reference: MISC:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0012
Reference: MISC:http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0013
Reference: MISC:http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/index.html
Reference: MS:MS02-006
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS02-006.asp
Reference: CERT:CA-2002-03
Reference: URL:http://www.cert.org/advisories/CA-2002-03.html
Reference: CERT-VN:VU#854306
Reference: URL:http://www.kb.cert.org/vuls/id/854306
Reference: CERT-VN:VU#107186
Reference: URL:http://www.kb.cert.org/vuls/id/107186

Description:
Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or merged with other candidates. This and other PROTOS-related candidates, especially CAN-2002-0012 and CAN-2002-0013, will be updated when more accurate information is available.

Votes:

   ACCEPT(5) Ziese, Wall, Foat, Cole, Green

CAN-2002-0056

Phase: Proposed (20020315)
Reference: MS:MS02-007
Reference: URL:http://www.microsoft.com/technet/security/bulletin/MS02-007.asp
Reference: BUGTRAQ:20020219 MSDE, Sql Server 7 & 2000 Adhoc Heterogenous Queries Buffer Overflow and DOS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101422555428036&w=2
Reference: VULN-DEV:20020219 MSDE, Sql Server 7 & 2000 Adhoc Heterogenous Queries Buffer Overflow and DOS
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=101413924631329&w=2

Description:
Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.

Votes:

   ACCEPT(5) Ziese, Wall, Foat, Cole, Green
   MODIFY(1) Christey
Voter Comments:
 Christey> Consider adding BID:4135
 CHANGE> [Christey changed vote from NOOP to MODIFY]
 Christey> ADDREF BID:4135
   XF:mssql-oledb-adhoc-bo(8243)
   URL:http://www.iss.net/security_center/static/8243.php


CAN-2002-0058

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020305 Java HTTP proxy vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101534535304228&w=2
Reference: SUN:00216
Reference: URL:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/216
Reference: MS:MS02-013
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-013.asp

Description:
Vulnerability in Java Runtime Environment (JRE) allows remote malicious web sites to hijack or sniff a web client's sessions, when an HTTP proxy is being used, via a Java applet that redirects the session to another server, as seen in (1) Netscape 6.0 through 6.1 and 4.79 and earlier, (2) Microsoft VM build 3802 and earlier as used in Internet Explorer 4.x and 5.x, and possibly other implementations that use vulnerable versions of SDK or JDK.

Votes:

   ACCEPT(5) Ziese, Wall, Foat, Cole, Green
   NOOP(1) Christey
Voter Comments:
 Christey> Consider adding BID:4228
 Christey> XF:java-vm-session-hijacking(8351)
   URL:http://www.iss.net/security_center/static/8351.php
   HP:HPSBUX0203-186
   URL:http://online.securityfocus.com/advisories/3930
   BID:4228
   URL:http://www.securityfocus.com/bid/4228
   
   Need to add "HttpURLConnection" to description (commonly used word)
 Christey> ADDREF COMPAQ:SSRT0822
 Christey> COMPAQ:SSRT0822
 Christey> SGI:20020807-01-I
   URL:ftp://patches.sgi.com/support/free/security/advisories/20020807-01-I
 Christey> BID:4228
   URL:http://www.securityfocus.com/bid/4228


CAN-2002-0077

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020113 Internet Explorer Pop-Up OBJECT Tag Bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101103188711920&w=2
Reference: MS:MS02-015
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-015.asp

Description:
Microsoft Internet Explorer 5.01, 5.5 and 6.0 treats objects invoked on an HTML page with the codebase property as part of Local Computer zone, which allows remote attackers to invoke executables present on the local system through objects such as the popup object, aka the "Local Executable Invocation via Object tag" vulnerability.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(2) Cox, Christey
Voter Comments:
 Christey> Consider adding BID:3867
 Christey> According to Microsoft, the fix for this issue also addresses:
   BUGTRAQ:20020227 IE execution of arbitrary commands without Active Scripting or ActiveX (GM#001-IE)
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101496184505815&w=2
   
   Need to add this reference (and/or double-check to make sure
   this is the right issue) and consider modifying the
   description accordingly, though on the surface there
   does not appear to be any close relation, since the
   GreyMagic bug deals with Data Source (DSO)
   for Data Binding with the dataFormatAs attribute set to HTML, then
   using innerHTML for script injection.
 Frech> XF:ie-codebase-execute-programs(7941)


CAN-2002-0084

Phase: Modified (20020513)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO4198.asp
Reference: CERT-VN:VU#161931
Reference: URL:http://www.kb.cert.org/vuls/id/161931
Reference: CONFIRM:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309
Reference: BUGTRAQ:20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability
Reference: URL:http://cert.uni-stuttgart.de/archive/bugtraq/2002/04/msg00416.html

Description:
Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.

Votes:

   ACCEPT(3) Wall, Cole, Green
   NOOP(3) Ziese, Foat, Christey
Voter Comments:
 Christey> CERT:CA-2002-11
   CERT-VN:VU#635811
   AUSCERT:AA-2002.01
   URL:http://www.auscert.org.au/Information/Advisories/advisory/AA-2002.01.txt
 Christey> BUGTRAQ:20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability
   URL:http://online.securityfocus.com/archive/1/270135
 Christey> ADDREF CERT-VN:VU#161931
   ADDREF BUGTRAQ:20020429 eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mount file buffer overflow vulnerability
   ADDREF CONFIRM:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44309
   
   Note: this is a different vulnerability than CAN-2002-0033.
   However, if there are different patches for the 2 issues, then
   they may need to be merged per CD:SF-LOC.
   
   Add that the affected function is fscache_setup()
 Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4198 - Sun Solaris cachefsd mou nt file buffer overflow vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0048.html
   BID:4631
   URL:http://www.securityfocus.com/bid/4631


CAN-2002-0085

Phase: Proposed (20020315)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO4197.asp

Description:
cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.

Votes:

   ACCEPT(3) Wall, Cole, Green
   NOOP(3) Ziese, Foat, Christey
Voter Comments:
 Christey> BUGTRAQ:20020429 eSecurityOnline Security Advisory 4197 - Sun Solaris cachefsd denial of service vulnerability
   URL:http://online.securityfocus.com/archive/1/270134
   BID:4634
   URL:http://online.securityfocus.com/bid/4634


CAN-2002-0086

Phase: Proposed (20020315)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO4126.asp
Reference: MISC:http://www.esecurityonline.com/advisories/eSO4124.asp

Description:
Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.

Votes:

   ACCEPT(3) Foat, Cole, Green
   MODIFY(1) Balinsky
   NOOP(3) Ziese, Wall, Christey
Voter Comments:
 Christey> Consider adding BID:4317
 Christey> Consider adding BID:4319
 CHANGE> [Balinsky changed vote from ACCEPT to MODIFY]
 Balinsky> Should say 5.0.4 through 5.0.9 (not including version 5.0.9a, which includes the fix)
 Balinsky> Additional Modification: Should say "Linux and Solaris"
 CHANGE> [Foat changed vote from NOOP to ACCEPT]
 Christey> CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=92579CFD6F92B39A85256B7D006AC89B
   CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=D52DF997ABFFFC8385256B7D0062AD5C
   VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4126 - Lotus Domino bindsock Notes_ExecDirectory buffer overflow vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0046.html
   VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4124 - Lotus Domino bindsock PATH buffer overflow vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0044.html


CAN-2002-0087

Phase: Proposed (20020315)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO4125.asp

Description:
bindsock in Lotus Domino 5.07 on Solaris allows local users to create arbitrary files via a symlink attack on temporary files.

Votes:

   ACCEPT(4) Balinsky, Foat, Cole, Green
   NOOP(3) Ziese, Wall, Christey
Voter Comments:
 Christey> Consider adding BID:4318
 CHANGE> [Foat changed vote from NOOP to ACCEPT]
 Christey> CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=463&rt=0&org=sims&doc=93B3ED336951525385256B7D006A3CE3
   VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4125 - Lotus Domino bindsock arbitrary file creation vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0045.html


CAN-2002-0088

Phase: Proposed (20020315)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO4123.asp

Description:
Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.

Votes:

   ACCEPT(3) Wall, Cole, Green
   NOOP(3) Ziese, Foat, Christey
Voter Comments:
 Christey> BUGTRAQ:20020429 eSecurityOnline Security Advisory 4123 - Sun Solaris admintool media installation path buffer overflow vulnerability
   URL:http://online.securityfocus.com/archive/1/270137
   BID:4632
   URL:http://www.securityfocus.com/bid/4632
   VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 4123 - Sun Solaris admintool me dia installation path buffer overflow vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0043.html
 Christey> CONFIRM:http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fsalert%2F44541&zone_32=category%3Asecurity%20admintool
   
   (thanks to Matt Wojcik for this info)


CAN-2002-0089

Phase: Proposed (20020315)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO2397.asp

Description:
Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.

Votes:

   ACCEPT(3) Ziese, Cole, Green
   NOOP(3) Wall, Foat, Christey
Voter Comments:
 Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2397 - Sun Solaris admintool -d and PRODVERS buffer overflow vulnerabilities
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0035.html
   BUGTRAQ:20020429 eSecurityOnline Security Advisory 2397 - Sun Solaris admintool -d and PRODVERS buffer overflow vulnerabilities
   URL:http://online.securityfocus.com/archive/1/270122
   BID:4624
   URL:http://www.securityfocus.com/bid/4624
 Christey> CONFIRM:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F27353


CAN-2002-0090

Phase: Interim (20030326)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO3761.asp
Reference: VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 3761 - Sun Solaris lbxproxy display name buffer overflow vulnerability
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0041.html
Reference: BUGTRAQ:20020429 eSecurityOnline Security Advisory 3761 - Sun Solaris lbxproxy display name buffer overflow vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/270149
Reference: CONFIRM:http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert%2F44842&zone_32=category%3Asecurity%20lbxproxy
Reference: CERT-VN:VU#188507
Reference: URL:http://www.kb.cert.org/vuls/id/188507
Reference: BID:4633
Reference: URL:http://www.securityfocus.com/bid/4633
Reference: XF:solaris-lbxproxy-display-bo(8958)
Reference: URL:http://www.iss.net/security_center/static/8958.php

Description:
Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.

Votes:

   ACCEPT(4) Balinsky, Wall, Cole, Green
   NOOP(3) Ziese, Foat, Christey
Voter Comments:
 Balinsky> Patch at http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F108652
   resolves an lbxproxy buffer overflow.
 Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 3761 - Sun Solaris lbxproxy display name buffer overflow vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0041.html
   BUGTRAQ:20020429 eSecurityOnline Security Advisory 3761 - Sun Solaris lbxproxy display name buffer overflow vulnerability
   URL:http://online.securityfocus.com/archive/1/270149
   BID:4633
   URL:http://www.securityfocus.com/bid/4633


CAN-2002-0091

Phase: Proposed (20020315)
Reference: MISC:http://www.esecurityonline.com/advisories/eSO2408.asp

Description:
Multiple CGI scripts in CIDER SHADOW 1.5 and 1.6 allows remote attackers to execute arbitrary commands via certain form fields.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(4) Ziese, Wall, Foat, Christey
Voter Comments:
 Christey> VULNWATCH:20020429 [VulnWatch] eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0038.html
   BID:4625
   URL:http://www.securityfocus.com/bid/4625
   BUGTRAQ:20020429 eSecurityOnline Security Advisory 2408 - CIDER SHADOW CGI
   URL:http://online.securityfocus.com/archive/1/270111


CAN-2002-0093

Phase: Proposed (20020830)
Reference: COMPAQ:SSRT0794
Reference: URL:http://archives.neohapsis.com/archives/compaq/2002-q3/0009.html
Reference: XF:tru64-ipcs-bo(9613)
Reference: URL:http://www.iss.net/security_center/static/9613.php
Reference: BID:5241
Reference: URL:http://www.securityfocus.com/bid/5241

Description:
Buffer overflow in ipcs for HP Tru64 UNIX 4.0f through 5.1a may allow attackers to execute arbitrary code, a different vulnerability than CAN-2001-0423.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Frech> Correction:
   URL:http://archives.neohapsis.com/archives/compaq/2002-q3/0010.html


CAN-2002-0099

Phase: Modified (20020911-01)
Reference: BUGTRAQ:20020105 Savant Webserver Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101027722904078&w=2
Reference: NTBUGTRAQ:20020109 Savant Webserver Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101062823305479&w=2
Reference: BID:3788
Reference: URL:http://online.securityfocus.com/bid/3788
Reference: XF:savant-long-parameter-bo(7786)
Reference: URL:http://www.iss.net/security_center/static/7786.php

Description:
Buffer overflow in Michael Lamont Savant Web Server 3.0 allows remote attackers to cause a denial of service (crash) via a long HTTP request to the cgi-bin directory in which the CGI program name contains a large number of . (dot) characters.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(4) Ziese, Wall, Foat, Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> Should CAN-2002-0099 and/or CAN-2001-0433 be MERGED with
   CVE-2000-0641?  All describe slightly different overflows
   that, perhaps, should be merged according to CD:SF-LOC.
   It depends on which versions are affected, which would require
   some vendor acknowledgement or consultation.
   
   A vague changelog for version 3.1 at
   http://sourceforge.net/project/shownotes.php?release_id=75333 says
   "security fixes" but it's not clear *which* security fixes
   were made.
   
   The description for CVE-2000-0641 is slightly incorrect.  The
   exploit is clearly due to a large number of headers, not
   arguments to the GET request itself.  So, CVE-2000-0641
   clearly overlaps with CAN-2001-0433.
   
   The exploit for CAN-2001-0433 also doesn't really have
   anything to do with a "cgi-test.pl" program (which isn't in
   the distribution).  The discloser simply used that as an
   example program of a long request.
 Christey> Modify description so that overflow is described as being
   part of the CGI module (so it appears).
   
   Also, Tamer Sahin confirmed via email (9/11/02) that the
   problem was explicitly exhibited using a large number of
   . (dot) characters.


CAN-2002-0100

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020106 AOLserver 3.4.2 Unauthorized File Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101038936305397&w=2
Reference: NTBUGTRAQ:20020109 AOLserver 3.4.2 Unauthorized File Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101062823205474&w=2
Reference: BID:3791
Reference: URL:http://online.securityfocus.com/bid/3791
Reference: XF:aolserver-protected-file-access(7825)
Reference: URL:http://www.iss.net/security_center/static/7825.php

Description:
AOL AOLserver 3.4.2 Win32 allows remote attackers to bypass authentication and read password-protected files via a URL that directly references the file.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(4) Ziese, Wall, Foat, Cole

CAN-2002-0101

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020106 Internet Explorer Javascript Modeless Popup Local Denial of Service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101039104608083&w=2
Reference: BID:3789
Reference: URL:http://online.securityfocus.com/bid/3789
Reference: XF:ie-modeless-dialog-dos(7826)
Reference: URL:http://www.iss.net/security_center/static/7826.php

Description:
Microsoft Internet Explorer 6.0 and earlier allows local users to cause a denial of service via an infinite loop for modeless dialogs showModelessDialog, which causes CPU usage while the focus for the dialog is not released.

Votes:

   ACCEPT(4) Frech, Ziese, Foat, Green
   NOOP(1) Cole
   REVIEWING(1) Wall
Voter Comments:
 Ziese> would seem appropriate as a CVE entry.
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-2002-0102

Phase: Proposed (20020315)
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/webcache2.pdf
Reference: BID:3760
Reference: URL:http://online.securityfocus.com/bid/3760
Reference: BID:3762
Reference: URL:http://online.securityfocus.com/bid/3762

Description:
Oracle9iAS Web Cache 2.0.0.x allows remote attackers to cause a denial of service via (1) a request to TCP ports 1100, 4000, 4001, and 4002 with a large number of null characters, and (2) a request to TCP port 4000 with a large number of "." characters.

Votes:

   ACCEPT(4) Ziese, Foat, Cole, Green
   MODIFY(1) Frech
   NOOP(1) Wall
Voter Comments:
 Frech> XF:oracle-appserver-admin-dos(7310)
   XF:oracle-appserver-null-dos(7765)
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-2002-0103

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020107 [PTL-2002-01] Vulnerabilities in Oracle9iAS Web Cache
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101041510727937&w=2
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/webcache2.pdf
Reference: BID:3761
Reference: URL:http://online.securityfocus.com/bid/3761
Reference: BID:3764
Reference: URL:http://online.securityfocus.com/bid/3764

Description:
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.

Votes:

   ACCEPT(5) Ziese, Wall, Foat, Cole, Green
   MODIFY(1) Frech
Voter Comments:
 Frech> XF:oracle-appserver-webcached-privileges(7766)
   XF:oracle-appserver-webcache-password(7768)
 CHANGE> [Foat changed vote from NOOP to ACCEPT]


CAN-2002-0104

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020107 Aftpd core dump vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101041333323486&w=2
Reference: BID:3806
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3806
Reference: XF:aftpd-crash-core-dump(7832)
Reference: URL:http://www.iss.net/security_center/static/7832.php

Description:
AFTPD 5.4.4 allows remote attackers to gain sensitive information via a CD (CWD) ~ (tilde) command, which causes a core dump.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(4) Ziese, Wall, Foat, Cole

CAN-2002-0105

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020108 CDE bug in Unixware 7.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101060400802428&w=2
Reference: BID:3818
Reference: URL:http://www.securityfocus.com/bid/3818
Reference: XF:unixware-dtlogin-log-symlink(7864)
Reference: URL:http://www.iss.net/security_center/static/7864.php

Description:
CDE dtlogin in Caldera UnixWare 7.1.0, and possibly other operating systems, allows local users to gain privileges via a symlink attack on /var/dt/Xerrors since /var/dt is world-writable.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(4) Ziese, Wall, Foat, Cole
   REVIEWING(1) Christey
Voter Comments:
 Christey> CALDERA:CSSA-2002-SCO.18
   XF:cde-dt-world-writable(9045)
   URL:http://www.iss.net/security_center/static/9045.php
   Note: the advisory sort-of implies that world-write
   permissions were the key problem, so the fact that a symlink
   attack could take place did not necessarily mean that a
   symlink following vulnerability really existed, in the sense
   that symlink attacks don't exist in directories that are
   not writable by other users (well, without those users
   exploiting some *other* vulnerability to allow them to create
   the symlink!)
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Hmmm... should XF:cde-dt-world-writable(9045) really be added
   here?  ISS may have "split" between the permissions issue
   and the symlink problem.


CAN-2002-0106

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020108 KPMG-2002003: Bea Weblogic DOS-device Denial of Service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101050440629269&w=2
Reference: BID:3816
Reference: URL:http://www.securityfocus.com/bid/3816
Reference: XF:weblogic-dos-jsp-dos(7808)
Reference: URL:http://www.iss.net/security_center/static/7808.php

Description:
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP files that contain an MS-DOS device name.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(4) Ziese, Wall, Foat, Cole

CAN-2002-0108

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020108 Allaire Forums Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/249026
Reference: BID:3827
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3827
Reference: XF:allaire-forums-message-spoofing(7841)
Reference: URL:http://www.iss.net/security_center/static/7841.php

Description:
Allaire Forums 2.0.4 and 2.0.5 and Forums! 3.0 and 3.1 allows remote authenticated users to spoof messages as other users by modifying the hidden form fields for the name and e-mail address.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(4) Ziese, Wall, Foat, Cole

CAN-2002-0109

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020106 Linksys 'routers', SNMP issues
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101039288111680&w=2
Reference: BID:3795
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3795
Reference: BID:3797
Reference: URL:http://online.securityfocus.com/bid/3797
Reference: XF:linksys-etherfast-default-snmp(7827)
Reference: URL:http://www.iss.net/security_center/static/7827.php

Description:
Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.

Votes:

   ACCEPT(2) Frech, Green
   MODIFY(1) Foat
   NOOP(2) Wall, Cole
Voter Comments:
 Foat> Our testing showed that this vulnerabiltiy did not apply to BEFSR41 
   routers.


CAN-2002-0110

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020109 MiraMail 1.04 can give POP account access and details
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101063476715154&w=2
Reference: BID:3843
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3843
Reference: XF:miramail-plaintext-auth-info(7855)
Reference: URL:http://www.iss.net/security_center/static/7855.php

Description:
Nevrona Designs MiraMail 1.04 and earlier stores authentication information such as POP usernames and passwords in plaintext in a .ini file, which allows an attacker to gain privileges by reading the passwords from the file.

Votes:

   ACCEPT(4) Frech, Balinsky, Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0112

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020109 Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101062172226812&w=2
Reference: NTBUGTRAQ:20020109 Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101062823505486&w=2
Reference: BUGTRAQ:20020111 Eserv 2.97 Password Protected File Arbitrary Read Access Vulnerability (Solution)
Reference: URL:http://online.securityfocus.com/archive/1/249734
Reference: BID:3838
Reference: URL:http://online.securityfocus.com/bid/3838

Description:
Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Green> Vendor has released upgrades
 Frech> XF:eserv-protected-file-access(7849)
   ADDREF:http://online.securityfocus.com/archive/1/249210


CAN-2002-0113

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020110 Legato Vulnerable
Reference: URL:http://online.securityfocus.com/archive/1/249420
Reference: BID:3840
Reference: URL:http://online.securityfocus.com/bid/3840
Reference: XF:legato-nsrd-log-permissions(7897)
Reference: URL:http://www.iss.net/security_center/static/7897.php

Description:
Legato NetWorker 6.1 stores log files in the /nsr/logs/ directory with world-readable permissions, which allows local users to read sensitive information and possibly gain privileges.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0114

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020110 Legato Vulnerable
Reference: URL:http://online.securityfocus.com/archive/1/249420
Reference: BID:3842
Reference: URL:http://online.securityfocus.com/bid/3842
Reference: XF:legato-nsrd-log-plaintext(7898)
Reference: URL:http://www.iss.net/security_center/static/7898.php

Description:
Legato NetWorker 6.1 stores passwords in plaintext in the daemon.log file, which allows local users to gain privileges by reading the password from the file.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0116

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020110 Handspring Visor D.O.S
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101069677929208&w=2
Reference: BUGTRAQ:20020110 Re: Handspring Visor D.O.S
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101070523119956&w=2
Reference: BID:3847
Reference: URL:http://online.securityfocus.com/bid/3847
Reference: XF:palmos-nmap-dos(7865)
Reference: URL:http://www.iss.net/security_center/static/7865.php

Description:
Palm OS 3.5h and possibly other versions, as used in Handspring Visor and Xircom products, allows remote attackers to cause a denial of service via a TCP connect scan, e.g. from nmap.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Green> Caused a full reset on a Visor


CAN-2002-0118

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020108 CSS vulnerabilities in YaBB and UBB allow account hijack [Multiple Vendor]
Reference: URL:http://online.securityfocus.com/archive/1/249031
Reference: BID:3829
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3829
Reference: XF:ultimatebb-encoded-css(7838)
Reference: URL:http://www.iss.net/security_center/static/7838.php

Description:
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attackers to execute arbitrary script and steal cookies via a message containing encoded Javascript in an IMG tag.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0119

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020111 Bug in alcatel speed touch home adsl modem
Reference: URL:http://online.securityfocus.com/archive/1/249746
Reference: BID:3851
Reference: URL:http://online.securityfocus.com/bid/3851
Reference: XF:alcatel-speedtouch-nmap-dos(7893)
Reference: URL:http://www.iss.net/security_center/static/7893.php

Description:
Alcatel Speed Touch Home ADSL Modem allows remote attackers to cause a denial of service (reboot) via a network scan with unusual packets, such as nmap with OS detection.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(4) Christey, Wall, Foat, Cole
Voter Comments:
 Christey> According to an email from Alcatel personnel, the ADSL modem
   business was sold to TMM (Thomson Multi Media) in 2001;
   therefore TMM should be consulted for acknowledgement.


CAN-2002-0122

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020114 Siemens Mobie SMS Exceptional Character Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/250115
Reference: BID:3870
Reference: URL:http://online.securityfocus.com/bid/3870
Reference: XF:siemens-invalid-sms-dos(7902)
Reference: URL:http://www.iss.net/security_center/static/7902.php

Description:
Siemens 3568i WAP mobile phones allows remote attackers to cause a denial of service (crash) via an SMS message containing unusual characters.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0124

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020114 Web Server 4D/eCommerce 3.5.3 Directory Traversal Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/250231
Reference: BID:3872
Reference: URL:http://online.securityfocus.com/bid/3872
Reference: XF:ws4d-dot-directory-traversal(7878)
Reference: URL:http://www.iss.net/security_center/static/7878.php

Description:
MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> ADDREF:http://www.mdg.com/(MDG Web site)


CAN-2002-0125

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020114 Clanlib overflow / Super Methane Brothers overflow
Reference: URL:http://online.securityfocus.com/archive/1/250414
Reference: BID:3877
Reference: URL:http://online.securityfocus.com/bid/3877
Reference: XF:clanlib-long-env-bo(7905)
Reference: URL:http://www.iss.net/security_center/static/7905.php

Description:
Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and others, via a long HOME environment variable.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0126

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020115 BlackMoon FTPd Buffer Overflow Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/250543
Reference: BID:3884
Reference: URL:http://online.securityfocus.com/bid/3884
Reference: MISC:http://members.rogers.com/blackmoon2k/pages/news_page.html
Reference: XF:blackmoon-ftpd-static-bo(7895)
Reference: URL:http://www.iss.net/security_center/static/7895.php

Description:
Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0127

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020115 Vulnerability Netgear RP-114 Router - nmap causes DOS
Reference: URL:http://online.securityfocus.com/archive/1/250405
Reference: BID:3876
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3876

Description:
Netgear RP114 Cable/DSL Web Safe Router Firmware 3.26, when configured to block traffic below port 1024, allows remote attackers to cause a denial of service (hang) via a port scan of the WAN port.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:netgear-wan-scan-dos(7903)


CAN-2002-0129

Phase: Proposed (20020315)
Reference: VULN-DEV:20020116 efax
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=101114350330912&w=2
Reference: BUGTRAQ:20020116 Re: efax
Reference: URL:http://online.securityfocus.com/archive/1/250837
Reference: BID:3895
Reference: URL:http://online.securityfocus.com/bid/3895
Reference: XF:efax-d-read-files(7921)
Reference: URL:http://www.iss.net/security_center/static/7921.php

Description:
efax 0.9 and earlier, when installed setuid root, allows local users to read arbitrary files via the -d option, which prints the contents of the file in a warning message.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0130

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020116 Re: efax
Reference: URL:http://online.securityfocus.com/archive/1/250799
Reference: VULN-DEV:20020117 Re: efax - Exploitation info
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=101133782204289&w=2
Reference: BID:3894
Reference: URL:http://online.securityfocus.com/bid/3894
Reference: XF:efax-x-bo(7920)
Reference: URL:http://www.iss.net/security_center/static/7920.php

Description:
Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0131

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020115 Serious privacy leak in Python for Windows
Reference: URL:http://marc.theaimsgroup.com/?t=101113015900001&r=1&w=2
Reference: BID:3893
Reference: URL:http://online.securityfocus.com/bid/3893
Reference: XF:activepython-activex-read-files(7910)
Reference: URL:http://www.iss.net/security_center/static/7910.php

Description:
ActivePython ActiveX control for Python, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0132

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020116 Chinput Buffer Overflow Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/250815
Reference: BID:3896
Reference: URL:http://online.securityfocus.com/bid/3896
Reference: XF:chinput-long-env-bo(7911)
Reference: URL:http://www.iss.net/security_center/static/7911.php

Description:
Buffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0133

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020117 Avirt Proxy Buffer Overflow Vulnerabilities
Reference: URL:http://online.securityfocus.com/archive/1/251055
Reference: BUGTRAQ:20020121 [resend] Avirt Gateway Telnet Vulnerability (and more?)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101164598828092&w=2
Reference: BUGTRAQ:20020220 Avirt 4.2 question
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101424723728817&w=2
Reference: BUGTRAQ:20020212 Avirt Gateway 4.2 remote buffer overflow: proof of concept
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101366658112809&w=2
Reference: BID:3904
Reference: URL:http://online.securityfocus.com/bid/3904
Reference: BID:3905
Reference: URL:http://online.securityfocus.com/bid/3905
Reference: XF:avirt-http-proxy-bo(7916)
Reference: URL:http://www.iss.net/security_center/static/7916.php
Reference: XF:avirt-telnet-proxy-bo(7918)
Reference: URL:http://www.iss.net/security_center/static/7918.php

Description:
Buffer overflows in Avirt Gateway Suite 4.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) long header fields to the HTTP proxy, or (2) a long string to the telnet proxy.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0134

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020117 Avirt Gateway Suite Remote SYSTEM Level Compromise
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101131669102843&w=2
Reference: BUGTRAQ:20020220 Avirt 4.2 question
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101424723728817&w=2
Reference: BID:3901
Reference: URL:http://online.securityfocus.com/bid/3901
Reference: XF:avirt-gateway-telnet-access(7915)
Reference: URL:http://www.iss.net/security_center/static/7915.php

Description:
Telnet proxy in Avirt Gateway Suite 4.2 does not require authentication for connecting to the proxy system itself, which allows remote attackers to list file contents of the proxy and execute arbitrary commands via a "dos" command.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0135

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020118 Timbuktu 6.0.1 and Older DoS Advisory
Reference: URL:http://online.securityfocus.com/archive/1/251582
Reference: BID:3918
Reference: URL:http://online.securityfocus.com/bid/3918
Reference: XF:timbuktu-multiple-conn-dos(7935)
Reference: URL:http://www.iss.net/security_center/static/7935.php

Description:
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420).

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0136

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020115 IE FORM DOS
Reference: URL:http://online.securityfocus.com/archive/1/250592
Reference: BID:3892
Reference: URL:http://online.securityfocus.com/bid/3892

Description:
Microsoft Internet Explorer 5.5 on Windows 98 allows remote web pages to cause a denial of service (hang) via extremely long values for form fields such as INPUT and TEXTAREA, which can be automatically filled via Javascript.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(2) Foat, Cole
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:ie-html-form-dos(7938)


CAN-2002-0137

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020112 cdrdao insecure filehandling
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101102759631000&w=2
Reference: BID:3865
Reference: URL:http://online.securityfocus.com/bid/3865

Description:
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configuration file.

Votes:

   ACCEPT(1) Green
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
Voter Comments:
 Frech> XF:cdrdao-home-symlink(7934)


CAN-2002-0138

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020112 cdrdao insecure filehandling
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101102759631000&w=2
Reference: BUGTRAQ:20020115 Re: cdrdao insecure filehandling
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101111688819855&w=2

Description:
CDRDAO 1.1.4 and 1.1.5 allows local users to read arbitrary files via the show-data command.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Frech

CAN-2002-0140

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020120 dnrd 2.10 dos
Reference: URL:http://online.securityfocus.com/archive/1/251619
Reference: BID:3928
Reference: URL:http://online.securityfocus.com/bid/3928

Description:
Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code via a long or malformed DNS reply, which is not handled properly by parse_query, get_objectname, and possibly other functions.

Votes:

   ACCEPT(2) Foat, Green
   MODIFY(1) Frech
   NOOP(2) Wall, Cole
Voter Comments:
 Frech> XF:dnrd-dns-dos(7957)


CAN-2002-0141

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020120 Maelstrom 1.4.3 abartity file overwrite
Reference: URL:http://online.securityfocus.com/archive/1/251419
Reference: BID:3911
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3911
Reference: XF:maelstrom-tmp-symlink(7939)
Reference: URL:http://www.iss.net/security_center/static/7939.php

Description:
Maelstrom GPL 3.0.1 allows local users to overwrite arbitrary files of other Maelstrom users via a symlink attack on the /tmp/f file.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0142

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020114 Pi3Web Webserver v2.0 Buffer Overflow Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/250126
Reference: BUGTRAQ:20020121 Re: Pi3Web Webserver v2.0 Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101164598828093&w=2
Reference: NTBUGTRAQ:20020113 Pi3Web Webserver v2.0 Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101102275316307&w=2
Reference: CONFIRM:http://sourceforge.net/tracker/index.php?func=detail&aid=505583&group_id=17753&atid=317753
Reference: BID:3866
Reference: URL:http://online.securityfocus.com/bid/3866
Reference: XF:pi3web-long-parameter-bo(7880)
Reference: URL:http://www.iss.net/security_center/static/7880.php

Description:
CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash) via a series of requests whose physical path is exactly 260 characters long and ends in a series of . (dot) characters.

Votes:

   ACCEPT(3) Frech, Cole, Green
   NOOP(4) Christey, Balinsky, Wall, Foat
Voter Comments:
 Christey> VULNWATCH:20020113 Pi3Web Webserver v2.0 Buffer Overflow Vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0015.html


CAN-2002-0144

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020121 security vulnerability in chuid
Reference: URL:http://online.securityfocus.com/archive/1/251763
Reference: BID:3937
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3937
Reference: XF:chuid-unauthorized-ownership-change(7976)
Reference: URL:http://www.iss.net/security_center/static/7976.php

Description:
Directory traversal vulnerability in chuid 1.2 and earlier allows remote attackers to change the ownership of files outside of the upload directory via a .. (dot dot) attack.

Votes:

   ACCEPT(4) Frech, Balinsky, Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0145

Phase: Proposed (20020315)
Reference: BUGTRAQ:20020121 security vulnerability in chuid
Reference: URL:http://online.securityfocus.com/archive/1/251763
Reference: BID:3937
Reference: URL:http://online.securityfocus.com/cgi-bin/vulns-item.pl?section=info&id=3937

Description:
chuid 1.2 and earlier does not properly verify the ownership of files that will be changed, which allows remote attackers to change files owned by other users, such as root.

Votes:

   ACCEPT(3) Balinsky, Cole, Green
   MODIFY(1) Frech
   NOOP(3) Ziese, Wall, Foat
Voter Comments:
 Frech> XF:chuid-unauthorized-ownership-change(7976)


CAN-2002-0154

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020305 Another Sql Server 7 Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101535353331625&w=2
Reference: BUGTRAQ:20020312 Many, many, many Sql Server 7 & 2000 Buffer Overflows
Reference: URL:http://www.securityfocus.com/archive/1/261775
Reference: MS:MS02-020
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-020.asp

Description:
Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.

Votes:

   ACCEPT(5) Wall, Foat, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(2) Christey, Cox
Voter Comments:
 Christey> BID:4231
   URL:http://www.securityfocus.com/bid/4231
   XF:mssql-xp-dirtree-bo(8359)
   URL:http://www.iss.net/security_center/static/8359.php
   
   Need to specifically mention xp_dirtree.
 Christey> CERT:CA-2002-22
   CERT-VN:VU#627275
 Frech> XF:mssql-multiple-xp-bo(8359)


CAN-2002-0158

Phase: Modified (20020616-01)
Reference: BUGTRAQ:20020402 NSFOCUS SA2002-01: Sun Solaris Xsun "-co" heap overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101776858410652&w=2
Reference: VULNWATCH:20020402 NSFOCUS SA2002-01: Sun Solaris Xsun "-co" heap overflow
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0000.html
Reference: CONFIRM:http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F108652

Description:
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.

Votes:

   ACCEPT(4) Baker, Foat, Armstrong, Green
   MODIFY(1) Frech
   NOOP(3) Christey, Cox, Cole
   REVIEWING(1) Wall
Voter Comments:
 Green> The documentation of this vulnerability is compelling
 Christey> CONFIRM:http://sunsolve.Sun.COM/pub-cgi/retrieve.pl?doc=fpatches%2F108652
   the description for patch 108652-52, bug 4661987,
   explicitly references CAN-2002-0158.
 Green> The documentation of this vulnerability is compelling
 Frech> XF:solaris-xsun-co-bo(8703)


CAN-2002-0161

Phase: Assigned (20020327)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0162

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20020327 Root compromise through LogWatch 2.1.1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101724766216872
Reference: VULN-DEV:20020327 Root compromise through LogWatch 2.1.1
Reference: URL:http://online.securityfocus.com/archive/82/264233
Reference: CONFIRM:http://list.kaybee.org/archives/logwatch-announce/2002-March/000002.html
Reference: REDHAT:RHSA-2002:053
Reference: REDHAT:RHSA-2002:054
Reference: XF:logwatch-tmp-race-condition(8652)
Reference: URL:http://www.iss.net/security_center/static/8652.php
Reference: BID:4374
Reference: URL:http://online.securityfocus.com/bid/4374

Description:
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary directory.

Votes:

   ACCEPT(4) Cox, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> Modify the desc: it's temporary *directory* creation.
   
   XF:logwatch-tmp-race-condition(8652)
   URL:http://www.iss.net/security_center/static/8652.php
   BID:4374
   URL:http://online.securityfocus.com/bid/4374
 Frech> XF:logwatch-tmp-race-condition(8652)


CAN-2002-0164

Phase: Proposed (20020502)
Reference: CALDERA:CSSA-2002-009.0
Reference: URL:http://www.calderasystems.com/support/security/advisories/CSSA-2002-009.0.txt
Reference: CALDERA:CSSA-2002-SCO.14
Reference: URL:ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.14/CSSA-2002-SCO.14.txt

Description:
Vulnerability in the MIT-SHM extension of the X server on Linux allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges.

Votes:

   ACCEPT(5) Cox, Wall, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(2) Christey, Foat
Voter Comments:
 Christey> SGI:20021001-01-P
 Christey> BUGTRAQ:20021024 GLSA: xfree
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103547625009363&w=2
   
   This Gentoo advisory mentions XFree86 4.2.0-r12 and earlier.
 Frech> XF:xfree86-mitshm-memory-access(8706)
 Christey> REDHAT:RHSA-2003:067
   URL:http://www.redhat.com/support/errata/RHSA-2003-067.html


CAN-2002-0165

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20020403 LogWatch 2.5 still vulnerable
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101787227513000&w=2
Reference: REDHAT:RHSA-2002:053
Reference: REDHAT:RHSA-2002:054
Reference: CONFIRM:http://list.kaybee.org/archives/logwatch-announce/2002-March/000003.html
Reference: XF:logwatch-tmp-race-condition(8652)
Reference: URL:http://www.iss.net/security_center/static/8652.php

Description:
LogWatch 2.5 allows local users to gain root privileges via a symlink attack, a different vulnerability than CAN-2002-0162.

Votes:

   ACCEPT(4) Cox, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> XF:logwatch-tmp-race-condition(8652)
   URL:http://www.iss.net/security_center/static/8652.php
   CONFIRM:http://list.kaybee.org/archives/logwatch-announce/2002-March/000003.html
   (notice how this is a different announcement than CAN-2002-0162)
 Frech> XF:logwatch-tmp-race-condition(8652)


CAN-2002-0177

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020402 icecast 1.3.11 remote shell/root exploit - #temp
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101780890326179&w=2
Reference: BUGTRAQ:20020403 Icecast temp patch (OR: Patches? We DO need stinkin' patches!!@$!)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101786838300906&w=2
Reference: BUGTRAQ:20020404 Full analysis of multiple remotely exploitable bugs in Icecast 1.3.11
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101793704306035&w=2
Reference: CONFIRM:http://www.xiph.org/archives/icecast/2616.html
Reference: BID:4415
Reference: URL:http://online.securityfocus.com/bid/4415

Description:
Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client.

Votes:

   ACCEPT(3) Cox, Cole, Green
   MODIFY(1) Frech
   NOOP(4) Christey, Wall, Foat, Armstrong
Voter Comments:
 Christey> CALDERA:CSSA-2002-020.0
 Christey> Change "allows" to "allow," and add "as exploited through the
   client_login function" (to facilitate matching).
   REDHAT:RHSA-2002:063
 Frech> XF:icecast-clientlogin-bo(8741)


CAN-2002-0180

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020415 Remote buffer overflow in Webalizer
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101888467527673&w=2
Reference: CONFIRM:http://www.mrunix.net/webalizer/news.html

Description:
Buffer overflow in Webalizer 2.01-06, when configured to use reverse DNS lookups, allows remote attackers to execute arbitrary code by connecting to the monitored web server from an IP address that resolves to a long hostname.

Votes:

   ACCEPT(4) Baker, Cox, Cole, Green
   MODIFY(2) Frech, Jones
   NOOP(4) Christey, Wall, Foat, Armstrong
Voter Comments:
 Cox> According to the author of Webalizer the issue is not remotely
   exploitable, but this hasn't been confirmed by us yet.  Needs
   investigation.
   
   http://www.mrunix.net/webalizer/news.html
 CHANGE> [Cox changed vote from MODIFY to REVIEWING]
 Cox> Author says this cannot be exploited to execute arbitrary code
 Jones> Description of acknowledged vulnerability indicates remotely
   exploitable (buffer overflow is in code which is processing
   input from a remote system (a DNS server)); root or non-root
   depends on privileges of resolver process (which is likely
   same as privileges of Webalizer process).  So, remotely
   exploitable to run arbitrary code with privileges of the
   Webalizer process.
 Cox> I actually meant that the author doesn't think this is an exploitable
   overflow at all, see 
   
   ---------- Forwarded message ----------
   Date: Wed, 17 Apr 2002 02:19:37 -0400 (EDT)
   From: Bradford L. Barrett <brad@mrunix.net>
   To: Franck Coppola <franck@hosting42.com>
   Cc: Spybreak <spybreak@host.sk>, bugtraq@securityfocus.com,
   vulnwatch@vulnwatch.org
   Subject: Re: Remote buffer overflow in Webalizer
   
   
   > Here is a patch to fix the vulnerability (tested against webalizer-2.01-06).
   
   Bad fix.. while it will prevent the buffer from overflowing (which I still
   fail to see how can be used to execute a 'root' exploit, even with a LOT
   of imagination), but will cause the buffer to be filled with a non-null
   terminated string which will do all sorts of nasty things to your output,
   not to mention wreak havoc on the stats since you are cutting off the
   domain portion, not the hostname part, and adding random garbage at the
   end.
   
   Anyway, Version 2.01-10 has been released, which fixes this and a few
   other buglets that have been discovered in the last month or so.  Get it
   at the usual place (web: www.mrunix.net/webalizer/ or www.webalizer.org
   or ftp: ftp.mrunix.net/pub/webalizer/), and should be on the mirror sites
   soon.
   
   --
   Bradford L. Barrett                      brad@mrunix.net
   A free electron in a sea of neutrons     DoD#1750 KD4NAW
   
   
 Christey> XF:webalizer-reverse-dns-bo(8837)
   URL:http://www.iss.net/security_center/static/8837.php
   BID:4504
   URL:http://www.securityfocus.com/bid/4504
   VULNWATCH:20020415 [VulnWatch] Remote buffer overflow in Webalizer
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0017.html
   ENGARDE:ESA-20020423-009
   CONECTIVA:CLA-2002:476
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000476
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Cox> after reviewing I agree with the description given
 Frech> XF: webalizer-reverse-dns-bo(8837)
 Christey> REDHAT:RHSA-2002:254
 Christey> CALDERA:CSSA-2002-036.0
   (note: CAN-2002-1234 was accidentally assigned to that Caldera
   advisory, but this is the correct CAN to use)


CAN-2002-0182

Phase: Assigned (20020417)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0188

Phase: Modified (20030320-01)
Reference: BUGTRAQ:20020516 [SNS Advisory No.48] Microsoft Internet Explorer Still Download And Execute ANY Program Automatically
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0126.html
Reference: MS:MS02-023
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-023.asp
Reference: MISC:http://www.lac.co.jp/security/english/snsadv_e/48_e.html
Reference: XF:ie-content-disposition-variant2(9086)
Reference: URL:http://www.iss.net/security_center/static/9086.php

Description:
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the second variant of the "Content Disposition" vulnerability.

Votes:

   ACCEPT(5) Baker, Wall, Foat, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Cox
Voter Comments:
 Frech> XF:ie-content-disposition-variant2(9086)


CAN-2002-0189

Phase: Proposed (20020611)
Reference: MS:MS02-023
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-023.asp

Description:
Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.

Votes:

   ACCEPT(5) Baker, Wall, Foat, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Cox
   REVIEWING(1) Christey
Voter Comments:
 Christey> NOTE: As of 5/20/2002, there is a lack of clarity regarding
   the details of this vulnerability and other vulnerabilities
   being reported by GreyMagic and Thor Larholm.  Additional
   details will be added to this candidate if/when they become
   available.  This candidate is solely for the issue that is
   being addressed by Microsoft in MS:MS02-023.  Its relationship
   with other reported issues is currently unproven.
   
   This candidate is subject to CD:VAGUE.
 Christey> XF:ie-dialog-window-css(8868)
   URL:http://www.iss.net/security_center/static/8868.php
 Frech> XF:ie-dialog-window-css(8868)
 Baker> I agree some of the information appears vague, but seems to be legitimate.


CAN-2002-0192

Phase: Modified (20030529-01)

Description:
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. This candidate was published with a description that identified a different vulnerability than what was identified in the original reference. Consult CAN-2002-0193 or CAN-2002-1564 to find the identifier for the proper issue.

Votes:

   ACCEPT(5) Baker, Wall, Foat, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Cox
   REJECT(1) Christey
Voter Comments:
 Frech> XF:ie-content-disposition-variant(9085)
 Christey> Hrmmm... the MS advisory says this is the "Script within
   Cookies Reading Cookies" vulnerability...  This description
   was also used for CAN-2002-0193.
 CHANGE> [Christey changed vote from NOOP to REJECT]
 Christey> This CAN had the wrong description added to it, which made
   it look like a different vulnerability than the one identified
   by Microsoft in MS:MS02-023.  Therefore this CAN should be
   REJECTed.


CAN-2002-0193

Phase: Proposed (20020611)
Reference: MS:MS02-023
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-023.asp

Description:
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.

Votes:

   ACCEPT(5) Baker, Wall, Foat, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Cox
Voter Comments:
 Frech> XF:ie-content-disposition-variant(9085)


CAN-2002-0194

Phase: Assigned (20020420)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0195

Phase: Assigned (20020420)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0198

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020122 pldaniels - ripMime 1.2.6 and lower?
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101182636812381&w=2
Reference: CONFIRM:http://pldaniels.org/ripmime/CHANGELOG
Reference: BID:3941
Reference: URL:http://online.securityfocus.com/bid/3941
Reference: XF:ripmime-long-filename-bo(7983)
Reference: URL:http://www.iss.net/security_center/static/7983.php

Description:
Buffer overflow in plDaniels ripMime 1.2.6 and earlier, as used in other programs such as xamime and inflex, allows remote attackers to execute arbitrary code via an attachment in a long filename.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0199

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020119 Shoutcast server 1.8.3 win32
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101167484012724&w=2
Reference: BID:3934
Reference: URL:http://online.securityfocus.com/bid/3934

Description:
Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an argument with a large number of backslashes.

Votes:

   ACCEPT(1) Green
   NOOP(4) Christey, Wall, Foat, Cole
Voter Comments:
 Christey> XF:shoutcast-admin-cgi-dos(7958)
   URL:http://xforce.iss.net/static/7958.php


CAN-2002-0200

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020122 CyberStop-Server-DoS-remote-attacks
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101174569103289&w=2
Reference: BID:3929
Reference: URL:http://online.securityfocus.com/bid/3929
Reference: XF:cyberstop-device-name-dos(7959)
Reference: URL:http://www.iss.net/security_center/static/7959.php

Description:
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name

Votes:

   ACCEPT(1) Green
   NOOP(4) Christey, Wall, Foat, Cole
Voter Comments:
 Christey> Add period to the end of the description.


CAN-2002-0201

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020122 CyberStop-Server-DoS-remote-attacks
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101174569103289&w=2
Reference: BID:3930
Reference: URL:http://online.securityfocus.com/bid/3930
Reference: XF:cyberstop-long-request-dos(7960)
Reference: URL:http://www.iss.net/security_center/static/7960.php

Description:
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0202

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020123 Vulnerabilty in PaintBBS v1.2
Reference: URL:http://online.securityfocus.com/archive/1/251985
Reference: BID:3948
Reference: URL:http://online.securityfocus.com/bid/3948
Reference: XF:paintbbs-insecure-permissions(7982)
Reference: URL:http://www.iss.net/security_center/static/7982.php

Description:
PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) modify the server configuration via the world-writeable /oekaki/ folder.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0203

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020124 ISSTW Security Advisory Tarantella Enterprise 3.11.903 Directory Index Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101190195430376&w=2
Reference: CONFIRM:http://www.tarantella.com/security/bulletin-03.html

Description:
ttawebtop.cgi in Tarantella Enterprise 3.20 on SPARC Solaris and Linux, and 3.1x and 3.0x including 3.11.903, allows remote attackers to view directory contents via an empty pg parameter.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0204

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020124 gnuchess buffer overflow vulnerabilty
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101189688815514&w=2
Reference: BID:3949
Reference: URL:http://online.securityfocus.com/bid/3949
Reference: XF:gnu-chess-bo(7991)
Reference: URL:http://www.iss.net/security_center/static/7991.php

Description:
Buffer overflow in GNU Chess (gnuchess) 5.02 and earlier, if modified or used in a networked capacity contrary to its own design as a single-user application, may allow local or remote attackers to execute arbitrary code via a long command.

Votes:

   NOOP(2) Foat, Cole
   REJECT(1) Wall
   REVIEWING(1) Green
Voter Comments:
 Green> The issue of modifying code and/or using code for purposes other than intended raises the hypothetical (albeit ridiculous) prospect of having to classify vulnerabilities within gcc, since one could develop malicious code using the compiler.


CAN-2002-0205

Phase: Proposed (20020502)
Reference: VULN-DEV:20020104 Cross-Site Scripting in PlumTree?
Reference: URL:http://online.securityfocus.com/archive/82/248396
Reference: BUGTRAQ:20020124 Plumtree Corporate Portal Cross-Site Scripting (Patch Available)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101189911121808&w=2
Reference: BID:3799
Reference: URL:http://online.securityfocus.com/bid/3799
Reference: XF:plumtree-css-error(7817)
Reference: URL:http://www.iss.net/security_center/static/7817.php

Description:
Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0206

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020116 PHP-Nuke allows Command Execution & Much more
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101121913914205&w=2
Reference: BID:3889
Reference: URL:http://online.securityfocus.com/bid/3889

Description:
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier allows remote attackers to execute arbitrary PHP code by specifying a URL to the malicious code in the file parameter.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0208

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020125 Identifying PGP Corporate Desktop 7.1 with PGPfire Personal Desktop Firewall installed (no need to be enabled) on Microsoft Windows Based OSs
Reference: URL:http://online.securityfocus.com/archive/1/252407
Reference: BID:3961
Reference: URL:http://online.securityfocus.com/bid/3961
Reference: XF:pgpfire-icmp-fingerprint(8008)
Reference: URL:http://www.iss.net/security_center/static/8008.php

Description:
PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in ICMP error messages in a way that allows remote attackers to determine that the system is running PGPfire.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0210

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020126 bru backup program
Reference: URL:http://online.securityfocus.com/archive/1/252614
Reference: BID:3970
Reference: URL:http://online.securityfocus.com/bid/3970
Reference: XF:bru-tmp-file-symlink(8003)
Reference: URL:http://www.iss.net/security_center/static/8003.php

Description:
setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0212

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020126 [ARL02-A01] Vulnerability in Hosting Controller
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101224151705897&w=2
Reference: MISC:http://hostingcontroller.com/English/patches/ForAll/index.html
Reference: BID:3971
Reference: URL:http://online.securityfocus.com/bid/3971
Reference: XF:hosting-controller-brute-force(8006)
Reference: URL:http://www.iss.net/security_center/static/8006.php

Description:
The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows remote attackers to determine the existence of valid usernames and makes it easier to conduct a brute force attack.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0214

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020128 Intel WLAN Driver storing 128bit WEP-Key in plain text!
Reference: URL:http://online.securityfocus.com/archive/1/252607
Reference: BID:3968
Reference: URL:http://online.securityfocus.com/bid/3968
Reference: XF:intel-wlan-wep-plaintext(8015)
Reference: URL:http://www.iss.net/security_center/static/8015.php

Description:
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the WEP key from the registry key.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0215

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020128 [SUPERPETZ ADVISORY #001 - agora.cgi Secret Path Disclosure Vulnerability]
Reference: URL:http://online.securityfocus.com/archive/1/252761
Reference: BID:3976
Reference: URL:http://online.securityfocus.com/bid/3976
Reference: XF:agora-cgi-revel-path(8011)
Reference: URL:http://www.iss.net/security_center/static/8011.php

Description:
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi file by requesting a non-existent .html file, which leaks the pathname in an error message.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0216

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020129 Xoops SQL fragment disclosure and SQL injection vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/252827
Reference: BID:3977
Reference: URL:http://online.securityfocus.com/bid/3977
Reference: XF:xoops-userinfo-information-disclosure(8028)
Reference: URL:http://www.iss.net/security_center/static/8028.php

Description:
userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0217

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020129 Xoops Private Message System Script injection
Reference: URL:http://online.securityfocus.com/archive/1/252828
Reference: BID:3978
Reference: URL:http://online.securityfocus.com/bid/3978
Reference: BID:3981
Reference: URL:http://online.securityfocus.com/bid/3981
Reference: XF:xoops-private-message-css(8025)
Reference: URL:http://www.iss.net/security_center/static/8025.php
Reference: XF:xoops-pmlite-image-css(8030)
Reference: URL:http://www.iss.net/security_center/static/8030.php

Description:
Cross-site scripting (CSS) vulnerabilities in the Private Message System for XOOPS 1.0 RC1 allow remote attackers to execute Javascript on other web clients via (1) the Title field or a Private Message Box or (2) the image field parameter in pmlite.php.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0218

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020129 sastcpd Buffer Overflow and Format String Vulnerabilities
Reference: URL:http://online.securityfocus.com/archive/1/252891
Reference: BUGTRAQ:20020129 Re: [VulnWatch] sastcpd Buffer Overflow and Format String Vulnerabilities
Reference: URL:http://online.securityfocus.com/archive/1/252847
Reference: MISC:http://www.sas.com/service/techsup/unotes/SN/004/004201.html
Reference: BID:3980
Reference: URL:http://online.securityfocus.com/bid/3980

Description:
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0219

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020129 sastcpd Buffer Overflow and Format String Vulnerabilities
Reference: URL:http://online.securityfocus.com/archive/1/252891
Reference: BUGTRAQ:20020129 Re: [VulnWatch] sastcpd Buffer Overflow and Format String Vulnerabilities
Reference: URL:http://online.securityfocus.com/archive/1/252847
Reference: MISC:http://www.sas.com/service/techsup/unotes/SN/004/004201.html
Reference: BID:3979
Reference: URL:http://online.securityfocus.com/bid/3979

Description:
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0220

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020129 PhpSmsSend remote execute commands bug
Reference: URL:http://online.securityfocus.com/archive/1/252918
Reference: BID:3982
Reference: URL:http://online.securityfocus.com/bid/3982
Reference: XF:phpsmssend-command-execution(8019)
Reference: URL:http://www.iss.net/security_center/static/8019.php

Description:
phpsmssend.php in PhpSmsSend 1.0 allows remote attackers to execute arbitrary commands via an SMS message containing shell metacharacters.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0221

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020129 Vulnerabilities in EServ 2.97
Reference: URL:http://online.securityfocus.com/archive/1/252944
Reference: BID:3983
Reference: URL:http://online.securityfocus.com/bid/3983
Reference: XF:eserv-pasv-dos(8020)
Reference: URL:http://www.iss.net/security_center/static/8020.php

Description:
Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0222

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020129 Vulnerabilities in EServ 2.97
Reference: URL:http://online.securityfocus.com/archive/1/252944
Reference: BID:3986
Reference: URL:http://online.securityfocus.com/bid/3986
Reference: XF:eserv-ftp-bounce(8021)
Reference: URL:http://www.iss.net/security_center/static/8021.php

Description:
Etype Eserv 2.97 allows remote attackers to to redirect traffic to other sites (aka FTP bounce) via the PORT command.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0223

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020130 [ WWWThreads, UBBThreads ] Security Hole in upload system
Reference: URL:http://online.securityfocus.com/archive/1/253172
Reference: XF:ubbthreads-file-upload(8022)
Reference: URL:http://www.iss.net/security_center/static/8022.php
Reference: BID:3993
Reference: URL:http://online.securityfocus.com/bid/3993

Description:
Infopop UBB.Threads 5.4 and Wired Community Software WWWThreads 5.0 through 5.0.9 allows remote attackers to upload arbitrary files by using a filename that contains an accepted extension, but ends in a different extension.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0224

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020131 msdtc on 3372
Reference: URL:http://online.securityfocus.com/archive/1/253360
Reference: BUGTRAQ:20020419 KPMG-2002015: Microsoft Distributed Transaction Coordinator DoS
Reference: URL:http://online.securityfocus.com/archive/1/268593
Reference: BID:4006
Reference: URL:http://online.securityfocus.com/bid/4006

Description:
The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input.

Votes:

   ACCEPT(1) Green
   NOOP(2) Foat, Cole
   REVIEWING(1) Wall

CAN-2002-0225

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020130 tac_plus version F4.0.4.alpha on at least Solaris 8 sparc
Reference: URL:http://online.securityfocus.com/archive/1/253288
Reference: BID:4003
Reference: URL:http://www.securityfocus.com/bid/4003
Reference: XF:tacplus-insecure-accounting-files(8061)
Reference: URL:http://www.iss.net/security_center/static/8061.php

Description:
tac_plus Tacacs+ daemon F4.0.4.alpha, originally maintained by Cisco, creates files from the accounting directive with world-readable and writable permissions, which allows local users to access and modify sensitive files.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0227

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020201 KICQ 2.0.0b1 can be remotely crashed
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101266856410129&w=2
Reference: BID:4018
Reference: URL:http://online.securityfocus.com/bid/4018
Reference: XF:kicq-telnet-dos(8064)
Reference: URL:http://www.iss.net/security_center/static/8064.php

Description:
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0228

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020202 MSN Messenger reveals your name to websites (and can reveal email addresses too)
Reference: URL:http://online.securityfocus.com/archive/1/254021
Reference: XF:msn-messenger-reveal-information(8084)
Reference: URL:http://www.iss.net/security_center/static/8084.php
Reference: BID:4028
Reference: URL:http://online.securityfocus.com/bid/4028

Description:
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).

Votes:

   ACCEPT(2) Cole, Green
   NOOP(1) Foat
   REVIEWING(1) Wall

CAN-2002-0229

Phase: Proposed (20020502)
Reference: NTBUGTRAQ:20020203 PHP Safe Mode Filesystem Circumvention Problem
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101285016125377&w=2
Reference: BUGTRAQ:20020203 PHP Safe Mode Filesystem Circumvention Problem
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101286577109716&w=2
Reference: NTBUGTRAQ:20020205 Re: PHP Safe Mode Filesystem Circumvention Problem
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101303065423534&w=2
Reference: BUGTRAQ:20020206 DW020203-PHP clarification
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101304702002321&w=2
Reference: NTBUGTRAQ:20020206 DW020203-PHP clarification
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101303819613337&w=2
Reference: BID:4026
Reference: URL:http://online.securityfocus.com/bid/4026
Reference: XF:php-mysql-safemode-bypass(8105)
Reference: URL:http://www.iss.net/security_center/static/8105.php

Description:
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe Mode access restrictions and read arbitrary files using "LOAD DATA INFILE LOCAL" SQL statements.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0230

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020204 [SUPERPETZ ADVISORY #002- Faq-O-Matic Cross-Site Scripting Vulnerability]
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101285834018701&w=2
Reference: BUGTRAQ:20020205 Faq-O-Matic Cross-Site Scripting
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101293973111873&w=2
Reference: CONFIRM:http://sourceforge.net/mailarchive/forum.php?thread_id=464940&forum_id=6367
Reference: DEBIAN:DSA-109
Reference: URL:http://www.debian.org/security/2002/dsa-109

Description:
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascript on other clients via the cmd parameter, which causes the script to be inserted into an error message.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat
   RECAST(1) Christey
Voter Comments:
 Christey> XF:faqomatic-cgi-css(8066)
   URL:http://www.iss.net/security_center/static/8066.php
   BID:4023
   URL:http://www.securityfocus.com/bid/4023
   
   A similar issue was discovered a few months afterward in the
   "file" parameter, but it was already fixed by the vendor along
   with the cmd parameter.  Thus CD:SF-LOC suggests combining
   these into a single item.
   CONFIRM:http://sourceforge.net/mailarchive/forum.php?thread_id=477665&forum_id=6367
   BID:4565
   URL:http://www.securityfocus.com/bid/4565


CAN-2002-0231

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020203 Buffer overflow in mIRC allowing arbitary code to be executed.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101286747013955&w=2
Reference: MISC:http://www.uuuppz.com/research/adv-001-mirc.htm
Reference: XF:mirc-nickname-bo(8083)
Reference: URL:http://www.iss.net/security_center/static/8083.php
Reference: BID:4027
Reference: URL:http://online.securityfocus.com/bid/4027

Description:
Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickname.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0232

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020202 new advisory
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101266821909189&w=2
Reference: BID:4017
Reference: URL:http://www.securityfocus.com/bid/4017
Reference: XF:mrtg-cgi-view-files(8062)
Reference: URL:http://www.iss.net/security_center/static/8062.php

Description:
Directory traversal vulnerability in Multi Router Traffic Grapher (MRTG) allows remote attackers to read portions of arbitrary files via a .. (dot dot) in the cfg parameter for (1) 14all.cgi, (2) 14all-1.1.cgi, (3) traffic.cgi, or (4) mrtg.cgi.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0233

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020205 Viewing arbitrary file from the file system using Eshare Expressions 4 server
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101292885809975&w=2
Reference: XF:expressions-dot-directory-traversal(8079)
Reference: URL:http://www.iss.net/security_center/static/8079.php
Reference: BID:4029
Reference: URL:http://www.securityfocus.com/bid/4029

Description:
Directory traversal vulnerability in eshare Expressions 4 Web server allows remote attackers to read arbitrary files via a .. (dot dot) in an HTTP request.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0234

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020205 NetScreen Response to ScreenOS Port Scan DoS Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/254268
Reference: BUGTRAQ:20020201 NetScreen ScreenOS 2.6 Subject to Trust Interface DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101258281818524&w=2
Reference: BUGTRAQ:20020201 RE: NetScreen ScreenOS 2.6 Subject to Trust Interface DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101258887105690&w=2
Reference: BID:4015
Reference: URL:http://www.securityfocus.com/bid/4015
Reference: XF:netscreen-screenos-scan-dos(8057)
Reference: URL:http://www.iss.net/security_center/static/8057.php

Description:
NetScreen ScreenOS before 2.6.1 does not support a maximum number of concurrent sessions for a system, which allows an attacker on the trusted network to cause a denial of service (resource exhaustion) via a port scan to an external network, which consumes all available connections.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0235

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020205 Castelle Faxpress: Password used for NT Print queue can be discl osed in Plain Text
Reference: URL:http://online.securityfocus.com/archive/1/254168
Reference: BID:4030
Reference: URL:http://www.securityfocus.com/bid/4030
Reference: XF:faxpress-plaintext-password(8086)
Reference: URL:http://www.iss.net/security_center/static/8086.php

Description:
Castelle FaxPress, possibly 6.3 and other versions, when configured to use the Network print queue, allows attackers to obtain the username and password by submitting an incorrect login, which causes Faxpress to leak the correct username and password in plaintext in an error event.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0236

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020205 Published Report of Vulnerability in Lucent VitalSuite Software
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101294507827698&w=2
Reference: XF:vitalnet-unauth-access(7936)
Reference: URL:http://www.iss.net/security_center/static/7936.php
Reference: BID:3784
Reference: URL:http://www.securityfocus.com/bid/3784

Description:
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers to bypass authentication via a direct HTTP request to the VsSetCookie.exe program, which returns a valid cookie for the desired user.

Votes:

   ACCEPT(2) Cole, Green
   NOOP(2) Wall, Foat

CAN-2002-0238

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020203 Netgear RT311/RT314
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101286360203461&w=2
Reference: XF:netgear-web-interface-css(8082)
Reference: URL:http://www.iss.net/security_center/static/8082.php
Reference: BID:4024
Reference: URL:http://online.securityfocus.com/bid/4024

Description:
Cross-site scripting vulnerability in web administration interface for NetGear RT314 and RT311 Gateway Routers allows remote attackers to execute arbitrary script on another client via a URL that contains the script.

Votes:

   ACCEPT(1) Green
   NOOP(3) Wall, Foat, Cole

CAN-2002-0239

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 another hanterm exploit
Reference: URL:http://online.securityfocus.com/archive/1/255168
Reference: BUGTRAQ:20020207 Overflow Vulnerabilities in hanterm
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101310874106455&w=2
Reference: DEBIAN:DSA-112
Reference: URL:http://www.debian.org/security/2002/dsa-112
Reference: XF:hanterm-command-line-bo(8109)
Reference: URL:http://www.iss.net/security_center/static/8109.php
Reference: BID:4050
Reference: URL:http://online.securityfocus.com/bid/4050

Description:
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -fn, (2) -hfb, or (3) -hfn argument.

Votes:

   ACCEPT(4) Frech, Cox, Cole, Armstrong
   NOOP(2) Wall, Foat
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]


CAN-2002-0240

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 PHP Advisory #2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101311746611160&w=2
Reference: BID:4057
Reference: URL:http://www.securityfocus.com/bid/4057
Reference: XF:apache-php-options-information(8119)
Reference: URL:http://www.iss.net/security_center/static/8119.php

Description:
PHP, when installed with Apache and configured to search for index.php as a default web page, allows remote attackers to obtain the full pathname of the server via the HTTP OPTIONS method, which reveals the pathname in the resulting error message.

Votes:

   ACCEPT(2) Baker, Frech
   MODIFY(1) Cox
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to MODIFY]
 Cox> Change to "....installed with Apache 2.0 for Windows"


CAN-2002-0242

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101309907709138&w=2

Description:
Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Cox, Foat, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:ie-opera-contenttype-css(8218)


CAN-2002-0243

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 Web Browsers vulnerable to the Extended HTML Form Attack (IE and OPERA)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101309907709138&w=2

Description:
Cross-site scripting vulnerability in Opera 6.0 and earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Foat, Cole, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:ie-opera-contenttype-css(8218)


CAN-2002-0244

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 AtheOS: escaping from a chroot jail
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101310622531303&w=2

Description:
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot dot) in the pathname argument to chdir.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:atheos-dot-directory-traversal(8108)


CAN-2002-0245

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101310812804716&w=2
Reference: CONFIRM:http://www-1.ibm.com/support/manager.wss?rs=1&rt=0&org=sims&doc=07B32060E4CC97E985256B64005AEB0F
Reference: BID:4049
Reference: URL:http://online.securityfocus.com/bid/4049
Reference: XF:lotus-domino-reveal-information(8160)
Reference: URL:http://www.iss.net/security_center/static/8160.php

Description:
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's version name in the HTTP error message.

Votes:

   ACCEPT(4) Frech, Wall, Cole, Armstrong
   NOOP(2) Cox, Foat

CAN-2002-0247

Phase: Proposed (20020502)
Reference: DEBIAN:DSA-108
Reference: URL:http://www.debian.org/security/2002/dsa-108
Reference: BID:4054
Reference: URL:http://online.securityfocus.com/bid/4054
Reference: XF:wmtv-local-bo(8111)
Reference: URL:http://www.iss.net/security_center/static/8111.php

Description:
Buffer overflows in wmtv 0.6.5 and earlier may allow local users to gain privileges.

Votes:

   ACCEPT(4) Frech, Wall, Cole, Armstrong
   NOOP(2) Cox, Foat
Voter Comments:
 Frech> CONFIRM:http://www.debian.org/security/2002/dsa-108


CAN-2002-0248

Phase: Proposed (20020502)
Reference: DEBIAN:DSA-108
Reference: URL:http://www.debian.org/security/2002/dsa-108
Reference: BID:4052
Reference: URL:http://online.securityfocus.com/bid/4052
Reference: XF:wmtv-config-file-symlink(8110)
Reference: URL:http://www.iss.net/security_center/static/8110.php

Description:
wmtv 0.6.5 and earlier allows local users to modify arbitrary files via a symlink attack on a configuration file.

Votes:

   ACCEPT(3) Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0249

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 Security Advisory - #1
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101311698909691&w=2
Reference: XF:php-123-path-information(8121)
Reference: URL:http://www.iss.net/security_center/static/8121.php
Reference: BID:4056
Reference: URL:http://www.securityfocus.com/bid/4056

Description:
PHP for Windows, when installed on Apache 2.0.28 beta as a standalone CGI module, allows remote attackers to obtain the physical path of the php.exe via a request with malformed arguments such as /123, which leaks the pathname in the error message.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0252

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020208 [SPSadvisory#46]Apple QuickTime Player "Content-Type" Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101320742616105&w=2
Reference: XF:quicktime-content-header-bo(8126)
Reference: URL:http://www.iss.net/security_center/static/8126.php
Reference: BID:4064
Reference: URL:http://www.securityfocus.com/bid/4064

Description:
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a response containing a long Content-Type MIME header.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0253

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020207 Advisory #3 - PHP & JSP
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101318944130790&w=2
Reference: BID:4063
Reference: URL:http://online.securityfocus.com/bid/4063
Reference: XF:php-slash-path-information(8122)
Reference: URL:http://www.iss.net/security_center/static/8122.php

Description:
PHP, when not configured with the "display_errors = Off" setting in php.ini, allows remote attackers to obtain the physical path for an include file via a trailing slash in a request to a directly accessible PHP program, which modifies the base path, causes the include directive to fail, and produces an error message that contains the path.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Christey, Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Christey> Is this another case when PHP leaks path information by design,
   as supported by "display_errors" option?  Then the
   vulnerability (rather, exposure) would be in the use of the 
   display_errors option itself, whose implications may include
   this particular scenario.
 CHANGE> [Cox changed vote from REVIEWING to NOOP]


CAN-2002-0254

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020208 -possible- Bufferoverflow in ICQ 2001b
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101320492009565&w=2

Description:
ICQ 2001b Build 3659 allows remote attackers to cause a denial of service (crash) via a malformed picture that contains large height and width values, which causes the crash when viewed in Userdetails.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:icq-large-jpg-bo(8159)


CAN-2002-0255

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020208 arescom 800 authentification flaw
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101323620111951&w=2
Reference: XF:netdsl-telnet-bypass-authentication(8125)
Reference: URL:http://www.iss.net/security_center/static/8125.php
Reference: BID:4066
Reference: URL:http://www.securityfocus.com/bid/4066

Description:
The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0256

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020209 Arescom NetDSL-1000 telnetd DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101328827420630&w=2
Reference: BID:4067
Reference: URL:http://www.securityfocus.com/bid/4067
Reference: XF:netdsl-telnet-dos(8123)
Reference: URL:http://www.iss.net/security_center/static/8123.php

Description:
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of connections with long strings, which causes a large number of login failures and causes the telnet service to stop.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0257

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020209 Account theft vulnerability in MakeBid Auction Deluxe 3.30
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101328880521775&w=2
Reference: CONFIRM:http://www.netcreations.addr.com/dcforum/DCForumID2/126.html
Reference: XF:makebid-description-css(8161)
Reference: URL:http://www.iss.net/security_center/static/8161.php
Reference: BID:4069
Reference: URL:http://www.securityfocus.com/bid/4069

Description:
Cross-site scripting vulnerability in auction.pl of MakeBid Auction Deluxe 3.30 allows remote attackers to obtain information from other users via the form fields (1) TITLE, (2) DESCTIT, (3) DESC, (4) searchstring, (5) ALIAS, (6) EMAIL, (7) ADDRESS1, (8) ADDRESS2, (9) ADDRESS3, (10) PHONE1, (11) PHONE2, (12) PHONE3, or (13) PHONE4.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0258

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020209 Security Issue in Icewarp
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101328887821909&w=2

Description:
Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain privileges as that user, e.g. by extracting the ID from the user's answer or forward URLs.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:icewarp-static-sessionid(9807)


CAN-2002-0259

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020209 InstantServers MiniPortal Multiple Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101329397901071&w=2
Reference: CONFIRM:http://www.instantservers.com/releases.html
Reference: XF:miniportal-plaintext-information(8170)
Reference: URL:http://www.iss.net/security_center/static/8170.php
Reference: BID:4076
Reference: URL:http://www.securityfocus.com/bid/4076

Description:
InstantServers MiniPortal 1.1.5 and earlier stores sensitive login and account data in plaintext in (1) .pwd files in the miniportal/apache directory, or (2) mplog.txt, which could allow local users to gain privileges.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0260

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020209 InstantServers MiniPortal Multiple Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101329397901071&w=2
Reference: CONFIRM:http://www.instantservers.com/releases.html
Reference: BID:4073
Reference: URL:http://www.securityfocus.com/bid/4073
Reference: XF:miniportal-ftp-login-bo(8172)
Reference: URL:http://www.iss.net/security_center/static/8172.php

Description:
Buffer overflow in InstantServers MiniPortal 1.1.5 and earlier allows remote attackers to execute arbitrary code via a long login name, which is not properly handled by the logging utility.

Votes:

   ACCEPT(3) Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0261

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020209 InstantServers MiniPortal Multiple Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101329397901071&w=2
Reference: CONFIRM:http://www.instantservers.com/releases.html
Reference: BID:4075
Reference: URL:http://www.securityfocus.com/bid/4075
Reference: XF:miniportal-ftp-directory-traversal(8171)
Reference: URL:http://www.iss.net/security_center/static/8171.php

Description:
Directory traversal vulnerability in InstantServers MiniPortal 1.1.5 and earlier allows remote authenticated users to read arbitrary files via a ... (modified dot dot) in the GET command.

Votes:

   ACCEPT(3) Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0262

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020210 Sybex E-Trainer Directory Traversal Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101344812311216&w=2
Reference: BID:4071
Reference: URL:http://online.securityfocus.com/bid/4071
Reference: XF:sybex-etrainer-directory-traversal(8175)
Reference: URL:http://www.iss.net/security_center/static/8175.php

Description:
Directory traversal vulnerability in netget for Sybex E-Trainer web server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0263

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020211 EasyBoard 2000 Remote Buffer Overflow Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101345069220199&w=2
Reference: XF:ezboard-bbs-contenttype-bo(8162)
Reference: URL:http://www.iss.net/security_center/static/8162.php
Reference: BID:4068
Reference: URL:http://www.securityfocus.com/bid/4068

Description:
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long boundary value in a multipart Content-Type header to (1) ezboard.cgi, (2) ezman.cgi, or (3) ezadmin.cgi.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0264

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020211 PowerFTP Personal FTP Server Multiple Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101361745222207&w=2
Reference: BID:4074
Reference: URL:http://www.securityfocus.com/bid/4074

Description:
PowerFTP Personal FTP Server 2.03 through 2.10 stores sensitive account information in plaintext in the ftpserver.ini file, which allows attackers with access to the file to gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:powerftp-ftpserver-ini-plaintext(8183)


CAN-2002-0266

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020211 Re: texis(CGI) Path Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101346478229431&w=2
Reference: BUGTRAQ:20020206 texis(CGI) Path Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101301228031165&w=2
Reference: XF:texis-cgi-information-disclosure(8103)
Reference: URL:http://www.iss.net/security_center/static/8103.php
Reference: BID:4035
Reference: URL:http://online.securityfocus.com/bid/4035

Description:
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexistent file, which generates an error message that includes the full pathname.

Votes:

   ACCEPT(3) Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0268

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020212 Identix BioLogon 3
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101366270807034&w=2
Reference: BID:4101
Reference: URL:http://online.securityfocus.com/bid/4101

Description:
Identix BioLogon 3 allows users with physical access to the system to gain administrative privileges by using CTRL-ALT-DEL and running a "Browse" function, which runs Explorer with SYSTEM privileges.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:biologon3-gina-bypass-authentication(8201)
   CONFIRM:http://www.identix.com/support/sp_it.html


CAN-2002-0269

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020212 [GSA2002-01] Web browsers ignore the Content-Type header, thus allowing cross-site scripting
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101363764421623&w=2

Description:
Internet Explorer 5.x and 6 interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Foat, Cole, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:ie-opera-contenttype-css(8218)


CAN-2002-0270

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020212 [GSA2002-01] Web browsers ignore the Content-Type header, thus allowing cross-site scripting
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101363764421623&w=2

Description:
Opera, when configured with the "Determine action by MIME type" option disabled, interprets an object as an HTML document even when its MIME Content-Type is text/plain, which could allow remote attackers to execute arbitrary script in documents that the user does not expect, possibly through web applications that use a text/plain type to prevent cross-site scripting attacks.

Votes:

   MODIFY(1) Frech
   NOOP(5) Christey, Cox, Wall, Foat, Cole
   REJECT(1) Armstrong
Voter Comments:
 Frech> XF:ie-opera-contenttype-css(8218)
 Christey> BID:4098
   URL:http://www.securityfocus.com/bid/4098


CAN-2002-0271

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020212 RUS-CERT Advisory 2002-02:01: Temporary file handling in GNAT
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101353440624007&w=2
Reference: BID:4086
Reference: URL:http://online.securityfocus.com/bid/4086

Description:
Runtime library in GNU Ada compiler (GNAT) 3.12p through 3.14p allows local users to modify files of other users via a symlink attack on temporary files.

Votes:

   ACCEPT(1) Cox
   MODIFY(1) Frech
   NOOP(4) Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 Frech> XF:gnat-temp-symlink(8178)


CAN-2002-0272

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020213 Re: mpg321
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101366518310823&w=2
Reference: VULN-DEV:20020212 mpg321
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=101355590918475&w=2
Reference: CONFIRM:http://sourceforge.net/project/shownotes.php?release_id=79237
Reference: BID:4091
Reference: URL:http://online.securityfocus.com/bid/4091

Description:
Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3) an FTP request.

Votes:

   ACCEPT(2) Cole, Armstrong
   MODIFY(2) Frech, Cox
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Cox> "possibly" is vague.  It can be exploited by remote attackers
   if doing network streaming.
 Christey> REDHAT:RHSA-2002:078
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:mpg321-long-filename-bo(10032)


CAN-2002-0273

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020213 NetWin CWMail.exe Buffer Overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101362100602008&w=2
Reference: BID:4093
Reference: URL:http://online.securityfocus.com/bid/4093

Description:
Buffer overflow in CWMail.exe in NetWin before 2.8a allows remote authenticated users to execute arbitrary code via a long item parameter.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Armstrong
Voter Comments:
 Frech> XF:cwmail-item-bo(8185)


CAN-2002-0275

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020213 Falcon Web Server Authentication Circumvention Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101363946626951&w=2
Reference: BID:4099
Reference: URL:http://online.securityfocus.com/bid/4099

Description:
Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(6) Christey, Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:falcon-protected-dir-access(8189)
 Christey> This issue was rediscovered a few months later:
   VULNWATCH:20020526 [VulnWatch] [SecurityOffice] Falcon Web Server Unauthorized File Disclosure Vulnerability
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0082.html
   BUGTRAQ:20020526 [SecurityOffice] Falcon Web Server Unauthorized File Disclosure Vulnerability
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102253858809370&w=2


CAN-2002-0277

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020214 Add2it Mailman command execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101371994219708&w=2
Reference: CONFIRM:http://www.add2it.com/scripts/mailman-free-history.shtml

Description:
Add2it Mailman Free 1.73 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the list parameter.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Armstrong
Voter Comments:
 Frech> XF:mailman-open-execute-commands(8202)


CAN-2002-0278

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020214 Add2it Mailman command execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101371994219708&w=2
Reference: CONFIRM:http://www.add2it.com/scripts/mailman-free-history.shtml

Description:
Directory traversal vulnerability in Add2it Mailman Free 1.73 and earlier allows remote attackers to modify arbitrary files via a .. (dot dot) in the list parameter.

Votes:

   ACCEPT(2) Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:mailman-open-directory-traversal(8202)


CAN-2002-0279

Phase: Proposed (20020502)
Reference: HP:HPSBUX0202-183
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101372194225046&w=2
Reference: BID:4094
Reference: URL:http://online.securityfocus.com/bid/4094

Description:
The kernel in HP-UX 11.11 does not properly provide arguments for setrlimit, which could allow local attackers to cause a denial of service (kernel panic) and possibly gain privileges.

Votes:

   ACCEPT(2) Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Frech> XF:hp-setrlimit-kernel-panic(8195)


CAN-2002-0280

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020215 codeblue remote root
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101392671306875&w=2
Reference: MISC:http://freshmeat.net/releases/71514/

Description:
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary code via a long string in an SMTP reply.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> May have been 'rediscovered' by VulnWatch Mailing List, Wed
   Jul 24 2002 - 11:05:00 CDT, "Remote hole in Codeblue log scanner" at
   http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0037.html.
   If these are the same issue, then v5 also contains this security
   issue.


CAN-2002-0281

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020215 [ARL02-A03] DCP-Portal Cross Site Scripting Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101379217032525&w=2
Reference: MISC:http://www.dcp-portal.com/contents.php?id=18
Reference: BID:4112
Reference: URL:http://online.securityfocus.com/bid/4112

Description:
Cross-site scripting vulnerability in DCP-Portal 4.2 and earlier allows remote attackers to gain privileges of other portal users by providing Javascript in the job information field to user_update.php.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:dcpportal-userupdate-css(8197)


CAN-2002-0282

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020228 [ARL02-A04] DCP-Portal System Information Path Disclosure
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101494497608620&w=2
Reference: BUGTRAQ:20020215 [ARL02-A02] DCP-Portal Root Path Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101379160830631&w=2
Reference: CONFIRM:http://www.dcp-portal.com/files.php?action=viewcat&fcat_id=1
Reference: BID:4113
Reference: URL:http://online.securityfocus.com/bid/4113
Reference: XF:dcpportal-language-path-disclosure(8310)
Reference: URL:http://www.iss.net/security_center/static/8310.php

Description:
DCP-Portal 3.7 through 4.5 allows remote attackers to obtain the physical path of the server via (1) a direct request to add_user.php, or via an invalid new_language parameter in (2) contents.php, (3) categories.php, or (4) files.php, which leaks the path in an error message.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0283

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020215 Windows XP Remote DOS attacks with SYN Flag. Make CPU 100%
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101408718030099&w=2

Description:
Windows XP with port 445 open allows remote attackers to cause a denial of service (CPU consumption) via a flood of TCP SYN packets containing possibly malformed data.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Foat, Cole, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:winxp-cifs-dos(8209)


CAN-2002-0284

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020215 winamp and wma Song Licenses
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101408781031527&w=2

Description:
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:winamp-wma-pathname-disclosure(10030)


CAN-2002-0285

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020212 Outlook will see non-existing attachments
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101362077701164&w=2
Reference: BID:4092
Reference: URL:http://online.securityfocus.com/bid/4092

Description:
Outlook Express 5.5 and 6.0 on Windows treats a carriage return ("CR") in a message header as if it were a valid carriage return/line feed combination (CR/LF), which could allow remote attackers to bypass virus protection and or other filtering mechanisms via a mail message with headers that only contain the CR, which causes Outlook to create separate headers.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Foat, Cole, Armstrong
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:outlook-express-return-bypass(8198)


CAN-2002-0286

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020216 SiteNews remote add user exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101388393808699&w=2
Reference: BID:4046
Reference: URL:http://online.securityfocus.com/bid/4046

Description:
The GetPassword function in function.php of SiteNews 0.10 and 0.11 allows remote attackers to gain privileges and add users by providing a non-existent user name and the MD5 checksum for an empty password to add_user.php, which causes GetPassword to produce and compare a blank password for the non-existent user.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:sitenews-getpassword-add-users(8181)
   CONFIRM:http://www.securitytracker.com/alerts/2002/Feb/100349
   8.html


CAN-2002-0288

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020217 Phusion-Webserver-v1.0-Bugs&Exploits-Remotes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101408906001958&w=2
Reference: BID:4117
Reference: URL:http://online.securityfocus.com/bid/4117

Description:
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (triple dot dot) in the HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:phusion-dot-directoy-traversal(8212)


CAN-2002-0289

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020217 Phusion-Webserver-v1.0-Bugs&Exploits-Remotes
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101408906001958&w=2
Reference: BID:4118
Reference: URL:http://online.securityfocus.com/bid/4118
Reference: BID:4119
Reference: URL:http://online.securityfocus.com/bid/4119

Description:
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary code via a long HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:phusion-get-bo(8215)
   XF:phusion-long-url-dos(8213)


CAN-2002-0291

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020218 Dino's Webserver v1.2 DoS, possible overflow
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101415416513746&w=2
Reference: XF:dino-log-tag-bo(8233)
Reference: URL:http://www.iss.net/security_center/static/8233.php
Reference: BID:4123
Reference: URL:http://online.securityfocus.com/bid/4123

Description:
Dino's Webserver 1.2 allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via several large HTTP requests within a short time.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0293

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020219 Security BugWare : Alcatel 4400 PBX hack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101413767925869&w=2

Description:
FTP service in Alcatel OmniPCX 4400 allows the "halt" user to gain root privileges by modifying root's .profile file.

Votes:

   MODIFY(1) Frech
   NOOP(5) Christey, Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:omnipcx-ftp-root-access(8225)
 Christey> Acknowledged by Alcatel via email October 4, 2002


CAN-2002-0294

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020219 Security BugWare : Alcatel 4400 PBX hack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101413767925869&w=2
Reference: BID:4130
Reference: URL:http://online.securityfocus.com/bid/4130

Description:
Alcatel 4400 installs the /chetc/shutdown command with setgid privileges, which allows many different local users to shut down the system.

Votes:

   MODIFY(1) Frech
   NOOP(5) Christey, Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:omnipcx-shutdown-permissions(8226)
   REASON: LIKELY
 Christey> Acknowledged by Alcatel via email October 4, 2002


CAN-2002-0295

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020219 Security BugWare : Alcatel 4400 PBX hack
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101413767925869&w=2
Reference: BID:4133
Reference: URL:http://online.securityfocus.com/bid/4133

Description:
Alcatel OmniPCX 4400 installs files with world-writable permissions, which allows local users to reconfigure the system and possibly gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(5) Christey, Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:omnipcx-insecure-groups(8227)
   REASON: LIKELY
 Christey> Acknowledged by Alcatel via email October 4, 2002


CAN-2002-0296

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020219 Another local root vulnerability during installation of Tarantella Enterprise 3.
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-02/0187.html
Reference: BUGTRAQ:20020224 Exploit for Tarantella Enterprise installation (bid 4115)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101467193803592&w=2
Reference: BID:4115
Reference: URL:http://www.securityfocus.com/bid/4115

Description:
The installation of Tarantella Enterprise 3 allows local users to overwrite arbitrary files via a symlink attack on the "spinning" temporary file.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:tarantella-tmp-spinning-symlink(8223)


CAN-2002-0297

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020219 ScriptEase MiniWeb Server DoS Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101415883727615&w=2
Reference: BID:4128
Reference: URL:http://online.securityfocus.com/bid/4128

Description:
Buffer overflow in ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL in an HTTP request.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:scriptease-long-http-dos(8236)


CAN-2002-0298

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020219 Four More ScriptEase MiniWeb Server v0.95 DoS Attacks
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101424439220931&w=2
Reference: BID:4145
Reference: URL:http://online.securityfocus.com/bid/4145

Description:
ScriptEase MiniWeb Server 0.95 allows remote attackers to cause a denial of service (crash) via certain HTTP GET requests containing (1) a %2e%2e (encoded dot-dot), (2) several /../ (dot dot) sequences, (3) a missing URI, or (4) several ../ in a URI that does not begin with a / (slash) character.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:scriptease-get-dos(8250)


CAN-2002-0301

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020220 Re: Citrix NFuse 1.6 - additional network exposure
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101424947801895&w=2
Reference: BID:4142
Reference: URL:http://online.securityfocus.com/bid/4142

Description:
Citrix NFuse 1.6 allows remote attackers to bypass authentication and obtain sensitive information by directly calling launch.asp with invalid NFUSE_USER and NFUSE_PASSWORD parameters.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(4) Christey, Cox, Wall, Foat
Voter Comments:
 Christey> XF:nfuse-user-information-disclosure(8257)
   URL:http://www.iss.net/security_center/static/8257.php
 Frech> XF:nfuse-user-information-disclosure(8257)


CAN-2002-0303

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020220 Security issue with GroupWise 6 and LDAP authentication in PostOffice
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101425369510983&w=2
Reference: BID:4154
Reference: URL:http://online.securityfocus.com/bid/4154

Description:
GroupWise 6, when using LDAP authentication and when Post Office has a blank username and password, allows attackers to gain privileges of other users by logging in without a password.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Frech> XF:groupwise-ldap-blank-password(8244)


CAN-2002-0304

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020220 SecurityOffice Security Advisory:// LilHTTP Web Server Protected File Access Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101432338000591&w=2
Reference: BUGTRAQ:20020320 LilHTTP Web Server Protected File Access Vulnerability (Solution)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101665069500433&w=2
Reference: MISC:http://www.summitcn.com/lilhttp/lildocs.html#WhatsNew

Description:
Lil HTTP Server 2.1 allows remote attackers to read password-protected files via a /./ in the HTTP request.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(4) Christey, Cox, Wall, Foat
Voter Comments:
 Christey> VULNWATCH:20020222 [VulnWatch] SecurityOffice Security Advisories: Essentia and LilHTTP web servers
   URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0051.html
   XF:lilhttp-protected-file-access(8247)
   URL:http://www.iss.net/security_center/static/8247.php
   BID:4153
   URL:http://www.securityfocus.com/bid/4153
 Frech> XF:lilhttp-protected-file-access(8247)


CAN-2002-0305

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020221 Zero One Tech (ZOT) P100s PrintServer and SNMP
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101432416503293&w=2

Description:
Zero One Tech (ZOT) P100s print server does not properly disable the SNMP service or change the default password, which could leave the server open to attack without the administrator's knowledge.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:zot-default-snmp-string(8270)


CAN-2002-0306

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020221 "Cthulhu xhAze" - Command execution in Ans.pl
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101430868616112&w=2
Reference: BID:4149
Reference: URL:http://online.securityfocus.com/bid/4149

Description:
ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the p (plugin) parameter.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:ans-plugin-execute-commands(8256)


CAN-2002-0307

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020221 "Cthulhu xhAze" - Command execution in Ans.pl
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101430868616112&w=2
Reference: BID:4147
Reference: URL:http://online.securityfocus.com/bid/4147

Description:
Directory traversal vulnerability in ans.pl in Avenger's News System (ANS) 2.11 and earlier allows remote attackers to determine the existence of arbitrary files or execute any Perl program on the system via a .. (dot dot) in the p parameter, which reads the target file and attempts to execute line using Perl's eval function.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:ans-plugin-execute-commands(8256)


CAN-2002-0308

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020221 AdMentor Login Flaw
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101430885516675&w=2
Reference: BID:4152
Reference: URL:http://online.securityfocus.com/bid/4152

Description:
admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:admentor-asp-gain-access(8245)


CAN-2002-0310

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020221 Netwin Webnews 1.1k
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101432236729631&w=2
Reference: BID:4156
Reference: URL:http://online.securityfocus.com/bid/4156

Description:
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, which allows remote attackers to gain privileges via the username/password combinations (1) testweb/newstest, (2) alwn3845/imaptest, (3) alwi3845/wtest3452, or (4) testweb2/wtest4879.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:webnews-cgi-default-accounts(8255)


CAN-2002-0311

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020120 Unixware 7.1.1 scoadminreg.cgi local exploit
Reference: URL:http://online.securityfocus.com/archive/1/251747
Reference: CALDERA:CSSA-2002-SCO.6
Reference: URL:ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.6/CSSA-2002-SCO.6.txt
Reference: BID:3936
Reference: URL:http://online.securityfocus.com/bid/3936
Reference: XF:unixware-webtop-execute-commands(7977)
Reference: URL:http://www.iss.net/security_center/static/7977.php

Description:
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root privileges via shell metacharacters in the -c argument for (1) in scoadminreg.cgi or (2) service_action.cgi.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0312

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020226 SecurityOffice Security Advisory:// Essentia Web Server Vulnerabilities (Vendor Patch)
Reference: URL:http://online.securityfocus.com/archive/1/258365
Reference: NTBUGTRAQ:20020222 SecurityOffice Security Advisory:// Essentia Web Server Vulnerabilities (Vendor Patch)
Reference: URL:http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0202&L=ntbugtraq&F=P&S=&P=10201
Reference: BUGTRAQ:20020221 SecurityOffice Security Advisory:// Essentia Web Server Directory Traversal Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101439734827908&w=2
Reference: XF:essentia-server-directory-traversal(8248)
Reference: URL:http://www.iss.net/security_center/static/8248.php
Reference: BID:4160
Reference: URL:http://www.securityfocus.com/bid/4160

Description:
Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0313

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020226 SecurityOffice Security Advisory:// Essentia Web Server Vulnerabilities (Vendor Patch)
Reference: URL:http://online.securityfocus.com/archive/1/258365
Reference: BUGTRAQ:20020221 SecurityOffice Security Advisory:// Essentia Web Server DoS Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101440530023617&w=2
Reference: XF:essentia-server-long-request-dos(8249)
Reference: URL:http://www.iss.net/security_center/static/8249.php
Reference: BID:4159
Reference: URL:http://www.securityfocus.com/bid/4159

Description:
Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(4) Christey, Cox, Wall, Foat
Voter Comments:
 Christey> FULLDISC:20030704 Essentia Web Server 2.12 (Linux)
   URL:http://lists.netsys.com/pipermail/full-disclosure/2003-July/010909.html


CAN-2002-0314

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020222 Morpheus, Kazaa and Grokster Remote DoS. Also Identity faking vulnerability.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101441689224760&w=2
Reference: BID:4122
Reference: URL:http://www.securityfocus.com/bid/4122
Reference: XF:fasttrack-message-service-dos(8273)
Reference: URL:http://www.iss.net/security_center/static/8273.php

Description:
fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0315

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020222 Morpheus, Kazaa and Grokster Remote DoS. Also Identity faking vulnerability.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101441689224760&w=2
Reference: XF:fasttrack-message-service-spoof(8272)
Reference: URL:http://www.iss.net/security_center/static/8272.php
Reference: BID:4121
Reference: URL:http://www.securityfocus.com/bid/4121

Description:
fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0316

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020222 XMB cross-scripting vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101447886404876&w=2
Reference: XF:xmb-php-css(8262)
Reference: URL:http://www.iss.net/security_center/static/8262.php
Reference: BID:4167
Reference: URL:http://www.securityfocus.com/bid/4167

Description:
Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute script as other XMB users by inserting the script into an IMG tag.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0317

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020220 Gator installer Plugin allows any software to be installed
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101438671922874&w=2
Reference: MISC:http://www.gator.com/update/
Reference: XF:gator-activex-install(8266)
Reference: URL:http://www.iss.net/security_center/static/8266.php
Reference: BID:4161
Reference: URL:http://www.securityfocus.com/bid/4161

Description:
Gator ActiveX component (IEGator.dll) 3.0.6.1 allows remote web sites to install arbitrary software by specifying a Trojan Gator installation file (setup.ex_) in the src parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0319

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020222 pforum: cross-site-scripting bug
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101446366708757&w=2
Reference: BID:4165
Reference: URL:http://www.securityfocus.com/bid/4165
Reference: XF:pforum-username-css(8263)
Reference: URL:http://www.iss.net/security_center/static/8263.php

Description:
Cross-site scripting vulnerability in edituser.php for pforum 1.14 and earlier allows remote attackers to execute script and steal cookies from other users via Javascript in a username.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0320

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020221 Remote crashes in Yahoo messenger
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101439616623230&w=2
Reference: XF:yahoo-messenger-message-bo(8264)
Reference: URL:http://www.iss.net/security_center/static/8264.php
Reference: XF:yahoo-messenger-imvironment-bo(8265)
Reference: URL:http://www.iss.net/security_center/static/8265.php
Reference: BID:4162
Reference: URL:http://online.securityfocus.com/bid/4162
Reference: BID:4163
Reference: URL:http://online.securityfocus.com/bid/4163

Description:
Buffer overflow in Yahoo! Messenger 5.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long (1) message or (2) IMvironment field.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Cox, Foat
   REVIEWING(1) Wall

CAN-2002-0321

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020221 Remote crashes in Yahoo messenger
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101439616623230&w=2
Reference: XF:yahoo-messenger-username-spoof(8267)
Reference: URL:http://www.iss.net/security_center/static/8267.php
Reference: BID:4164
Reference: URL:http://www.securityfocus.com/bid/4164

Description:
Yahoo! Messenger 5.0 allows remote attackers to spoof other users by modifying the username and using the spoofed username for social engineering or denial of service (flooding) attacks.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(2) Cox, Foat
   REVIEWING(1) Wall

CAN-2002-0322

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020223 Re: Remote crashes in Yahoo messenger
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101466489113920&w=2
Reference: BUGTRAQ:20020223 Re: Re: Remote crashes in Yahoo messenger
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101467298107635&w=2
Reference: BID:4173
Reference: URL:http://online.securityfocus.com/bid/4173

Description:
Yahoo! Messenger 4.0 sends user passwords in cleartext, which could allow remote attackers to gain privileges of other users via sniffing.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(2) Cox, Foat
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:yahooim-plaintext-password(5943)


CAN-2002-0323

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020224 ScriptEase:WebServer Edition vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101465709621105&w=2

Description:
comment2.jse in ScriptEase:WebServer allows remote attackers to read arbitrary files by specifying the target file as an argument in the URL.

Votes:

   MODIFY(1) Frech
   NOOP(5) Christey, Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:netware-webserver-directory-traversal(7726)
 Christey> Need to investigate why some information sources are combining
   this with a Novell web server viewcode.asp issue (e.g. the ISS
   reference).
   
   Consider BID:3715


CAN-2002-0324

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020224 Greymatter 1.21c and earlier - remote login/pass exposure
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101465343308249&w=2
Reference: MISC:http://www.dangerousmonkey.com/dangblog/dangarch/00000051.htm
Reference: XF:greymatter-gmrightclick-account-information(8277)
Reference: URL:http://www.iss.net/security_center/static/8277.php
Reference: BID:4169
Reference: URL:http://online.securityfocus.com/bid/4169

Description:
Greymatter 1.21c and earlier with the Bookmarklet feature enabled allows remote attackers to read a cleartext password and gain administrative privileges by guessing the name of a gmrightclick-*.reg file which contains the administrator name and password in cleartext, then retrieving the file from the web server before the Greymatter administrator performs a "Clear And Exit" action.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0325

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020226 BadBlue Yet Another Directory Traversal
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101474689126219&w=2
Reference: BID:4179
Reference: URL:http://www.securityfocus.com/bid/4179
Reference: XF:badblue-dotdotdot-directory-traversal(8295)
Reference: URL:http://www.iss.net/security_center/static/8295.php

Description:
Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (modified dot dot) in the URL.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0326

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020226 BadBlue XSS vulnerabilities / Filesharing Server Worm
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101474387016066&w=2
Reference: BID:4180
Reference: URL:http://www.securityfocus.com/bid/4180
Reference: XF:badblue-url-css(8294)
Reference: URL:http://www.iss.net/security_center/static/8294.php

Description:
Cross-site scripting vulnerability in BadBlue before 1.6.1 beta allows remote attackers to execute arbitrary script and possibly additional commands via a URL that contains Javascript.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0327

Phase: Proposed (20020502)
Reference: VULN-DEV:20020222 Censoft TERM Emu bOf
Reference: URL:http://online.securityfocus.com/archive/82/257731
Reference: BUGTRAQ:20020227 Century Software Term Exploit
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101477608215471&w=2
Reference: XF:term-tty-bo(8291)
Reference: URL:http://www.iss.net/security_center/static/8291.php
Reference: BID:4174
Reference: URL:http://online.securityfocus.com/bid/4174

Description:
Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the callin program.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0328

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020226 Re: Open Bulletin Board javascript bug.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101475420818274&w=2
Reference: BID:4182
Reference: URL:http://online.securityfocus.com/bid/4182

Description:
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonboard users and steal cookies via Javascript in an IMG tag.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:ikonboard-img-css(7460)


CAN-2002-0331

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 BPM STUDIO PRO 4.2 DIRECTORY ESCAPE VULNERABILITY
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101486044323352&w=2
Reference: XF:bpm-http-directory-traversal(8300)
Reference: URL:http://www.iss.net/security_center/static/8300.php
Reference: BID:4198
Reference: URL:http://online.securityfocus.com/bid/4198

Description:
Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP request.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0332

Phase: Modified (20020817-01)
Reference: BUGTRAQ:20020227 Remote exploit against xtelld and other fun
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101494896516467&w=2
Reference: DEBIAN:DSA-121
Reference: URL:http://www.debian.org/security/2002/dsa-121
Reference: BID:4193
Reference: URL:http://www.securityfocus.com/bid/4193
Reference: XF:xtell-bo(8312)
Reference: URL:http://www.iss.net/security_center/static/8312.php

Description:
Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary code via (1) a long DNS hostname that is determined using reverse DNS lookups, (2) a long AUTH string, or (3) certain data in the xtell request.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(4) Christey, Cox, Wall, Foat
Voter Comments:
 Christey> DELREF XF:xtell-tty-directory-traversal(8313)
   ADDREF XF:xtell-bo(8312)


CAN-2002-0333

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 Remote exploit against xtelld and other fun
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101494896516467&w=2
Reference: DEBIAN:DSA-121
Reference: URL:http://www.debian.org/security/2002/dsa-121
Reference: BID:4194
Reference: URL:http://www.securityfocus.com/bid/4194
Reference: XF:xtell-tty-directory-traversal(8313)
Reference: URL:http://www.iss.net/security_center/static/8313.php

Description:
Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to read files with short names, and local users to read more files using a symlink with a short name, via a .. in the TTY argument.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0334

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 Remote exploit against xtelld and other fun
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101494896516467&w=2
Reference: DEBIAN:DSA-121
Reference: URL:http://www.debian.org/security/2002/dsa-121
Reference: BID:4197
Reference: URL:http://www.securityfocus.com/bid/4197
Reference: XF:xtell-log-symlink(8314)
Reference: URL:http://www.iss.net/security_center/static/8314.php

Description:
xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows local users to modify files via a symlink attack on the .xtell-log file.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0335

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 LBYTE&SECURITY.NNOV: Buffer overflows in Worldgroup
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101484128203523&w=2
Reference: BID:4186
Reference: URL:http://www.securityfocus.com/bid/4186
Reference: XF:worldgroup-http-get-bo(8298)
Reference: URL:http://www.iss.net/security_center/static/8298.php

Description:
Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long HTTP GET request.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0336

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 LBYTE&SECURITY.NNOV: Buffer overflows in Worldgroup
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101484128203523&w=2
Reference: XF:worldgroup-ftp-list-bo(8297)
Reference: URL:http://www.iss.net/security_center/static/8297.php
Reference: BID:4185
Reference: URL:http://www.securityfocus.com/bid/4185

Description:
Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a LIST command containing a large number of / (slash), * (wildcard), and .. characters.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0337

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 2K, with RealPlayer Installed 100 % CPU utilization
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101495354424868&w=2
Reference: XF:realplayer-mp3-invalid-dos(8320)
Reference: URL:http://www.iss.net/security_center/static/8320.php
Reference: BID:4200
Reference: URL:http://www.securityfocus.com/bid/4200

Description:
RealPlayer 8 allows remote attackers to cause a denial of service (CPU utilization) via malformed .mp3 files.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0338

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 SECURITY.NNOV: Special device access in The Bat!
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101483832026841&w=2
Reference: BID:4187
Reference: URL:http://www.securityfocus.com/bid/4187
Reference: XF:thebat-msdos-device-dos(8303)
Reference: URL:http://www.iss.net/security_center/static/8303.php

Description:
The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) via an attachment whose name includes an MS-DOS device name.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0340

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020222 Windows Media Player executes WMF content in .MP3 files.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101447771102582&w=2

Description:
Windows Media Player (WMP) 8.00.00.4477, and possibly other versions, automatically detects and executes .wmf and other content, even when the file's extension or content type does not specify .wmf, which could make it easier for attackers to conduct unauthorized activities via Trojan horse files containing .wmf content.

Votes:

   MODIFY(1) Frech
   NOOP(3) Cox, Foat, Cole
   REVIEWING(1) Wall
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:mediaplayer-wmf-file-spoof(9971)


CAN-2002-0341

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020227 SecurityOffice Security Advisory:// Novell GroupWise Web Access Path Disclosure Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101494830315071&w=2

Description:
GWWEB.EXE in GroupWise Web Access 5.5, and possibly other versions, allows remote attackers to determine the full pathname of the web server via an HTTP request with an invalid HTMLVER parameter.

Votes:

   MODIFY(1) Frech
   NOOP(5) Christey, Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:groupwise-arg-path-disclosure(8311)
 Christey> Desc: "... which leaks the pathname in an error message."


CAN-2002-0342

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020226 BUG: Kmail client DoS
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101475683425671&w=2
Reference: XF:kmail-message-body-dos(8283)
Reference: URL:http://www.iss.net/security_center/static/8283.php
Reference: BID:4177
Reference: URL:http://www.securityfocus.com/bid/4177

Description:
Kmail 1.2 on KDE 2.1.1 allows remote attackers to cause a denial of service (crash) via an email message whose body is approximately 55 K long.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0343

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020228 Hotline Client Plain password vuln.
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101495128121299&w=2
Reference: XF:hotline-connect-plaintext-password(8327)
Reference: URL:http://www.iss.net/security_center/static/8327.php
Reference: BID:4210
Reference: URL:http://www.securityfocus.com/bid/4210

Description:
Hotline Client 1.8.5 stores sensitive user information, including passwords, in plaintext in the bookmarks file, which could allow local users with access to the bookmarks file to gain privileges by extracting the passwords.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0344

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020225 Symantec LiveUpdate
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101466781122312&w=2
Reference: BUGTRAQ:20020228 Re: "Javier Sanchez" jsanchez157@hotmail.com 02/25/2002 11:14 AM, Symantec
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101496301307285&w=2
Reference: BID:4170
Reference: URL:http://www.securityfocus.com/bid/4170
Reference: XF:nav-liveupdate-plaintext-account(8282)
Reference: URL:http://www.iss.net/security_center/static/8282.php

Description:
Symantec LiveUpdate 1.5 and earlier in Norton Antivirus stores usernames and passwords for a local LiveUpdate server in cleartext in the registry, which may allow remote attackers to impersonate the LiveUpdate server.

Votes:

   ACCEPT(4) Prosser, Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Prosser> http://securityresponse.symantec.com/avcenter/security/Content/2002.02.28a.html


CAN-2002-0345

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020301 Re: "Peter Miller" pcmiller61@yahoo.com, 02/26/2002 03:48 AM RE: Symantec
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101529792821615&w=2
Reference: BUGTRAQ:20020226 RE: Symantec LiveUpdate
Reference: URL:http://online.securityfocus.com/archive/1/258293
Reference: BID:4181
Reference: URL:http://www.securityfocus.com/bid/4181
Reference: XF:ghost-plaintext-account(8305)
Reference: URL:http://www.iss.net/security_center/static/8305.php

Description:
Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServer\params registry key, which could allow an attacker to gain privileges.

Votes:

   ACCEPT(2) Prosser, Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Prosser> This was verified and responded to via BugTraq and fixed via
   LiveUpdate http://online.securityfocus.com/archive/1/259559


CAN-2002-0346

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020228 Colbalt-RAQ-v4-Bugs&Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101495944202452&w=2
Reference: BID:4211
Reference: URL:http://www.securityfocus.com/bid/4211
Reference: XF:cobalt-raq-css(8321)
Reference: URL:http://www.iss.net/security_center/static/8321.php

Description:
Cross-site scripting vulnerability in Cobalt RAQ 4 allows remote attackers to execute arbitrary script as other Cobalt users via Javascript in a URL to (1) service.cgi or (2) alert.cgi.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0347

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020228 Colbalt-RAQ-v4-Bugs&Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101495944202452&w=2
Reference: BID:4208
Reference: URL:http://www.securityfocus.com/bid/4208
Reference: XF:cobalt-raq-directory-traversal(8322)
Reference: URL:http://www.iss.net/security_center/static/8322.php

Description:
Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root, via a .. (dot dot) in an HTTP request.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0348

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020228 Colbalt-RAQ-v4-Bugs&Vulnerabilities
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101495944202452&w=2
Reference: XF:cobalt-raq-service-dos(8323)
Reference: URL:http://www.iss.net/security_center/static/8323.php
Reference: BID:4209
Reference: URL:http://www.securityfocus.com/bid/4209

Description:
service.cgi in Cobalt RAQ 4 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long service argument.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0349

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020228 ... Tiny Personal Firewall ...
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101494587110288&w=2
Reference: BID:4207
Reference: URL:http://www.securityfocus.com/bid/4207
Reference: XF:tinyfw-popup-gain-access(8324)
Reference: URL:http://www.iss.net/security_center/static/8324.php

Description:
Tiny Personal Firewall (TPF) 2.0.15, under certain configurations, will pop up an alert to the system even when the screen is locked, which could allow an attacker with physical access to the machine to hide activities or bypass access restrictions.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0350

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020301 DoS on HP ProCurve 4000M switch (possibly others)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101500123900612&w=2
Reference: BID:4212
Reference: URL:http://online.securityfocus.com/bid/4212
Reference: XF:hp-procurve-portscan-dos(8329)
Reference: URL:http://www.iss.net/security_center/static/8329.php

Description:
HP Procurve Switch 4000M running firmware C.08.22 and C.09.09 allows remote attackers to cause a denial of service via a port scan of the management IP address, which disables the telnet service.

Votes:

   ACCEPT(1) Frech
   NOOP(6) Cox, Wall, Foat, Cole, Armstrong, Green

CAN-2002-0351

Phase: Proposed (20020502)
Reference: DEBIAN:DSA-116
Reference: URL:http://www.debian.org/security/2002/dsa-116
Reference: XF:cfs-bo(8330)
Reference: URL:http://www.iss.net/security_center/static/8330.php
Reference: BID:4219
Reference: URL:http://online.securityfocus.com/bid/4219

Description:
Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.

Votes:

   ACCEPT(4) Frech, Cole, Armstrong, Green
   NOOP(3) Cox, Wall, Foat

CAN-2002-0352

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020302 Phorum Discussion Board Security Bug (Email Disclosure)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101508207206900&w=2
Reference: BID:4226
Reference: URL:http://online.securityfocus.com/bid/4226
Reference: XF:phorum-admin-users-information(8344)
Reference: URL:http://www.iss.net/security_center/static/8344.php

Description:
Phorum 3.3.2 allows remote attackers to determine the email addresses of the 10 most active users via a direct HTTP request to the stats.php program, which does not require authentication.

Votes:

   ACCEPT(2) Frech, Green
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0353

Phase: Modified (20020817-01)
Reference: CONECTIVA:CLA-2002:474
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000474
Reference: CONFIRM:http://www.ethereal.com/appnotes/enpa-sa-00003.html
Reference: DEBIAN:DSA-130
Reference: URL:http://www.debian.org/security/2002/dsa-130
Reference: REDHAT:RHSA-2002:088
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-088.html
Reference: BID:4604
Reference: URL:http://www.securityfocus.com/bid/4604
Reference: XF:ethereal-asn1-dos(8952)
Reference: URL:http://www.iss.net/security_center/static/8952.php

Description:
The ASN.1 parser in Ethereal 0.9.2 and earlier allows remote attackers to cause a denial of service (crash) via a certain malformed packet, which causes Ethereal to allocate memory incorrectly, possibly due to zero-length fields.

Votes:

   ACCEPT(4) Cox, Cole, Armstrong, Green
   MODIFY(1) Frech
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> DEBIAN:DSA-130
 Christey> REDHAT:RHSA-2002:088
   URL:http://www.redhat.com/support/errata/RHSA-2002-088.html
   BID:4604
   URL:http://www.securityfocus.com/bid/4604
 Christey> XF:ethereal-asn1-dos(8952)
   URL:http://www.iss.net/security_center/static/8952.php
 Frech> XF:ethereal-asn1-dos(8952)
 Christey> CALDERA:CSSA-2002-037.0
   URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-037.0.txt


CAN-2002-0354

Phase: Proposed (20020502)
Reference: BUGTRAQ:20020430 Reading local files in Netscape 6 and Mozilla (GM#001-NS)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102017952204097&w=2
Reference: NTBUGTRAQ:20020430 Reading local files in Netscape 6 and Mozilla (GM#001-NS)
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=102020343728766&w=2

Description:
The XMLHttpRequest object (XMLHTTP) in Netscape 6.1 and Mozilla 0.9.7 allows remote attackers to read arbitrary files and list directories on a client system by opening a URL that redirects the browser to the file on the client, then reading the result using the responseText property.

Votes:

   ACCEPT(3) Wall, Cole, Green
   MODIFY(2) Frech, Cox
   NOOP(3) Christey, Foat, Armstrong
Voter Comments:
 CHANGE> [Cox changed vote from ACCEPT to MODIFY]
 Cox> Mozilla 0.9.9 is also vulnerable
   ADDREF: http://bugzilla.mozilla.org/show_bug.cgi?id=141061
 Christey> REDHAT:RHSA-2002:079
 Christey> BUGTRAQ:20020502 Fix for Mozilla XMLHttpRequest file disclosure vulnerability
   URL:http://archives.neohapsis.com/archives/bugtraq/2002-05/0016.html
   REDHAT:RHSA-2002:079
   URL:http://www.redhat.com/support/errata/RHSA-2002-079.html
   CONECTIVA:CLA-2002:490
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000490
   BID:4628
   URL:http://www.securityfocus.com/bid/4628
   BUGTRAQ:20020504 UPDATE (1-May-2002): Reading local files in Netscape 6 and Mozilla (GM#001-NS)
   URL:http://online.securityfocus.com/archive/1/270948
 Christey> XF:mozilla-netscape-xmlhttprequest-redirect(8963)
   URL:http://www.iss.net/security_center/static/8963.php
 Frech> XF:mozilla-netscape-xmlhttprequest-redirect(8963)


CAN-2002-0357

Phase: Modified (20030320-01)
Reference: SGI:20020601-01-P
Reference: URL:ftp://patches.sgi.com/support/free/security/advisories/20020601-01-P
Reference: XF:irix-rpcpasswd-gain-privileges(9261)
Reference: URL:http://www.iss.net/security_center/static/9261.php
Reference: BID:4939
Reference: URL:http://online.securityfocus.com/bid/4939

Description:
Unknown vulnerability in rpc.passwd in the nfs.sw.nis subsystem of SGI IRIX 6.5.15 and earlier allows local users to gain root privileges.

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(4) Christey, Cox, Wall, Foat
Voter Comments:
 Christey> XF:irix-rpcpasswd-gain-privileges(9261)
   URL:http://www.iss.net/security_center/static/9261.php
   BID:4939
   URL:http://online.securityfocus.com/bid/4939
   SecurityFocus' title for the BID implies that the problem
   is due to a buffer overflow, but there does not seem to be
   specific information about the type of problem in the
   SGI advisory, which appears to be the only public information
   regarding this vulnerability.
 Frech> XF:irix-rpcpasswd-gain-privileges(9261)


CAN-2002-0360

Phase: Proposed (20020611)
Reference: VULNWATCH:20020520 [VulnWatch] eSecurityOnline advisory 5063 - Sun AnswerBook2 gettransbitmap buffer overflow vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=vulnwatch&m=102194510509450&w=2
Reference: BUGTRAQ:20020520 eSecurityOnline advisory 5063 - Sun AnswerBook2 gettransbitmap buffer overflow vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102198846905064&w=2
Reference: MISC:http://www.eSecurityOnline.com/advisories/eSO5063.asp

Description:
Buffer overflow in Sun AnswerBook2 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long filename argument to the gettransbitmap CGI program.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(6) Christey, Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Christey> XF:sun-answerbook2-gettransbitmap-bo(9117)
   URL:http://www.iss.net/security_center/static/9117.php
   BID:4784
   URL:http://www.securityfocus.com/bid/4784
 Frech> XF:sun-answerbook2-gettransbitmap-bo(9117)


CAN-2002-0361

Phase: Assigned (20020503)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0362

Phase: Proposed (20020611)
Reference: VULNWATCH:20020506 [VulnWatch] w00w00 on AOL Instant Messenger remote overflow #2
Reference: BUGTRAQ:20020506 w00w00 on AOL Instant Messenger remote overflow #2
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102071080509955&w=2
Reference: BID:4677
Reference: URL:http://www.securityfocus.com/bid/4677

Description:
Buffer overflow in AOL Instant Messenger (AIM) 4.2 and later allows remote attackers to execute arbitrary code via a long AddExternalApp request and a TLV type greater than 0x2711.

Votes:

   ACCEPT(2) Baker, Wall
   MODIFY(1) Frech
   NOOP(5) Christey, Cox, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:aim-addexternalapp-bo(9017)
 Christey> XF:aim-addexternalapp-bo(9017)
   URL:http://www.iss.net/security_center/static/9017.php


CAN-2002-0365

Phase: Assigned (20020508)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0370

Phase: Proposed (20030317)
Reference: VULNWATCH:20021002 R7-0004: Multiple Vendor Long ZIP Entry Filename Processing Issues
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0009.html
Reference: BUGTRAQ:20021002 R7-0004: Multiple Vendor Long ZIP Entry Filename Processing Issues
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103428193409223&w=2
Reference: MS:MS02-054
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-054.asp
Reference: CERT-VN:VU#383779
Reference: URL:http://www.kb.cert.org/vuls/id/383779
Reference: CONFIRM:http://www.info.apple.com/usen/security/security_updates.html
Reference: XF:win-zip-decompression-bo(10251)
Reference: URL:http://www.iss.net/security_center/static/10251.php
Reference: BID:5873
Reference: URL:http://www.securityfocus.com/bid/5873

Description:
Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander before 7.0.

Votes:

   ACCEPT(4) Baker, Frech, Wall, Cole
   NOOP(1) Cox

CAN-2002-0371

Phase: Proposed (20020726)
Reference: BUGTRAQ:20020604 Buffer overflow in MSIE gopher code
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102320516707940&w=2
Reference: MS:MS02-027
Reference: URL:http://www.microsoft.com/technet/security/bulletin/ms02-027.asp
Reference: BUGTRAQ:20020613 Microsoft releases critical fix that breaks their own software!
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102397955217618&w=2
Reference: BUGTRAQ:20020613 Flawed workaround in MS02-027 -- gopher can run on _any_ port, not just 70
Reference: URL:http://online.securityfocus.com/archive/1/276848
Reference: CERT-VN:VU#440275
Reference: URL:http://www.kb.cert.org/vuls/id/440275
Reference: MISC:http://www.pivx.com/workaround_fail.html
Reference: XF:ie-gopher-bo(9247)
Reference: URL:http://www.iss.net/security_center/static/9247.php
Reference: BID:4930
Reference: URL:http://www.securityfocus.com/bid/4930

Description:
Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.

Votes:

   ACCEPT(4) Baker, Wall, Foat, Cole
   NOOP(2) Christey, Cox
Voter Comments:
 Christey> XF:ie-gopher-bo(9247)
   URL:http://www.iss.net/security_center/static/9247.php
   CERT-VN:VU#440275
   URL:http://www.kb.cert.org/vuls/id/440275
   BID:4930
   URL:http://www.securityfocus.com/bid/4930
 Christey> Investigate: should this include IE 5.01?
 Christey> Note: CAN-2002-0646 was accidentally assigned to this issue.
   That candidate will be rejected in favor of this one.
   
   ADDREF MS:MS02-047
   
   ADDREF BUGTRAQ:20020729 Re: Eat gopher!
   URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102796732424646&w=2


CAN-2002-0375

Phase: Proposed (20020611)
Reference: VULN-DEV:20020417 Smalls holes on 5 products #1
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=101908986415768&w=2
Reference: BUGTRAQ:20020510 Fix available for Sgdynamo
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102107488402057&w=2

Description:
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript via a URL with the script in the HTNAME parameter.

Votes:

   ACCEPT(1) Baker
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:sgdynamo-htname-parameter-xss(9830)


CAN-2002-0376

Phase: Proposed (20030317)
Reference: ATSTAKE:A091002-1
Reference: URL:http://www.atstake.com/research/advisories/2002/a091002-1.txt
Reference: BUGTRAQ:20020925 Fwd: QuickTime for Windows ActiveX security advisory
Reference: URL:http://online.securityfocus.com/archive/1/293095
Reference: XF:quicktime-activex-pluginspage-bo(10077)
Reference: URL:http://www.iss.net/security_center/static/10077.php
Reference: BID:5685
Reference: URL:http://www.securityfocus.com/bid/5685

Description:
Buffer overflow in Apple QuickTime 5.0 ActiveX component allows remote attackers to execute arbitrary code via a long pluginspage field.

Votes:

   ACCEPT(2) Baker, Cole
   NOOP(1) Cox
   REVIEWING(1) Wall

CAN-2002-0378

Phase: Modified (20020817-01)
Reference: REDHAT:RHSA-2002:089
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-089.html
Reference: MANDRAKE:MDKSA-2002:042
Reference: URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-042.php
Reference: HP:HPSBTL0206-048
Reference: URL:http://online.securityfocus.com/advisories/4205
Reference: XF:lprng-remote-jobs-dos(9322)
Reference: URL:http://www.iss.net/security_center/static/9322.php
Reference: BID:4980
Reference: URL:http://www.securityfocus.com/bid/4980

Description:
The default configuration of LPRng print spooler in Red Hat Linux 7.0 through 7.3, Mandrake 8.1 and 8.2, and other operating systems, accepts print jobs from arbitrary remote hosts.

Votes:

   ACCEPT(5) Baker, Cox, Wall, Foat, Cole
   NOOP(1) Christey
Voter Comments:
 Christey> Also affects HP.
   XF:lprng-remote-jobs-dos(9322)
   URL:http://www.iss.net/security_center/static/9322.php
   BID:4980
   URL:http://www.securityfocus.com/bid/4980
   HP:HPSBTL0206-048
   URL:http://online.securityfocus.com/advisories/4205


CAN-2002-0380

Phase: Interim (20030326)
Reference: REDHAT:RHSA-2002:094
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-094.html
Reference: FREEBSD:FreeBSD-SA-02:29
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102650721503642&w=2
Reference: CONECTIVA:CLA-2002:491
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000491
Reference: CALDERA:CSSA-2002-025.0
Reference: URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-025.0.txt
Reference: BUGTRAQ:20020606 TSLSA-2002-0055 - tcpdump
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=102339541014226&w=2
Reference: XF:tcpdump-nfs-bo(9216)
Reference: URL:http://www.iss.net/security_center/static/9216.php
Reference: BID:4890
Reference: URL:http://online.securityfocus.com/bid/4890
Reference: HP:HPSBTL0205-044
Reference: URL:http://online.securityfocus.com/advisories/4169

Description:
Buffer overflow in tcpdump 3.6.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via an NFS packet.

Votes:

   ACCEPT(4) Baker, Wall, Cole, Armstrong
   MODIFY(2) Frech, Cox
   NOOP(2) Christey, Foat
Voter Comments:
 Cox> ADDREF: CLA-2002:491 TSLSA-2002-0055
 Christey> I clearly screwed up the references here.  This is supposed
   to be REDHAT:RHSA-2002:094.   #089 is already covered by
   CAN-2001-1279.
   
   ADDREF FREEBSD:FreeBSD-SA-02:29
 Christey> CALDERA:CSSA-2002-025.0
   CONECTIVA:CLA-2002:491
   
   Consider SUSE:SuSE-SA:2002:020, but beware that it upgrades
   *to* 3.6.2, and it mentions *AFS* packets.  There are no
   cross-references to know for sure whether they meant this
   tcpdump vulnerability or an older one.
 Frech> XF:tcpdump-nfs-bo(9216)
 Christey> HP:HPSBTL0205-044
   URL:http://online.securityfocus.com/advisories/4169
 Christey> I'm not going to add the SuSE reference, which may be
   describing CAN-2001-1279.  I don't want to hold this CAN back
   from promotion to an entry any further.


CAN-2002-0383

Phase: Assigned (20020521)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0384

Phase: Proposed (20030317)
Reference: REDHAT:RHSA-2002:107
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-107.html
Reference: REDHAT:RHSA-2002:098
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-098.html
Reference: MANDRAKE:MDKSA-2002:054
Reference: URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-054.php
Reference: HP:HPSBTL0208-057
Reference: URL:http://online.securityfocus.com/advisories/4358
Reference: XF:gaim-jabber-module-bo(9766)
Reference: URL:http://www.iss.net/security_center/static/9766.php
Reference: BID:5406
Reference: URL:http://www.securityfocus.com/bid/5406

Description:
Buffer overflow in Jabber plug-in for Gaim client before 0.58 allows remote attackers to execute arbitrary code.

Votes:

   ACCEPT(4) Cox, Cole, Armstrong, Green
   NOOP(1) Christey
Voter Comments:
 Christey> ADDREF MANDRAKE:MDKSA-2002:054
 Cox> Addref: RHSA-2003:122


CAN-2002-0385

Phase: Assigned (20020522)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0386

Phase: Proposed (20030317)
Reference: ATSTAKE:A102802-1
Reference: URL:http://www.atstake.com/research/advisories/2002/a102802-1.txt
Reference: CONFIRM:http://otn.oracle.com/deploy/security/pdf/2002alert43rev1.pdf

Description:
The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data.

Votes:

   ACCEPT(4) Baker, Wall, Cole, Green
   NOOP(1) Cox

CAN-2002-0387

Phase: Proposed (20030317)
Reference: ATSTAKE:A031303-1
Reference: URL:http://www.atstake.com/research/advisories/2003/a031303-1.txt

Description:
Buffer overflow in gxnsapi6.dll NSAPI plugin of the Connector Module for Sun ONE Application Server before 6.5 allows remote attackers to execute arbitrary code via a long HTTP request URL.

Votes:

   ACCEPT(2) Baker, Green
   NOOP(3) Cox, Wall, Cole
Voter Comments:
 Green> ACKNOWLEDGED IN SP1 AVAILABLE AT
   http://wwws.sun.com/software/download/products/3e3afb89.html


CAN-2002-0388

Phase: Proposed (20020611)
Reference: CONFIRM:http://mail.python.org/pipermail/mailman-announce/2002-May/000042.html

Description:
Cross-site scripting vulnerabilities in Mailman before 2.0.11 allow remote attackers to execute script via (1) the admin login page, or (2) the Pipermail index summaries.

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   MODIFY(2) Frech, Cox
   NOOP(3) Christey, Wall, Foat
Voter Comments:
 Christey> REDHAT:RHSA-2002:099
 Cox> ADDREF: RHSA-2002:099 RHSA-2002:100 RHSA-2002:101
 Christey> CONECTIVA:CLA-2002:489
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000489
   BID:4825
   URL:http://www.securityfocus.com/bid/4825
   BID:4826
   URL:http://www.securityfocus.com/bid/4826
   XF:mailman-pipermail-index-css(9173)
   URL:http://www.iss.net/security_center/static/9173.php
   XF:mailman-admin-login-css(9172)
   URL:http://www.iss.net/security_center/static/9172.php
 Christey> DEBIAN:DSA-147
 Frech> XF:mailman-pipermail-index-css(9173)
 Christey> 
   It's not clear whether DEBIAN:DSA-147-2 addresses this issue
   in addition to, or instead of, CAN-2002-0855


CAN-2002-0390

Phase: Assigned (20020528)

Description:
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Votes:







CAN-2002-0393

Phase: Proposed (20020611)
Reference: ATSTAKE:A060502-1
Reference: URL:http://www.atstake.com/research/advisories/2002/a060502-1.txt

Description:
Buffer overflow in Red-M 1050 (Bluetooth Access Point) management web interface allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long administration password.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(3) Cox, Wall, Armstrong
   REJECT(1) Foat
Voter Comments:
 Foat> Unable to duplicate vulnerability
 Frech> XF:redm-1050ap-web-dos(9262)


CAN-2002-0395

Phase: Proposed (20020611)
Reference: ATSTAKE:A060502-1
Reference: URL:http://www.atstake.com/research/advisories/2002/a060502-1.txt

Description:
The TFTP server for Red-M 1050 (Bluetooth Access Point) can not be disabled and makes it easier for remote attackers to crack the administration password via brute force methods.

Votes:

   ACCEPT(2) Baker, Foat
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:redm-1050ap-tftp-bruteforce (9264)


CAN-2002-0396

Phase: Proposed (20020611)
Reference: ATSTAKE:A060502-1
Reference: URL:http://www.atstake.com/research/advisories/2002/a060502-1.txt

Description:
The web management server for Red-M 1050 (Bluetooth Access Point) does not use session-based credentials to authenticate users, which allows attackers to connect to the server from the same IP address as a user who has already established a session.

Votes:

   ACCEPT(2) Baker, Foat
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:redm-1050ap-insecure-session(9265)


CAN-2002-0397

Phase: Proposed (20020611)
Reference: ATSTAKE:A060502-1
Reference: URL:http://www.atstake.com/research/advisories/2002/a060502-1.txt

Description:
Red-M 1050 (Bluetooth Access Point) publicizes its name, IP address, and other information in UDP packets to a broadcast address, which allows any system on the network to obtain potentially sensitive information about the Access Point device by monitoring UDP port 8887.

Votes:

   ACCEPT(2) Baker, Foat
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:redm-1050ap-device-existence (9266)


CAN-2002-0398

Phase: Proposed (20020611)
Reference: ATSTAKE:A060502-1
Reference: URL:http://www.atstake.com/research/advisories/2002/a060502-1.txt

Description:
Red-M 1050 (Bluetooth Access Point) PPP server allows bonded users to cause a denial of service and possibly execute arbitrary code via a long user name.

Votes:

   ACCEPT(2) Baker, Foat
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Cole, Armstrong
Voter Comments:
 Frech> XF:redm-1050ap-ppp-dos(9267)


CAN-2002-0399

Phase: Proposed (20030317)
Reference: BUGTRAQ:20020928 GNU tar (Re: Allot Netenforcer problems, GNU TAR flaw)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=103419290219680&w=2
Reference: REDHAT:RHSA-2002:096
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-096.html
Reference: MANDRAKE:MDKSA-2002:066
Reference: URL:http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2002:066
Reference: CONECTIVA:CLA-2002:538
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000538
Reference: ENGARDE:ESA-20021003-022
Reference: URL:http://www.linuxsecurity.com/advisories/other_advisory-2400.html
Reference: XF:archive-extraction-directory-traversal(10224)
Reference: URL:http://www.iss.net/security_center/static/10224.php

Description:
Directory traversal vulnerability in GNU tar 1.13.19 through 1.13.25, and possibly later versions, allows attackers to overwrite arbitrary files during archive extraction via a (1) "/.." or (2) "./.." string, which removes the leading slash but leaves the "..", a variant of CAN-2001-1267.

Votes:

   ACCEPT(3) Cole, Armstrong, Green
   MODIFY(1) Cox
   NOOP(1) Christey
Voter Comments:
 Christey> MANDRAKE:MDKSA-2002:066
 Cox> Addref: RHSA-2002:138


CAN-2002-0400

Phase: Interim (20030326)
Reference: CERT:CA-2002-15
Reference: URL:http://www.cert.org/advisories/CA-2002-15.html
Reference: CERT-VN:VU#739123
Reference: URL:http://www.kb.cert.org/vuls/id/739123
Reference: REDHAT:RHSA-2002:105
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-105.html
Reference: ISS:20020604 Remote Denial of Service Vulnerability in ISC BIND
Reference: CALDERA:CSSA-2002-SCO.24
Reference: URL:ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.24.1/CSSA-2002-SCO.24.1.txt
Reference: CONECTIVA:CLA-2002:494
Reference: URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000494
Reference: SUSE:SuSE-SA:2002:021
Reference: URL:http://www.suse.de/de/security/2002_21_bind9.html
Reference: REDHAT:RHSA-2002:105
Reference: URL:http://www.redhat.com/support/errata/RHSA-2002-105.html
Reference: MANDRAKE:MDKSA-2002:038
Reference: URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-038.php
Reference: HP:HPSBUX0207-202
Reference: URL:http://archives.neohapsis.com/archives/hp/2002-q3/0022.html
Reference: BID:4936
Reference: URL:http://www.securityfocus.com/bid/4936
Reference: XF:bind-findtype-dos(9250)
Reference: URL:http://www.iss.net/security_center/static/9250.php

Description:
ISC BIND 9 before 9.2.1 allows remote attackers to cause a denial of service (shutdown) via a malformed DNS packet that triggers an error condition that is not properly handled when the rdataset parameter to the dns_message_findtype() function in message.c is not NULL.

Votes:

   ACCEPT(6) Baker, Cox, Wall, Foat, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(1) Christey
Voter Comments:
 Christey> CALDERA:CSSA-2002-SCO.24
 Christey> CALDERA:CSSA-2002-SCO.24
   URL:ftp://ftp.caldera.com/pub/updates/OpenUNIX/CSSA-2002-SCO.24.1/CSSA-2002-SCO.24.1.txt
   CONECTIVA:CLA-2002:494
   URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000494
   SUSE:SuSE-SA:2002:021
   URL:http://www.suse.de/de/support/security/2002_21_bind9.html
   XF:bind-findtype-dos(9250)
   URL:http://www.iss.net/security_center/static/9250.php
   BID:4936
   URL:http://www.securityfocus.com/bid/4936
 Christey> REDHAT:RHSA-2002:105
 Frech> XF:bind-findtype-dos(9250)
 Christey> MANDRAKE:MDKSA-2002:038
 Christey> HP:HPSBUX0207-202
   URL:http://archives.neohapsis.com/archives/hp/2002-q3/0022.html


CAN-2002-0405

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020527 Problems with various windows FTP servers
Reference: URL:http://online.securityfocus.com/archive/1/274279
Reference: XF:broker-ftp-dot-bo(6673)
Reference: URL:http://xforce.iss.net/static/6673.php
Reference: BID:4864
Reference: URL:http://online.securityfocus.com/bid/4864

Description:
Buffer overflow in Transsoft Broker FTP Server 5.0 evaluation allows remote attackers to cause a denial of service and possibly execute arbitrary code via a CWD command with a large number of . (dot) characters.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0407

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020207 Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service
Reference: URL:http://online.securityfocus.com/archive/1/254768
Reference: BUGTRAQ:20020402 KPMG-2002006: Lotus Domino Physical Path Revealed
Reference: URL:http://www.securityfocus.com/archive/1/265380
Reference: BID:4406
Reference: URL:http://www.securityfocus.com/bid/4406
Reference: XF:lotus-domino-reveal-information(8160)
Reference: URL:http://www.iss.net/security_center/static/8160.php

Description:
htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes htcgibin.exe to leak the pathname in an error message.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0408

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020207 Re: KPMG-2002004: Lotus Domino Webserver DOS-device Denial of Service
Reference: URL:http://online.securityfocus.com/archive/1/254768
Reference: BUGTRAQ:20020303 Re: KPMG-2002006: Lotus Domino Physical Path Revealed
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101785616526383&w=2
Reference: BID:4049
Reference: URL:http://www.securityfocus.com/bid/4049

Description:
htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.

Votes:

   ACCEPT(1) Alderson
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:lotus-domino-reveal-information(8160)


CAN-2002-0409

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020303 iBuySpy store hole
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101518860823788&w=2

Description:
orderdetails.aspx, as made available to Microsoft .NET developers as example code and demonstrated on www.ibuyspystore.com, allows remote attackers to view the orders of other users by modifying the OrderID parameter.

Votes:

   ACCEPT(2) Wall, Alderson
   NOOP(3) Cox, Foat, Cole
   REVIEWING(1) Frech
Voter Comments:
 Alderson> This is a whole new breed of exposure... vulnerable example code
   leading to cross industry and application exposure.  This to a point made by
   Gene Kim recently "they keep deploying problems faster than we can deploy
   solutions".


CAN-2002-0410

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020303 AeroMail multiple vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0004.html
Reference: CONFIRM:http://the.cushman.net/projects/aeromail/download/aeromail-1.45.tar.gz
Reference: MISC:http://the.cushman.net/projects/aeromail/download/
Reference: XF:aeromail-obtain-files(8345)
Reference: URL:http://www.iss.net/security_center/static/8345.php
Reference: BID:4214
Reference: URL:http://www.securityfocus.com/bid/4214

Description:
send_message.php in AeroMail before 1.45 allows remote attackers to read arbitrary files on the server, instead of just uploaded files, via an attachment that modifies the filename to be uploaded.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0411

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020303 AeroMail multiple vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0004.html
Reference: CONFIRM:http://the.cushman.net/projects/aeromail/download/aeromail-1.45.tar.gz
Reference: BID:4215
Reference: URL:http://www.securityfocus.com/bid/4215
Reference: XF:aeromail-subject-css(8346)
Reference: URL:http://www.iss.net/security_center/static/8346.php

Description:
Cross-site scripting vulnerability in message.php for AeroMail before 1.45 allows remote attackers to execute Javascript as an AeroMail user via an email message with the script in the Subject line.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0413

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020304 ReBB javascripts vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/259464
Reference: BID:4220
Reference: URL:http://www.securityfocus.com/bid/4220
Reference: XF:rebb-img-css(8353)
Reference: URL:http://www.iss.net/security_center/static/8353.php

Description:
Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via an IMG tag whose URL includes the malicious script.

Votes:

   ACCEPT(2) Frech, Alderson
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0415

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020302 RealPlayer bug
Reference: URL:http://www.securityfocus.com/archive/1/259333
Reference: BID:4221
Reference: URL:http://www.securityfocus.com/bid/4221
Reference: XF:realplayer-http-directory-traversal(8336)
Reference: URL:http://www.iss.net/security_center/static/8336.php

Description:
Directory traversal vulnerability in the web server used in RealPlayer 6.0.7, and possibly other versions, may allow local users to read files that are accessible to RealPlayer via a .. (dot dot) in an HTTP GET request to port 1275.

Votes:

   ACCEPT(2) Frech, Alderson
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0416

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 Buffer Overflows in sh39.com
Reference: URL:http://www.securityfocus.com/archive/1/259818
Reference: BID:4232
Reference: URL:http://www.securityfocus.com/bid/4232
Reference: XF:sh39-mailserver-dos(8379)
Reference: URL:http://www.iss.net/security_center/static/8379.php

Description:
Buffer overflow in SH39 MailServer 1.21 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long command to the SMTP port.

Votes:

   ACCEPT(2) Frech, Alderson
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Frech> Article title for BUGTRAQ:20020305 is "Buffer Overflows in
   sh39.com's mailserver 1.21".


CAN-2002-0417

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 Endymion SakeMail and MailMan File Disclosure Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/259730
Reference: CONFIRM:http://www.endymion.com/products/mailman/history.htm
Reference: XF:mailman-alternate-templates-traversal(8357)
Reference: URL:http://www.iss.net/security_center/static/8357.php
Reference: BID:4222
Reference: URL:http://www.securityfocus.com/bid/4222

Description:
Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES parameter for various mmstdo*.cgi programs.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0418

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 Endymion SakeMail and MailMan File Disclosure Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/259730
Reference: BID:4223
Reference: URL:http://www.securityfocus.com/bid/4223
Reference: XF:sakemail-paramname-directory-traversal(8358)
Reference: URL:http://www.iss.net/security_center/static/8358.php

Description:
Directory traversal vulnerability in the com.endymion.sake.servlet.mail.MailServlet servlet for Endymion SakeMail 1.0.36 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the param_name parameter.

Votes:

   ACCEPT(2) Frech, Alderson
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0419

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 Considerations for IIS Authentication (#NISR05032002C)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101535399100534&w=2
Reference: XF:iis-authentication-error-messages(8382)
Reference: URL:http://www.iss.net/security_center/static/8382.php
Reference: BID:4235
Reference: URL:http://www.securityfocus.com/bid/4235

Description:
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (1) the server reveals whether it supports Basic or NTLM authentication through 401 Access Denied error messages, (2) in certain configurations, the server IP address is provided as the realm for Basic authentication, which could reveal real IP addresses that were obscured by NAT, or (3) when NTLM authentication is used, the NetBIOS name of the server and its Windows NT domain are revealed in response to an Authorization request.

Votes:

   ACCEPT(2) Frech, Alderson
   NOOP(3) Cox, Foat, Cole
   REVIEWING(1) Wall

CAN-2002-0420

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 PureTLS Security Announcement: Upgrade to 0.9b2
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0056.html
Reference: BID:4237
Reference: URL:http://www.securityfocus.com/bid/4237
Reference: XF:puretls-injection-attack(8386)
Reference: URL:http://www.iss.net/security_center/static/8386.php

Description:
Vulnerability in PureTLS before 0.9b2 related to injection attacks, which could possibly allow remote attackers to corrupt or hijack user sessions.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0421

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020306 NT user (who is locked changing his/her password by administrator ) can bypass the security policy and Change the password.
Reference: URL:http://online.securityfocus.com/archive/1/259963
Reference: BID:4236
Reference: URL:http://www.securityfocus.com/bid/4236
Reference: XF:winnt-pw-policy-bypass(8388)
Reference: URL:http://www.iss.net/security_center/static/8388.php

Description:
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.

Votes:

   ACCEPT(3) Frech, Cole, Alderson
   NOOP(2) Cox, Foat
   REVIEWING(1) Wall

CAN-2002-0422

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 IIS Internal IP Address Disclosure (#NISR05032002B)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101536634207324&w=2
Reference: NTBUGTRAQ:20020305 IIS Internal IP Address Disclosure (#NISR05032002B)
Reference: URL:http://marc.theaimsgroup.com/?l=ntbugtraq&m=101535147125320&w=2

Description:
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Multi-Status response, or (2) via the WRITE or MKCOL method, which leaks the IP in the Location server header.

Votes:

   ACCEPT(1) Alderson
   MODIFY(1) Frech
   NOOP(3) Cox, Foat, Cole
   REVIEWING(1) Wall
Voter Comments:
 Frech> XF:iis-request-ip-disclosure(8385)


CAN-2002-0426

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020308 Linksys BEFVP41 VPN Server does not follow proper VPN standards
Reference: URL:http://online.securityfocus.com/archive/1/260613
Reference: MISC:ftp://ftp.linksys.com/pub/befsr41/befvp41-1402.zip
Reference: XF:linksys-etherfast-weak-encryption(8397)
Reference: URL:http://www.iss.net/security_center/static/8397.php
Reference: BID:4250
Reference: URL:http://www.securityfocus.com/bid/4250

Description:
VPN Server module in Linksys EtherFast BEFVP41 Cable/DSL VPN Router before 1.40.1 reduces the key lengths for keys that are supplied via manual key entry, which makes it easier for attackers to crack the keys.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Cox, Wall, Foat
   REVIEWING(1) Alderson

CAN-2002-0427

Phase: Proposed (20020611)
Reference: MANDRAKE:MDKSA-2002:021
Reference: URL:http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-021.php
Reference: FREEBSD:FreeBSD-SA-02:17
Reference: URL:ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:17.mod_frontpage.asc
Reference: BID:4251
Reference: URL:http://www.securityfocus.com/bid/4251
Reference: XF:apache-modfrontpage-bo(8400)
Reference: URL:http://www.iss.net/security_center/static/8400.php

Description:
Buffer overflows in fpexec in mod_frontpage before 1.6.1 may allow attackers to gain root privileges.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   MODIFY(1) Cox
   NOOP(2) Wall, Foat
Voter Comments:
 Cox> The description should say "improved mod_frontpage" as there
   are two Frontpage modules for Apache, the offical one and this one.


CAN-2002-0428

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020308 Checkpoint FW1 SecuRemote/SecureClient "re-authentication" (client side hacks of users.C)
Reference: URL:http://online.securityfocus.com/archive/1/260662
Reference: BID:4253
Reference: URL:http://www.securityfocus.com/bid/4253
Reference: XF:fw1-authentication-bypass-timeouts(8423)
Reference: URL:http://www.iss.net/security_center/static/8423.php

Description:
Check Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire values in the client's users.C configuration file.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Cox, Wall, Foat
   REVIEWING(1) Alderson

CAN-2002-0430

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020308 Remote Cobalt Raq XTR vulns
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0081.html
Reference: BID:4252
Reference: URL:http://online.securityfocus.com/bid/4252

Description:
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authentication and overwrite arbitrary files via a symlink attack on a temporary file, followed by a request to MultiFileUpload.php.

Votes:

   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
   REVIEWING(1) Alderson
Voter Comments:
 Frech> XF:cobalt-multifileupload-bypass-auth(8395)


CAN-2002-0432

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020309 Citadel/UX Server Remote DoS attack Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/260934
Reference: CONFIRM:http://uncensored.citadel.org/pub/citadel/citadel-ux-5.91.tar.gz
Reference: XF:citadel-helo-bo(8426)
Reference: URL:http://www.iss.net/security_center/static/8426.php
Reference: BID:4263
Reference: URL:http://www.securityfocus.com/bid/4263

Description:
Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks such as a long HELO command to the SMTP server.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0433

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020310 Pi3Web/2.0.0 File-Disclosure/Path Disclosure vuln
Reference: URL:http://online.securityfocus.com/archive/1/260734
Reference: XF:pi3web-asterisk-view-files(8429)
Reference: URL:http://www.iss.net/security_center/static/8429.php
Reference: BID:4262
Reference: URL:http://www.securityfocus.com/bid/4262

Description:
Pi3Web 2.0.0 allows remote attackers to view restricted files via an HTTP request containing a "*" (wildcard or asterisk) character.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Green, Cox, Wall, Foat, Cole

CAN-2002-0434

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020310 Marcus S. Xenakis "directory.php" allows arbitrary code execution
Reference: URL:http://www.securityfocus.com/archive/1/261512
Reference: BID:4278
Reference: URL:http://www.securityfocus.com/bid/4278
Reference: XF:xenakis-directory-execute-commands(8440)
Reference: URL:http://www.iss.net/security_center/static/8440.php

Description:
Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Green, Cox, Wall, Foat, Cole

CAN-2002-0436

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020311 SunSolve CD cgi scripts...
Reference: URL:http://www.securityfocus.com/archive/1/261544
Reference: BID:4269
Reference: URL:http://www.securityfocus.com/bid/4269
Reference: XF:sunsolve-cd-command-execution(8435)
Reference: URL:http://www.iss.net/security_center/static/8435.php

Description:
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2002-0438

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020311 ZyXEL ZyWALL10 DoS
Reference: URL:http://www.securityfocus.com/archive/1/261411
Reference: MISC:ftp://ftp.zyxel.com/public/zywall10/firmware/zywall10_V3.50(WA.2)C0_Standard.zip
Reference: XF:zyxel-zywall10-arp-dos(8436)
Reference: URL:http://www.iss.net/security_center/static/8436.php
Reference: BID:4272
Reference: URL:http://www.securityfocus.com/bid/4272
Reference: VULNWATCH:20020312 [VulnWatch] ZyXEL ZyWALL10 DoS
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0067.html

Description:
ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall's IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2002-0439

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020311 CaupoShop: cross-site-scripting bug
Reference: URL:http://www.securityfocus.com/archive/1/261218
Reference: XF:cauposhop-user-info-css(8431)
Reference: URL:http://www.iss.net/security_center/static/8431.php
Reference: BID:4270
Reference: URL:http://www.securityfocus.com/bid/4270

Description:
Cross-site scripting vulnerability in CaupoShop 1.30a and earlier, and possibly CaupoShopPro, allows remote attackers to execute arbitrary Javascript and steal credit card numbers or delete items by injecting the script into new customer information fields such as the message field.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2002-0440

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020311 VirusWall HTTP proxy content scanning circumvention
Reference: URL:http://www.securityfocus.com/archive/1/261083
Reference: BID:4265
Reference: URL:http://www.securityfocus.com/bid/4265

Description:
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows malicious web servers to bypass content scanning via a Content-length header set to 0, which is often ignored by HTTP clients.

Votes:

   MODIFY(1) Frech
   NOOP(5) Green, Cox, Wall, Foat, Cole
Voter Comments:
 Frech> XF:interscan-viruswall-http-proxy-bypass(8425)


CAN-2002-0443

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020307 Windows 2000 password policy bypass possibility
Reference: URL:http://online.securityfocus.com/archive/1/260704
Reference: XF:win2k-password-bypass-policy(8402)
Reference: URL:http://www.iss.net/security_center/static/8402.php
Reference: BID:4256
Reference: URL:http://www.securityfocus.com/bid/4256

Description:
Microsoft Windows 2000 allows local users to bypass the policy that prohibits reusing old passwords by changing the current password before it expires, which does not enable the check for previous passwords.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Alderson
   NOOP(1) Cox
   REVIEWING(1) Wall

CAN-2002-0444

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020408 Vulnerability: Windows2000Server running Terminalservices
Reference: URL:http://www.securityfocus.com/archive/1/266729
Reference: BID:4464
Reference: URL:http://www.securityfocus.com/bid/4464
Reference: XF:win2k-terminal-bypass-policies(8813)
Reference: URL:http://www.iss.net/security_center/static/8813.php

Description:
Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.

Votes:

   ACCEPT(4) Frech, Foat, Cole, Alderson
   NOOP(1) Cox
   REVIEWING(1) Wall

CAN-2002-0445

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020312 [ARL02-A05] PHP FirstPost System Information Path Disclosure Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/261337
Reference: XF:phpfirstpost-path-disclosure(8434)
Reference: URL:http://www.iss.net/security_center/static/8434.php
Reference: BID:4274
Reference: URL:http://www.securityfocus.com/bid/4274

Description:
article.php in PHP FirstPost 0.1 allows allows remote attackers to obtain the full pathname of the server via an invalid post number in the post parameter, which leaks the pathname in an error message.

Votes:

   ACCEPT(3) Green, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0446

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020312 [ARL02-A06] Black Tie Project System Information Path Disclosure Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/261681
Reference: BID:4275
Reference: URL:http://www.securityfocus.com/bid/4275
Reference: XF:btp-cid-path-disclosure(8439)
Reference: URL:http://www.iss.net/security_center/static/8439.php

Description:
categorie.php3 in Black Tie Project (BTP) 0.4b through 0.5b allows remote attackers to determine the absolute path of the web server via an invalid category ID (cid) parameter, which leaks the pathname in an error message.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Cox, Wall, Foat
   REVIEWING(1) Green

CAN-2002-0447

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020308 Xerver-2.10-File-Disclousure&DoS-attack
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0091.html
Reference: BUGTRAQ:20020312 Xerver Free Web Server 2.10 file Disclosure & DoS PATCH (update version)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0155.html
Reference: XF:xerver-dot-directory-traversal(8421)
Reference: URL:http://www.iss.net/security_center/static/8421.php
Reference: BID:4255
Reference: URL:http://www.securityfocus.com/bid/4255

Description:
Directory traversal vulnerability in Xerver Free Web Server 2.10 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in an HTTP GET request.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0448

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020308 Xerver-2.10-File-Disclousure&DoS-attack
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0091.html
Reference: BUGTRAQ:20020312 Xerver Free Web Server 2.10 file Disclosure & DoS PATCH (update version)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0155.html
Reference: XF:xerver-multiple-request-dos(8419)
Reference: URL:http://www.iss.net/security_center/static/8419.php
Reference: BID:4254
Reference: URL:http://www.securityfocus.com/bid/4254

Description:
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request that contains many "C:/" sequences.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0449

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020305 Buffer Overrun in Talentsoft's Web+ (#NISR01032002A)
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101535141925150&w=2
Reference: CONFIRM:http://www.talentsoft.com/Issues/IssueDetail.wml?ID=WP943
Reference: BID:4233
Reference: URL:http://www.securityfocus.com/bid/4233
Reference: XF:webplus-webpsvc-bo(8361)
Reference: URL:http://www.iss.net/security_center/static/8361.php

Description:
Buffer overflow in webpsvc.exe for Talentsoft Web+ 5.0 and earlier allows remote attackers execute arbitrary code via a long argument to webplus.exe program, which triggers the overflow in webpsvc.exe.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0450

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020313 2nd Buffer Overflow in Talentsoft's Web+ (#NISR13032002)
Reference: URL:http://www.securityfocus.com/archive/1/261658
Reference: CONFIRM:http://www.talentsoft.com/Issues/IssueDetail.wml?ID=WP943
Reference: BID:4282
Reference: URL:http://www.securityfocus.com/bid/4282

Description:
Buffer overflow in Talentsoft Web+ 5.0 and earlier allows remote attackers to execute arbitrary code via a long Web Markup Language (wml) file name to (1) webplus.dll or (2) webplus.exe.

Votes:

   ACCEPT(3) Baker, Cole, Alderson
   MODIFY(1) Frech
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Frech> XF:webplus-wml-bo(8446)


CAN-2002-0452

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020313 Foundry Networks ServerIron don't decode URIs
Reference: URL:http://www.securityfocus.com/archive/1/261834
Reference: XF:foundry-serveriron-reveal-source(8459)
Reference: URL:http://www.iss.net/security_center/static/8459.php
Reference: BID:4286
Reference: URL:http://www.securityfocus.com/bid/4286

Description:
Foundry Networks ServerIron switches do not decode URIs when applying "url-map" rules, which could make it easier for attackers to cause the switch to forward traffic to a different server than intended and exploit vulnerabilities that would otherwise be inaccessible.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Green> INCLUSION


CAN-2002-0453

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020314 Account Lockout Vulnerability in Oblix NetPoint v5.2
Reference: URL:http://www.securityfocus.com/archive/1/262066
Reference: BID:4288
Reference: URL:http://www.securityfocus.com/bid/4288
Reference: XF:netpoint-account-lockout-bypass(8461)
Reference: URL:http://www.iss.net/security_center/static/8461.php

Description:
The account lockout capability in Oblix NetPoint 5.2 and earlier only locks out users once for the specified lockout period, which makes it easier for remote attackers to conduct brute force password guessing by waiting until the lockout period ends, then guessing passwords without being locked out again.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Green> A PATCH IS AVAILABLE, FINDING IT IS ANOTHER STORY


CAN-2002-0455

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020315 MSIE vulnerability exploitable with IncrediMail
Reference: URL:http://www.securityfocus.com/archive/1/262262
Reference: BID:4297
Reference: URL:http://www.securityfocus.com/bid/4297
Reference: XF:incredimail-insecure-attachment-directory(8460)
Reference: URL:http://www.iss.net/security_center/static/8460.php

Description:
IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Cox, Wall, Foat, Cole
Voter Comments:
 Green> INCLUSION RATIONALE IS A REASONABLE APROACH


CAN-2002-0456

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020315 RE: MSIE vulnerability exploitable with IncrediMail
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101622857703677&w=2
Reference: BUGTRAQ:20020316 MSIE vulnerability exploitable with Eudora (was: IncrediMail)
Reference: URL:http://www.securityfocus.com/archive/1/262704
Reference: BID:4306
Reference: URL:http://www.securityfocus.com/bid/4306
Reference: XF:eudora-insecure-attachment-directory(8487)
Reference: URL:http://www.iss.net/security_center/static/8487.php

Description:
Eudora 5.1 and earlier versions stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and reading files from directories with known pathnames.

Votes:

   ACCEPT(3) Green, Frech, Cole
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Green> INCLUSION RATIONALE IS A REASONABLE APPROACH


CAN-2002-0457

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020316 [ARL02-A08] BG Guestbook Cross Site Scripting Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/262693
Reference: BID:4308
Reference: URL:http://www.securityfocus.com/bid/4308
Reference: XF:bgguestbook-post-css(8474)
Reference: URL:http://www.iss.net/security_center/static/8474.php

Description:
Cross-site scripting vulnerability in signgbook.php for BG GuestBook 1.0 allows remote attackers to execute arbitrary Javascript via encoded tags such as &lt;, &gt;, and &amp; in fields such as (1) name, (2) email, (3) AIM screen name, (4) website, (5) location, or (6) message.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Green, Cox, Wall, Foat

CAN-2002-0458

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020316 [ARL02-A10] News-TNK Cross Site Scripting Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0206.html
Reference: CONFIRM:http://translate.google.com/translate?u=http%3A%2F%2Fwww.linux-sottises.net%2Findex.php%3Fnews_init%3D13%23newstag&langpair=fr%7Cen&hl=en&ie=UTF8&oe=UTF8&prev=%2Flanguage_tools
Reference: XF:newstnk-web-css(8477)
Reference: URL:http://www.iss.net/security_center/static/8477.php

Description:
Cross-site scripting vulnerability in News-TNK 1.2.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

Votes:

   ACCEPT(4) Green, Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0459

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020316 [ARL02-A09] Board-TNK Cross Site Scripting Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/262694
Reference: CONFIRM:http://translate.google.com/translate?u=http%3A%2F%2Fwww.linux-sottises.net%2Findex.php%3Fnews_init%3D13%23newstag&langpair=fr%7Cen&hl=en&ie=UTF8&oe=UTF8&prev=%2Flanguage_tools
Reference: BID:4305
Reference: URL:http://www.securityfocus.com/bid/4305
Reference: XF:boardtnk-web-css(8475)
Reference: URL:http://www.iss.net/security_center/static/8475.php

Description:
Cross-site scripting vulnerability in Board-TNK 1.3.1 and earlier allows remote attackers to execute arbitrary Javascript via the WEB parameter.

Votes:

   ACCEPT(4) Green, Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0460

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020318 KPMG-2002005: BitVise WinSSH Denial of Service
Reference: URL:http://online.securityfocus.com/archive/1/262681
Reference: BID:4300
Reference: URL:http://www.securityfocus.com/bid/4300
Reference: XF:winsshd-incomplete-connection-dos(8470)
Reference: URL:http://www.iss.net/security_center/static/8470.php
Reference: VULNWATCH:20020318 [VulnWatch] KPMG-2002005: BitVise WinSSH Denial of Service
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0068.html

Description:
Bitvise WinSSHD before 2002-03-16 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of incomplete connections that are not properly terminated, which are not properly freed by SSHd.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2002-0461

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020318 Javascript loop causes IE to crash
Reference: URL:http://online.securityfocus.com/archive/1/262994
Reference: BID:4322
Reference: URL:http://www.securityfocus.com/bid/4322
Reference: XF:ie-javascript-dos(8488)
Reference: URL:http://www.iss.net/security_center/static/8488.php

Description:
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript in a web page that calls location.replace on itself, causing a loop.

Votes:

   ACCEPT(2) Frech, Foat
   NOOP(4) Green, Cox, Wall, Cole

CAN-2002-0465

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020105 Hosting Controller's - Multiple Security Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-01/0039.html
Reference: CONFIRM:http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip
Reference: XF:hosting-controller-dot-directory-traversal(7824)
Reference: URL:http://xforce.iss.net/static/7824.php
Reference: BID:3811
Reference: URL:http://www.securityfocus.com/bid/3811

Description:
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.

Votes:

   ACCEPT(4) Green, Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0466

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020105 Hosting Controller's - Multiple Security Vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-01/0039.html
Reference: CONFIRM:http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip
Reference: XF:hosting-controller-directory-browsing(7823)
Reference: URL:http://xforce.iss.net/static/7823.php
Reference: BID:3808
Reference: URL:http://www.securityfocus.com/bid/3808

Description:
Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrowse.asp.

Votes:

   ACCEPT(4) Green, Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0467

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020310 Ecartis/Listar multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/261209
Reference: DEBIAN:DSA-123
Reference: URL:http://www.debian.org/security/2002/dsa-123
Reference: CONFIRM:http://www.ecartis.org/
Reference: XF:ecartis-mystring-bo(8284)
Reference: URL:http://www.iss.net/security_center/static/8284.php
Reference: BID:4176
Reference: URL:http://www.securityfocus.com/bid/4176
Reference: VULNWATCH:20020311 [VulnWatch] Ecartis/Listar multiple vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0063.html

Description:
Buffer overflows in Ecartis (formerly Listar) 1.0.0 before snapshot 20020125 allows remote attackers to execute arbitrary code via (1) address_match() of mystring.c or (2) other functions in tolist.c.

Votes:

   ACCEPT(4) Green, Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0468

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020427 Response to KF about Listar/Ecartis Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/269879
Reference: VULN-DEV:20020227 listar / ecaris remote or local?
Reference: URL:http://online.securityfocus.com/archive/82/258763
Reference: BUGTRAQ:20020425 ecartis / listar PoC
Reference: URL:http://online.securityfocus.com/archive/1/269658
Reference: BUGTRAQ:20020310 Ecartis/Listar multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/261209
Reference: CONFIRM:http://www.ecartis.org/
Reference: MISC:http://marc.theaimsgroup.com/?l=listar-support&m=101590272221720&w=2
Reference: BID:4271
Reference: URL:http://www.securityfocus.com/bid/4271
Reference: XF:ecartis-local-bo(8445)
Reference: URL:http://www.iss.net/security_center/static/8445.php

Description:
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privileges via (1) a long command line argument, which is not properly handled in core.c, or possibly via bad uses of sprintf() in (2) moderate.c, (3) lcgi.c, (4) fileapi.c, (5) cookie.c, (6) codes.c, or other files.

Votes:

   ACCEPT(4) Green, Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0469

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020310 Ecartis/Listar multiple vulnerabilities
Reference: URL:http://www.securityfocus.com/archive/1/261209
Reference: BID:4277
Reference: URL:http://www.securityfocus.com/bid/4277
Reference: XF:ecartis-root-privileges(8444)
Reference: URL:http://www.iss.net/security_center/static/8444.php
Reference: VULNWATCH:20020311 [VulnWatch] Ecartis/Listar multiple vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0063.html

Description:
Ecartis (formerly Listar) 1.0.0 in snapshot 20020125 and earlier does not properly drop privileges when Ecartis is installed setuid-root, "lock-to-user" is not set, and ecartis is called by certain MTA's, which could allow local users to gain privileges.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0470

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020318 PHP Net Toolpack: input validation error
Reference: URL:http://www.securityfocus.com/archive/1/262594
Reference: BID:4304
Reference: URL:http://www.securityfocus.com/bid/4304
Reference: XF:phpnettoolpack-traceroute-insecure-path(8484)
Reference: URL:http://www.iss.net/security_center/static/8484.php

Description:
PHPNetToolpack 0.1 relies on its environment's PATH to find and execute the traceroute program, which could allow local users to gain privileges by inserting a Trojan horse program into the search path.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Green, Cox, Wall, Foat, Cole

CAN-2002-0471

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020318 PHP Net Toolpack: input validation error
Reference: URL:http://www.securityfocus.com/archive/1/262594
Reference: BID:4303
Reference: URL:http://www.securityfocus.com/bid/4303
Reference: XF:phpnettoolpack-traceroute-command-execution(8482)
Reference: URL:http://www.iss.net/security_center/static/8482.php

Description:
PHPNetToolpack 0.1 allows remote attackers to execute arbitrary code via shell metacharacters in the a_query variable.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Green, Cox, Wall, Foat, Cole

CAN-2002-0472

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020319 Potential vulnerabilities of the Microsoft RVP-based Instant Messaging
Reference: URL:http://www.securityfocus.com/archive/1/262906
Reference: MISC:http://www.encode-sec.com/esp0202.pdf
Reference: BID:4316
Reference: URL:http://www.securityfocus.com/bid/4316
Reference: XF:msn-messenger-message-spoofing(8582)
Reference: URL:http://www.iss.net/security_center/static/8582.php

Description:
MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(3) Cox, Foat, Cole
   REVIEWING(1) Wall

CAN-2002-0474

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020329 Re:[Advisory] phpBB 1.4.4 still suffers from Cross Site Scripting Vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/264897
Reference: BID:4394
Reference: URL:http://www.securityfocus.com/bid/4394
Reference: XF:zeroforum-img-css(8702)
Reference: URL:http://www.iss.net/security_center/static/8702.php

Description:
Cross-site scripting vulnerability in ZeroForum allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within IMG image tag.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0475

Phase: Proposed (20020611)
Reference: MISC:http://www.securiteam.com/unixfocus/6W00Q202UM.html
Reference: XF:phpbb-cross-site-scripting(7459)
Reference: URL:http://www.iss.net/security_center/static/7459.php
Reference: BID:4379
Reference: URL:http://www.securityfocus.com/bid/4379

Description:
Cross-site scripting vulnerability in phpBB 1.4.4 and earlier allows remote attackers to execute arbitrary Javascript on web clients by embedding the script within an IMG image tag while editing a message.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0476

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020319 More SWF vulnerabilities?
Reference: URL:http://www.securityfocus.com/archive/1/262990
Reference: CONFIRM:http://www.macromedia.com/support/flash/ts/documents/fs_save.htm
Reference: BID:4320
Reference: URL:http://www.securityfocus.com/bid/4320
Reference: XF:flash-fscommand-save(8584)
Reference: URL:http://www.iss.net/security_center/static/8584.php

Description:
Standalone Macromedia Flash Player 5.0 allows remote attackers to save arbitrary files and programs via a .SWF file containing the undocumented "save" FSCommand.

Votes:

   ACCEPT(5) Green, Baker, Frech, Wall, Cole
   NOOP(2) Cox, Foat
   REVIEWING(1) Christey
Voter Comments:
 Christey> See comments for CAN-2002-0477.


CAN-2002-0477

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020109 Shockwave Flash player issue
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101071988413107&w=2
Reference: BUGTRAQ:20020319 More SWF vulnerabilities?
Reference: URL:http://www.securityfocus.com/archive/1/262990
Reference: CONFIRM:http://www.macromedia.com/support/flash/ts/documents/swf_clear.htm
Reference: CONFIRM:http://www.macromedia.com/support/flash/ts/documents/standalone_update.htm
Reference: XF:flash-fscommand-exec(8587)
Reference: URL:http://www.iss.net/security_center/static/8587.php
Reference: BID:4321
Reference: URL:http://www.securityfocus.com/bid/4321

Description:
Standalone Macromedia Flash Player 5.0 before 5,0,30,2 allows remote attackers to execute arbitrary programs via a .SWF file containing the "exec" FSCommand.

Votes:

   ACCEPT(5) Green, Baker, Frech, Wall, Cole
   NOOP(2) Cox, Foat
   REVIEWING(1) Christey
Voter Comments:
 Christey> Is swf_clear.html *really* related to standalone_update.htm?
   Or is the former really talking about a third issue related to
   a virus?  standalone_update.htm is clearly fscommand ("exec").
   It has an "Additional information" statement that says:
   "For a description of the potential issue with the previous
   stand-alone player, please refer to [swf_clear.htm]"
   
   I interpret "the previous stand-alone player" as meaning "the player
   that we are updating with this advisory."  Since we know that
   standalone_update.htm is exec, this implies that swf_clear.htm is
   really the exec issue.  However, swf_clear.html doesn't
   mention fscommand ("exec") AT ALL, which casts doubt or at
   least uncertainty as to my conclusions.
   
   swf_clear.html links back to standalone_update.htm, so at
   least the references are circular.
   
   At least it's pretty clear that this issue is different from
   CAN-2002-0476.
   
   Email inquiry sent to Macromedia on June 13, 2002.


CAN-2002-0478

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020320 Default SNMP configuration issue with Foundry Networks EdgeIron 4802F
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101666425609914&w=2
Reference: XF:edgelron-default-snmp-string(8592)
Reference: URL:http://www.iss.net/security_center/static/8592.php
Reference: BID:4330
Reference: URL:http://www.securityfocus.com/bid/4330

Description:
The default configuration of Foundry Networks EdgeIron 4802F allows remote attackers to modify sensitive information via arbitrary SNMP community strings.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2002-0479

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020320 Gravity Storm Service Pack Manager 2000 Share Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0284.html
Reference: XF:sp-manager-insecure-directories(8607)
Reference: URL:http://www.iss.net/security_center/static/8607.php
Reference: BID:4347
Reference: URL:http://www.securityfocus.com/bid/4347

Description:
Gravity Storm Service Pack Manager 2000 creates a hidden share (SPM2000c$) mapped to the C drive, which may allow local users to bypass access restrictions on certain directories in the C drive, such as system32, by accessing them through the hidden share.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole
   REVIEWING(1) Green

CAN-2002-0480

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020320 NMRC Advisory - KeyManager Issue in ISS RealSecure on Nokia Appliances
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101666833321138&w=2
Reference: BUGTRAQ:20020322 RE: NMRC Advisory: RealSecure KeyManager Issue - Further Explanation
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101684141308876&w=2
Reference: BUGTRAQ:20020321 RE: [VulnWatch] NMRC Advisory - KeyManager Issue in ISS RealSecure on Nokia Appliances
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101675086010051&w=2
Reference: BID:4331
Reference: URL:http://online.securityfocus.com/bid/4331

Description:
ISS RealSecure for Nokia devices before IPSO build 6.0.2001.141d is configured to allow a user "skank" on a machine "starscream" to become a key manager when the "first time connection" feature is enabled and before any legitimate administrators have connected, which could allow remote attackers to gain access to the device during installation.

Votes:

   ACCEPT(3) Green, Baker, Cole
   NOOP(3) Cox, Wall, Foat
   REVIEWING(1) Frech

CAN-2002-0481

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020321 How Outlook 2002 can still execute JavaScript in an HTML email message
Reference: URL:http://online.securityfocus.com/archive/1/263429
Reference: BID:4340
Reference: URL:http://www.securityfocus.com/bid/4340
Reference: XF:outlook-iframe-javascript(8604)
Reference: URL:http://www.iss.net/security_center/static/8604.php

Description:
An interaction between Windows Media Player (WMP) and Outlook 2002 allows remote attackers to bypass Outlook security settings and execute Javascript via an IFRAME in an HTML email message that references .WMS (Windows Media Skin) or other WMP media files, whose onload handlers execute the player.LaunchURL() Javascript function.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Green, Cox, Foat, Cole
   REVIEWING(1) Wall

CAN-2002-0482

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020321 Webtraversal in PCI Netsupport Manager (all version up to 7 using web extensions)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0285.html
Reference: BID:4348
Reference: URL:http://www.securityfocus.com/bid/4348
Reference: XF:netsupport-manager-directory-traversal(8610)
Reference: URL:http://www.iss.net/security_center/static/8610.php

Description:
Directory traversal vulnerability in PCI Netsupport Manager before version 7, when running web extensions, allows remote attackers to read arbitrary files via a .. (dot dot) in the HTTP GET request.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0483

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020320 Fw: PHPNuke 5.4 Path Disclosure Vulnerability?
Reference: URL:http://online.securityfocus.com/archive/1/263337
Reference: BID:4333
Reference: URL:http://www.securityfocus.com/bid/4333
Reference: XF:phpnuke-index-path-disclosure(8618)
Reference: URL:http://www.iss.net/security_center/static/8618.php

Description:
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when the file parameter is set to index.php, which triggers an error message that leaks the pathname.

Votes:

   ACCEPT(2) Green, Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0485

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020322 One more way to bypass NAV
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101684260510079&w=2
Reference: BUGTRAQ:20020322 One more way to bypass NAV
Reference: URL:http://marc.theaimsgroup.com/?l=vuln-dev&m=101681724810317&w=2

Description:
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose Content-Type and Content-Disposition headers are mixed upper and lower case, which is ignored by some mail clients.

Votes:

   ACCEPT(1) Prosser
   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:nav-case-bypass-protection(9860)
 Prosser> This issues was a continuation of an earlier reported issue
   with non-RFC compliant MIME headers. The discover was testing a
   non-updated version of NAV 2002 which was vulnerable to this and other
   non-RFC compliant configurations. Updated and current releases are not
   vulnerable to this problem
   
   http://securityresponse.symantec.com/avcenter/security/Content/2002.04.03.html
   is the posted response to this issue.


CAN-2002-0486

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020322 Xpede passwords exposed (2 vuln.)
Reference: URL:http://www.securityfocus.com/archive/1/263485
Reference: BID:4344
Reference: URL:http://www.securityfocus.com/bid/4344
Reference: XF:xpede-password-weak-encryption(8614)

Description:
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users with access to the cookies to gain privileges.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 Frech> XF:xpede-password-weak-encryption(8614)


CAN-2002-0487

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020322 Xpede passwords exposed (2 vuln.)
Reference: URL:http://www.securityfocus.com/archive/1/263485
Reference: BID:4346
Reference: URL:http://www.securityfocus.com/bid/4346
Reference: XF:xpede-reauth-plaintext-password(8612)
Reference: URL:http://www.iss.net/security_center/static/8612.php

Description:
Intellisol Xpede 4.1 stores passwords in plaintext in a Javascript "session timeout" re-authentication capability, which could allow local users with access to gain privileges of other Xpede users by reading the password from the source file, e.g. from the browser's cache.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0489

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020322 Re: PHP script: Penguin Traceroute, Remote Command Execution
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101684215209558&w=2
Reference: XF:penguin-nslookup-command-execution(8601)
Reference: URL:http://www.iss.net/security_center/static/8601.php
Reference: BID:4353
Reference: URL:http://www.securityfocus.com/bid/4353

Description:
Linux Directory Penguin NsLookup CGI script (nslookup.pl) 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the (1) query or (2) type parameters.

Votes:

   ACCEPT(2) Frech, Foat
   NOOP(4) Green, Cox, Wall, Cole

CAN-2002-0491

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020324 Cookie vulnerability in Alguest guestbook (PHP)
Reference: URL:http://www.securityfocus.com/archive/1/263902
Reference: XF:alguest-php-admin-access(8623)
Reference: URL:http://www.iss.net/security_center/static/8623.php
Reference: BID:4355
Reference: URL:http://www.securityfocus.com/bid/4355

Description:
admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0492

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020325 dcshop.cgi anybody can delete *.setup for database
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0302.html

Description:
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the database parameter.

Votes:

   MODIFY(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:dscshop-cgi-delete-setup(9854)


CAN-2002-0496

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020326 SouthWest Telnet talker server. DoS (Denial of Service Attack).
Reference: URL:http://www.securityfocus.com/archive/1/264168
Reference: XF:southwest-http-port-dos(8626)
Reference: URL:http://www.iss.net/security_center/static/8626.php
Reference: BID:4362
Reference: URL:http://www.securityfocus.com/bid/4362

Description:
The HTTP server for SouthWest Talker server 1.0.0 allows remote attackers to cause a denial of service (server crash) via a malformed URL to port 5002.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0498

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020326 Etnus TotalView 5.
Reference: URL:http://www.securityfocus.com/archive/1/264085
Reference: BID:4365
Reference: URL:http://www.securityfocus.com/bid/4365
Reference: XF:totalview-insecure-privileges(8635)
Reference: URL:http://www.iss.net/security_center/static/8635.php

Description:
Etnus TotalView 5.0.0-4 installs certain files with UID 5039 and GID 59, which could allow local users with that UID or GID to modify the files and gain privileges as other TotalView users.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0499

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020326 d_path() truncating excessive long path name vulnerability
Reference: URL:http://www.securityfocus.com/archive/1/264117
Reference: MISC:http://www.cs.helsinki.fi/linux/linux-kernel/2002-13/0054.html
Reference: BID:4367
Reference: URL:http://www.securityfocus.com/bid/4367
Reference: XF:linux-dpath-truncate-path(8634)
Reference: URL:http://www.iss.net/security_center/static/8634.php
Reference: VULNWATCH:20020326 [VulnWatch] d_path() truncating excessive long path name vulnerability
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0074.html

Description:
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories.

Votes:

   ACCEPT(3) Frech, Foat, Cole
   NOOP(3) Cox, Wall, Armstrong
   REVIEWING(1) Christey
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 CHANGE> [Cox changed vote from ACCEPT to NOOP]
 Christey> Need to investigate this more... is it the responsibility
   of the kernel to address this, or the application
   programmer?


CAN-2002-0500

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020326 Retrieving information on local files in IE (GM#003-IE)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0331.html
Reference: BID:4371
Reference: URL:http://www.securityfocus.com/bid/4371
Reference: XF:ie-dynsrc-information-disclosure(8658)
Reference: URL:http://www.iss.net/security_center/static/8658.php

Description:
Internet Explorer 5.0 through 6.0 allows remote attackers to determine the existence of files on the client via an IMG tag with a dynsrc property that references the target file, which sets certain elements of the image object such as file size.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Cox, Foat, Armstrong
   REVIEWING(1) Wall

CAN-2002-0502

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020123 RE: Citrix NFuse 1.6
Reference: URL:http://www.securityfocus.com/archive/1/251923
Reference: BUGTRAQ:20020122 Citrix NFuse 1.6
Reference: URL:http://www.securityfocus.com/archive/1/251737
Reference: XF:nfuse-applist-information-disclosure(7984)
Reference: URL:http://xforce.iss.net/static/7984.php
Reference: BID:3926
Reference: URL:http://www.securityfocus.com/bid/3926

Description:
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp page.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Cox, Wall, Foat
   REJECT(1) Alderson
Voter Comments:
 Alderson> Too much FUD


CAN-2002-0503

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020327 Citrix Nfuse directory traversal with boilerplate.asp
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0343.html
Reference: BID:4382
Reference: URL:http://www.securityfocus.com/bid/4382
Reference: XF:nfuse-boilerplate-directory-traversal(8654)
Reference: URL:http://www.iss.net/security_center/static/8654.php

Description:
Directory traversal vulnerability in boilerplate.asp for Citrix NFuse 1.5 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the NFuse_Template parameter.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0504

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020327 NFuse Cross Site Scripting vulnerability
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-03/0334.html
Reference: BID:4372
Reference: URL:http://www.securityfocus.com/bid/4372
Reference: XF:nfuse-launch-css(8659)
Reference: URL:http://www.iss.net/security_center/static/8659.php

Description:
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method, which allows remote attackers to execute script in other clients via the NFuse_Application parameter to (1) launch.jsp or (2) launch.asp.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0507

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020328 Authentication with RSA SecurID and Outlook web access
Reference: URL:http://online.securityfocus.com/archive/1/264705
Reference: BID:4390
Reference: URL:http://www.securityfocus.com/bid/4390
Reference: XF:exchange-owa-securid-bypass(8681)
Reference: URL:http://www.iss.net/security_center/static/8681.php

Description:
An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, which is eventually accepted by OWA.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(3) Cox, Foat, Armstrong
   REVIEWING(1) Wall

CAN-2002-0508

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020328 vuln in wwwisis: remote command execution and get files
Reference: URL:http://online.securityfocus.com/archive/1/264682
Reference: BUGTRAQ:20020402 RE: [VulnWatch] vuln in wwwisis: remote command execution and get files
Reference: URL:http://online.securityfocus.com/archive/1/265456
Reference: CONFIRM:http://www.bireme.br/security.htm
Reference: BID:4384
Reference: URL:http://www.securityfocus.com/bid/4384
Reference: XF:wwwisis-remote-command-execution(8660)
Reference: URL:http://www.iss.net/security_center/static/8660.php
Reference: BID:4383
Reference: URL:http://www.securityfocus.com/bid/4383
Reference: VULNWATCH:20020328 [VulnWatch] vuln in wwwisis: remote command execution and get files
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q1/0077.html

Description:
wwwisis 3.45 and earlier allows remote attackers to execute arbitrary commands and read files via the parameters (1) prolog or (2) epilog.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0509

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020328 Oracle9i TSN DoS Attack
Reference: URL:http://online.securityfocus.com/archive/1/264697
Reference: BID:4391
Reference: URL:http://www.securityfocus.com/bid/4391
Reference: XF:oracle-tns-onetcp-dos(8657)
Reference: URL:http://www.iss.net/security_center/static/8657.php

Description:
Transparent Network Substrate (TNS) Listener in Oracle 9i 9.0.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a single malformed TCP packet to port 1521.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0510

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020319 Identifying Kernel 2.4.x based Linux machines using UDP
Reference: URL:http://www.securityfocus.com/archive/1/262840
Reference: BID:4314
Reference: URL:http://www.securityfocus.com/bid/4314
Reference: XF:linux-udp-fingerprint(8588)
Reference: URL:http://www.iss.net/security_center/static/8588.php

Description:
The UDP implementation in Linux 2.4.x kernels keeps the IP Identification field at 0 for all non-fragmented packets, which could allow remote attackers to determine that a target system is running Linux.

Votes:

   ACCEPT(3) Green, Frech, Foat
   NOOP(3) Cox, Wall, Cole
Voter Comments:
 CHANGE> [Cox changed vote from REVIEWING to NOOP]
 Cox> So I asked some kernel guys about this - it's not considered
   an issue.  There are several other ways to identify Linux on
   the wire and people who care about this kind of thing rewrite
   their packets in various ways via firewall technology to trick
   the identifier programs.


CAN-2002-0514

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020331 packet filter fingerprinting(open but closed, closed but filtered)
Reference: URL:http://www.securityfocus.com/archive/1/265188
Reference: BID:4401
Reference: URL:http://www.securityfocus.com/bid/4401
Reference: XF:firewall-rst-fingerprint(8738)
Reference: URL:http://www.iss.net/security_center/static/8738.php

Description:
PF in OpenBSD 3.0 with the return-rst rule sets the TTL to 128 in the RST packet, which allows remote attackers to determine if a port is being filtered because the TTL is different than the default TTL.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0515

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020331 packet filter fingerprinting(open but closed, closed but filtered)
Reference: URL:http://www.securityfocus.com/archive/1/265188
Reference: BID:4403
Reference: URL:http://www.securityfocus.com/bid/4403
Reference: XF:firewall-rst-fingerprint(8738)
Reference: URL:http://www.iss.net/security_center/static/8738.php

Description:
IPFilter 3.4.25 and earlier sets a different TTL when a port is being filtered than when it is not being filtered, which allows remote attackers to identify filtered ports by comparing TTLs.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0517

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020108 dtterm exploit in Unixware 7.1.1
Reference: URL:http://www.securityfocus.com/archive/1/249106
Reference: BUGTRAQ:20020108 xterm exploit in Unixware 7.0.1
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-01/0099.html
Reference: CALDERA:CSSA-2002-SCO.15
Reference: URL:ftp://stage.caldera.com/pub/security/openunix/CSSA-2002-SCO.15/CSSA-2002-SCO.15.txt
Reference: BID:4502
Reference: URL:http://www.securityfocus.com/bid/4502
Reference: XF:unixware-openunix-dtterm-bo(7282)
Reference: URL:http://www.iss.net/security_center/static/7282.php
Reference: XF:x11-xrm-bo(8828)
Reference: URL:http://www.iss.net/security_center/static/8828.php

Description:
Buffer overflow in X11 library (libX11) on Caldera Open UNIX 8.0.0, UnixWare 7.1.1, and possibly other operating systems, allows local users to gain root privileges via a long -xrm argument to programs such as (1) dtterm or (2) xterm.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Alderson
   NOOP(3) Cox, Wall, Foat

CAN-2002-0518

Phase: Proposed (20020611)
Reference: FREEBSD:FreeBSD-SA-02:20
Reference: URL:ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:20.syncache.asc
Reference: XF:bsd-syncache-inpcb-dos(8875)
Reference: URL:http://www.iss.net/security_center/static/8875.php
Reference: BID:4524
Reference: URL:http://www.securityfocus.com/bid/4524

Description:
The SYN cache (syncache) and SYN cookie (syncookie) mechanism in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (crash) (a) via a SYN packet that is accepted using syncookies that causes a null pointer to be referenced for the socket's TCP options, or (b) by killing and restarting a process that listens on the same socket, which does not properly clear the old inpcb pointer on restart.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0520

Phase: Proposed (20020611)
Reference: VULN-DEV:20020409 Security holes in ASP-Nuke
Reference: URL:http://online.securityfocus.com/archive/82/266705
Reference: CONFIRM:http://www.asp-nuke.com/news.asp?date=20020412&cat=11
Reference: MISC:http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt
Reference: BID:4475
Reference: URL:http://www.securityfocus.com/bid/4475
Reference: XF:aspnuke-image-css(8829)
Reference: URL:http://www.iss.net/security_center/static/8829.php

Description:
Cross-site scripting vulnerability in functions-inc.asp for ASP-Nuke RC1 allows remote attackers to execute script as other ASP-Nuke users by embedding it within an IMG tag.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0521

Phase: Proposed (20020611)
Reference: VULN-DEV:20020409 Security holes in ASP-Nuke
Reference: URL:http://online.securityfocus.com/archive/82/266705
Reference: CONFIRM:http://www.asp-nuke.com/news.asp?date=20020412&cat=11
Reference: MISC:http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt
Reference: BID:4481
Reference: URL:http://www.securityfocus.com/bid/4481
Reference: XF:aspnuke-downloads-post-css(8830)
Reference: URL:http://www.iss.net/security_center/static/8830.php
Reference: XF:aspnuke-user-profile-css(8831)
Reference: URL:http://www.iss.net/security_center/static/8831.php
Reference: BID:4477
Reference: URL:http://www.securityfocus.com/bid/4477

Description:
Cross-site scripting vulnerabilities in ASP-Nuke RC2 and earlier allow remote attackers to execute script or gain privileges as other ASP-Nuke users via script in (1) the name parameter in downloads.asp, (2) the message parameter in Post.asp, or (3) a web site URL in profile.asp.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0522

Phase: Proposed (20020611)
Reference: VULN-DEV:20020409 Security holes in ASP-Nuke
Reference: URL:http://online.securityfocus.com/archive/82/266705
Reference: CONFIRM:http://www.asp-nuke.com/news.asp?date=20020412&cat=11
Reference: MISC:http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt
Reference: XF:aspnuke-account-hijacking(8832)
Reference: URL:http://www.iss.net/security_center/static/8832.php
Reference: BID:4484
Reference: URL:http://www.securityfocus.com/bid/4484

Description:
ASP-Nuke RC2 and earlier allows remote attackers to bypass authentication and gain privileges by modifying the "pseudo" cookie.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0523

Phase: Proposed (20020611)
Reference: VULN-DEV:20020409 Security holes in ASP-Nuke
Reference: URL:http://online.securityfocus.com/archive/82/266705
Reference: CONFIRM:http://www.asp-nuke.com/news.asp?date=20020412&cat=11
Reference: MISC:http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt
Reference: XF:aspnuke-cookie-reveal-information(8833)
Reference: URL:http://www.iss.net/security_center/static/8833.php
Reference: BID:4489
Reference: URL:http://www.securityfocus.com/bid/4489

Description:
ASP-Nuke RC2 and earlier allows remote attackers to list all logged-in users by submitting an invalid "pseudo" cookie.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0524

Phase: Proposed (20020611)
Reference: VULN-DEV:20020409 Security holes in ASP-Nuke
Reference: URL:http://online.securityfocus.com/archive/82/266705
Reference: CONFIRM:http://www.asp-nuke.com/news.asp?date=20020412&cat=11
Reference: MISC:http://www.ifrance.com/kitetoua/tuto/ASPNuke.txt
Reference: XF:aspnuke-cookie-reveal-information(8833)
Reference: URL:http://www.iss.net/security_center/static/8833.php
Reference: BID:4489
Reference: URL:http://www.securityfocus.com/bid/4489

Description:
ASP-Nuke RC2 and earlier allows remote attackers to determine the absolute path of the server by (1) calling database-inc.asp with incorrect cookies, or (2) calling Post.asp with certain arguments, which leak the pathname in an error message.

Votes:

   ACCEPT(4) Baker, Frech, Cole, Armstrong
   NOOP(3) Cox, Wall, Foat

CAN-2002-0525

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020411 Inn (Inter Net News) security problems
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0140.html
Reference: BID:4501
Reference: URL:http://www.securityfocus.com/bid/4501
Reference: XF:inn-rnews-inews-format-string(8834)
Reference: URL:http://www.iss.net/security_center/static/8834.php

Description:
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

Votes:

   ACCEPT(3) Frech, Cox, Cole
   NOOP(2) Wall, Foat
   REVIEWING(1) Christey
Voter Comments:
 Christey> CALDERA:CSSA-2002-038.0
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Need to consult with Caldera on this.


CAN-2002-0526

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020411 Inn (Inter Net News) security problems
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0140.html

Description:
Vulnerability in (1) inews or (2) rnews for INN 2.2.3 and earlier, related to insecure open() calls.

Votes:

   ACCEPT(1) Cox
   MODIFY(1) Frech
   NOOP(3) Wall, Foat, Cole
   REVIEWING(1) Christey
Voter Comments:
 Frech> XF:inn-rnews-inews-format-string(8834)
 Christey> CALDERA:CSSA-2002-038.0
 CHANGE> [Cox changed vote from REVIEWING to ACCEPT]
 CHANGE> [Christey changed vote from NOOP to REVIEWING]
 Christey> Need to consult with Caldera on this.


CAN-2002-0527

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020408 KPMG-2002007: Watchguard SOHO Denial of Service
Reference: URL:http://online.securityfocus.com/archive/1/266380
Reference: VULNWATCH:20020408 [VulnWatch] KPMG-2002007: Watchguard SOHO Denial of Service
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0006.html
Reference: BID:4447
Reference: URL:http://www.securityfocus.com/bid/4447
Reference: XF:watchguard-soho-ipoptions-dos(8774)
Reference: URL:http://www.iss.net/security_center/static/8774.php

Description:
Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad IP options.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Cox, Wall, Foat, Cole, Armstrong

CAN-2002-0528

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020410 KPMG-2002008: Watchguard SOHO IP Restrictions Flaw
Reference: URL:http://online.securityfocus.com/archive/1/266948
Reference: XF:watchguard-soho-bypass-restrictions(8814)
Reference: URL:http://www.iss.net/security_center/static/8814.php
Reference: BID:4491
Reference: URL:http://www.securityfocus.com/bid/4491
Reference: VULNWATCH:20020410 [VulnWatch] KPMG-2002008: Watchguard SOHO IP Restrictions Flaw
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0009.html

Description:
Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0529

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020414 Vulnerability in HP Photosmart/Deskjet Drivers for Mac OS X (root compromise)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0169.html
Reference: BID:4518
Reference: URL:http://www.securityfocus.com/bid/4518
Reference: XF:macos-photosmart-weak-permissions(8856)
Reference: URL:http://www.iss.net/security_center/static/8856.php

Description:
HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain privileges of other Photosmart users by replacing hp_imaging_connectivity with a Trojan horse.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0530

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020410 Cgisecurity Advisory #9: Novell Websearch, and Microsoft IIS XSS Issues
Reference: URL:http://www.securityfocus.com/archive/1/266888
Reference: VULNWATCH:20020410 [VulnWatch] Cgisecurity Advisory #9: Novell Websearch, and Microsoft IIS XSS Issues
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0010.html

Description:
Cross-site scripting vulnerability in Novell Web Search 2.0.1 allows remote attackers to execute arbitrary script as other Web Search users via the search parameter.

Votes:

   ACCEPT(1) Cole
   MODIFY(1) Frech
   NOOP(4) Cox, Wall, Foat, Armstrong
Voter Comments:
 CHANGE> [Frech changed vote from REVIEWING to MODIFY]
 Frech> XF:netware-web-search-xss(9867)


CAN-2002-0533

Phase: Proposed (20020611)
Reference: VULN-DEV:20020404 (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability
Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=101794993119738&w=2
Reference: BUGTRAQ:20020404 (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability
Reference: URL:http://online.securityfocus.com/archive/1/265798
Reference: XF:phpbb-bbcode-function-dos(8764)
Reference: URL:http://www.iss.net/security_center/static/8764.php
Reference: BID:4432
Reference: URL:http://www.securityfocus.com/bid/4432
Reference: BID:4434
Reference: URL:http://www.securityfocus.com/bid/4434
Reference: VULNWATCH:20020404 [VulnWatch] (WSS-Advisories-02003) PHPBB BBcode Process Vulnerability
Reference: URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0005.html

Description:
phpBB 1.4.4 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0534

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020416 Multiple Vulnerabilities in PostBoard
Reference: URL:http://online.securityfocus.com/archive/1/267936
Reference: XF:postboard-bbcode-dos(8883)
Reference: URL:http://www.iss.net/security_center/static/8883.php
Reference: BID:4562
Reference: URL:http://www.securityfocus.com/bid/4562

Description:
PostBoard 2.0.1 and earlier with BBcode allows remote attackers to cause a denial of service (CPU consumption) and corrupt the database via null \0 characters within [code] tags.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0535

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020416 Multiple Vulnerabilities in PostBoard
Reference: URL:http://online.securityfocus.com/archive/1/267936
Reference: BID:4559
Reference: URL:http://www.securityfocus.com/bid/4559
Reference: XF:postboard-img-css(8881)
Reference: URL:http://www.iss.net/security_center/static/8881.php

Description:
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other users via (1) an [IMG] tag when BBCode is enabled, or (2) in a topic title.

Votes:

   ACCEPT(1) Frech
   NOOP(5) Christey, Cox, Wall, Foat, Cole
Voter Comments:
 Christey> ADDREF BID:4561
   URL:http://www.securityfocus.com/bid/4561


CAN-2002-0537

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020411 SWS Vuln (small but important to those using it.)
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0148.html
Reference: XF:sws-insecure-admin-page(8849)
Reference: URL:http://www.iss.net/security_center/static/8849.php
Reference: BID:4503
Reference: URL:http://www.securityfocus.com/bid/4503

Description:
The admin.html file in StepWeb Search Engine (SWS) 2.5 stores passwords in links to manager.pl, which allows remote attackers who can access the admin.html file to gain administrative privileges to SWS.

Votes:

   ACCEPT(1) Frech
   NOOP(4) Cox, Wall, Foat, Cole

CAN-2002-0540

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020419 Re: Nortel CVX 1800s will dump all local user names and passwords via SNMP
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0272.html
Reference: BUGTRAQ:20020413 Nortel CVX 1800s will dump all local user names and passwords via SNMP
Reference: URL:http://online.securityfocus.com/archive/1/267627
Reference: XF:nortel-default-snmp-string(8848)
Reference: URL:http://www.iss.net/security_center/static/8848.php
Reference: BID:4507
Reference: URL:http://www.securityfocus.com/bid/4507

Description:
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames and passwords and modify the CVX configuration.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0541

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020411 iXsecurity.20020328.tivoli_tsm_dsmsvc.a
Reference: URL:http://online.securityfocus.com/archive/1/267143
Reference: BUGTRAQ:20020411 iXsecurity.20020327.tivoli_tsm_dsmcad.a
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0126.html
Reference: AIXAPAR:IC33211
Reference: CONFIRM:http://www.tivoli.com/support/storage_mgr/flash_httpport.html
Reference: AIXAPAR:IC33212
Reference: BID:4500
Reference: URL:http://www.securityfocus.com/bid/4500
Reference: BID:4492
Reference: URL:http://www.securityfocus.com/bid/4492
Reference: XF:tivoli-storagemanager-client-bo(8817)
Reference: URL:http://www.iss.net/security_center/static/8817.php
Reference: XF:tivoli-storagemanager-login-bo(8825)
Reference: URL:http://www.iss.net/security_center/static/8825.php

Description:
Buffer overflow in Tivoli Storage Manager TSM (1) Server or Storage Agents 3.1 through 5.1, and (2) the TSM Client Acceptor Service 4.2 and 5.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 1580 or port 1581.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(3) Cox, Wall, Foat

CAN-2002-0544

Phase: Proposed (20020611)
Reference: CONFIRM:http://www.aprelium.com/news/abws103.html
Reference: BID:4467
Reference: URL:http://www.securityfocus.com/bid/4467

Description:
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges.

Votes:

   ACCEPT(3) Baker, Cole, Armstrong
   MODIFY(1) Frech
   NOOP(3) Cox, Wall, Foat
Voter Comments:
 Frech> XF:abyss-unicode-directory-traversal(8805)


CAN-2002-0546

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020403 Re: Winamp: Mp3 file can control the minibrowser
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0049.html
Reference: BUGTRAQ:20020403 Winamp: Mp3 file can control the minibrowser
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0026.html
Reference: XF:winamp-mp3-browser-css(8753)
Reference: URL:http://www.iss.net/security_center/static/8753.php
Reference: BID:4414
Reference: URL:http://www.securityfocus.com/bid/4414

Description:
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.

Votes:

   ACCEPT(3) Baker, Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0547

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020426 Mp3 file can execute code in Winamp [Sandblad advisory #5]
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0373.html
Reference: MISC:http://www.winamp.com/download/newfeatures.jhtml
Reference: BID:4609
Reference: URL:http://www.securityfocus.com/bid/4609
Reference: XF:winamp-mp3-id3v2-bo(8946)
Reference: URL:http://www.iss.net/security_center/static/8946.php

Description:
Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0548

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020406 Anthill login and JavaScript vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0089.html
Reference: XF:anthill-postbug-auth-bypass(8771)
Reference: URL:http://www.iss.net/security_center/static/8771.php
Reference: BID:4443
Reference: URL:http://www.securityfocus.com/bid/4443

Description:
Anthill allows remote attackers to bypass authentication and file bug reports by directly accessing the postbug.php program instead of enterbug.php.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0549

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020406 Anthill login and JavaScript vulnerabilities
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0089.html
Reference: XF:anthill-bug-tracking-css(8770)
Reference: URL:http://www.iss.net/security_center/static/8770.php
Reference: BID:4442
Reference: URL:http://www.securityfocus.com/bid/4442

Description:
Cross-site scripting vulnerabilities in Anthill allow remote attackers to execute script as other Anthill users.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0550

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020403 Dynamic Guestbook V3.0 Cross Site Scripting and Arbitrary Command Execution under certain circumstances
Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0052.html
Reference: XF:dynamic-guestbook-command-execution(8762)
Reference: URL:http://www.iss.net/security_center/static/8762.php
Reference: BID:4423
Reference: URL:http://www.securityfocus.com/bid/4423

Description:
Dynamic Guestbook 3.0 allows remote attackers to execute arbitrary code via shell metacharacters in the gbdaten parameter.

Votes:

   ACCEPT(2) Frech, Cole
   NOOP(4) Cox, Wall, Foat, Armstrong

CAN-2002-0551

Phase: Proposed (20020611)
Reference: BUGTRAQ:20020403 Dynamic Guestbook V3.0 Cross Site Scripting and Arbitrary Command Execution under certain cir